CodeDD CLI · open source
Can you audit code the company won’t hand over?
The CodeDD CLI runs the audit on the company’s own machines, across the estate — every repository in scope. CodeDD receives findings and metrics, not source files. It is open source, so their engineers can read exactly what it does before they run it.
$ codedd scope add ./payments-api ./web-app
2 repositories · 1,842 files · 214k lines
$ codedd audit start --show
payload summary written · approve? y
✓ File analysis 1,842 files
✓ Vulnerabilities 14 of 61 confirmed
✓ Complexity Radon · Lizard
✓ Dependencies 312 packages
✓ Git history 4,918 commits
✓ Architecture 38 components
→ Sent to CodeDD findings, metrics
■ Stayed local 1,842 source filespip install codedd-cli- Licence
- MIT, open source
- Runs on
- Windows, macOS, Linux
- Requires
- Python 3.10+
- LLM
- Your own key
What runs where
The analysis runs locally. The judgement runs on CodeDD.
Everything that has to read source code runs on the machine where the code lives. CodeDD turns the results into the same scores, benchmarks, and reports as a cloud audit.
On your machines
- File analysisEach file reviewed by an LLM, using your own API key
- Vulnerability validationCandidate issues checked with Semgrep and taint analysis
- ComplexityCyclomatic and Halstead metrics
- DependenciesLockfiles, manifests, and imports
- Git historyCommits, contributors, and activity
- ArchitectureComponents and the links between them
Sent to CodeDD
- Findings with file and line
- Metrics and scores
- Package list
- Architecture graph
- Scope metadata: paths, file types, line counts
Source files never leave
On CodeDD
- Consolidation and risk scoringOne score per area, across every repository
- Vulnerability and licence dataPackages matched against CVE and licence sources
- BenchmarksCompared with other audited codebases
- Recommendations and reportsDashboards, IC-ready reports, and a fix plan
Why engineers agree to run it
Nothing to take on trust
Code access is the first objection in a technical DD. With the CLI, the company’s own team can check every claim.
Read the source
The CLI is MIT-licensed and published on GitLab and PyPI. Security teams can review it, or pin and build it themselves.
Review every payload
In review mode the CLI writes a summary of every request before it is sent, and waits for approval. Nothing leaves without that confirmation.
Their keys, their LLM contract
Files are analysed with the company’s own Anthropic, OpenAI, Google Gemini, or xAI key, under the terms they already have with that provider.
After the audit
Work the findings down, or let an agent do it
The same CLI turns the audit into a fix loop. Progress is recorded against the audit in CodeDD, so the deal team sees the risk fall as the work lands.
- One finding at a time, by severityTake the next issue, fix it, note what changed, and mark it resolved.
- Built for AI coding agentsClaude Code, Cursor, and other agents can run the loop themselves. The CLI ships its own agent reference and a machine-readable session state.
› Fix the Critical CodeDD findings.
$ codedd fix context --json
14 open · 3 Critical · 5 High
$ codedd fix flags next --auto
[+] Critical · invoice export
no role check · billing/export.py:88
● agent edits billing/export.py
$ codedd fix resolve --comment "role check"
✓ resolved · 13 open · next: IDORQuick start
From install to a running audit in six commands
You need a CodeDD account, a CLI token (Account → CLI Access), and a key for at least one LLM provider. Each path you add must be a Git repository root.
- # Install from PyPI
$ pip install codedd-cli - # Paste your CLI token
$ codedd auth login - # Pick the audit to run
$ codedd audits select - # Add repositories
$ codedd scope add ./payments-api ./web-app - # Or openai, gemini, grok
$ codedd config set-key anthropic - # Review, confirm, run
$ codedd audit start --show
FAQ
Questions
Does any source code leave the company’s machines?
Source files are not sent to CodeDD. The CLI sends findings (with file and line references), metrics, the package list, the architecture graph, and scope metadata. Files are read by the LLM provider whose key the company supplies, under its own agreement with that provider. Run the audit with --show to review every payload first.
Is a CLI audit as complete as a cloud audit?
Yes. The CLI runs analysis logic taken from the CodeDD platform and kept in sync with it, and consolidation, scoring, benchmarks, and recommendations run on CodeDD exactly as for a cloud audit. The results appear in the same dashboards and reports.
What does it cost?
The CLI is free and open source. An audit run through it is billed like any CodeDD audit, by lines of code in scope; the CLI checks the budget before it starts. LLM usage is billed by the provider to the key that runs the analysis.
Which LLM providers are supported?
Anthropic, OpenAI, Google Gemini, and xAI. Keys are stored in the OS keychain with codedd config set-key, or read from environment variables such as ANTHROPIC_API_KEY on servers without a keychain.
Can it run in CI or on a headless server?
Yes. Set CODEDD_API_TOKEN and a provider key as environment variables instead of logging in, and use --yes to skip interactive prompts.
How are tokens and API keys stored?
In the operating system’s credential store (Windows Credential Locker, macOS Keychain, or Linux Secret Service), not in plain-text config. TLS certificate verification is always on, and CLI tokens expire after 90 days.
What if the audit is interrupted?
Progress is checkpointed after every batch. Run codedd audit start again and the CLI resumes from the last completed step instead of starting over.
Run your first audit without moving the code
Create an account, generate a CLI token, and start from your own terminal. Or walk through a CLI audit with the CodeDD team.