Getting Started

For AI Agents

DeployReady is a single-command CLI that emits machine-readable JSON. That makes it a clean tool for a coding agent to run end to end — scan, read findings, fix, and verify — with no UI in the loop.

TL;DR for the agent

Run npx deployready@latest analyze . --no-ai --export --json, read deployready-report.json, fix each critical finding, then re-run with --fail-on critical and confirm exit code 0.

Copy this into your agent

Paste the prompt below into Claude Code, Cursor, Windsurf, Cline, or any agent with shell access. It installs nothing globally — npx fetches and runs DeployReady on demand.

paste into your agent
Install and run DeployReady on this project, then help me fix what it finds.

1. Run:  npx deployready@latest analyze . --no-ai --export --json
2. Parse deployready-report.json. List every finding with
   severity === "critical" (file, line, title, CWE).
3. For each critical finding, propose a minimal fix as a diff.
   Apply it only after I approve.
4. Re-run:  npx deployready@latest analyze . --no-ai --fail-on critical
   Confirm the exit code is 0 and the readiness score went up.

Rules:
- Treat exit code 2 as "gate failed — unresolved critical findings".
- Never commit secrets; move them to env vars.
- Don't change app behavior beyond the security fix without asking.

What a run looks like

deployready — analyzerunning
~/my-app $
A full scan: parse → static → dynamic → AI → score.

Step 1 — Run a scan

Use the non-interactive analyze subcommand so the agent never hits an interactive menu. Emit both a JSON file (for parsing) and Markdown (for summarizing).

terminal
# scan the current directory, no AI, write report files
npx deployready@latest analyze . --no-ai --export --json

# static-only (skip live localhost testing)
npx deployready@latest analyze . --no-ai --no-dynamic --json

# stream JSON to stdout instead of a file
npx deployready@latest analyze . --no-ai --json --stdout

Step 2 — Parse the findings

Every finding is a structured object. Filter on severity and use fixable to decide what can be auto-fixed.

deployready-report.json
{
  "score": 18,
  "summary": { "critical": 16, "warning": 0, "info": 0 },
  "findings": [
    {
      "id": "CWE-798",
      "severity": "critical",
      "type": "hardcoded_secret",
      "title": "Hardcoded secret / credential in source",
      "file": "app/api/route.ts",
      "line": 15,
      "owasp": "A02:2021 – Cryptographic Failures",
      "fixable": true,
      "fix": "Move the value to an environment variable and rotate it"
    }
  ]
}

Step 3 — Fix, then verify

  • Apply the smallest change that resolves the finding (for a secret: move it to an env var and rotate it — never hard-code a replacement).
  • Re-run with --fail-on critical and read the exit code to confirm the gate passes.
  • Don’t change application behavior beyond the security fix without asking the human.
terminal
npx deployready@latest analyze . --no-ai --fail-on critical
echo "exit code: $?"   # 0 = clean, 2 = gate failed, 1 = tool error

Flags that matter for agents

FlagWhat it does
--jsonEmit machine-readable JSON (pair with --export or --stdout).
--exportWrite report files to the project directory.
--no-aiRun the deterministic checks only — no model, no network.
--no-dynamicSkip live localhost testing (static analysis only).
--fail-on <level>Exit non-zero at/above a severity (critical | warning). Use for gates.
--activeOpt-in authenticated access-control testing (needs --token).
-yAssume yes for prompts — fully non-interactive.

Exit codes

CodeMeaning
0Clean — no findings at or above the --fail-on level.
2Gate failed — findings at/above the threshold remain.
1Tool error — bad flags, parse failure, or crash.

Keep the human in the loop

Agents should propose and apply fixes, but a person approves diffs and reviews anything that touches auth, data access, or secrets. See the Security Disclaimer.