atuin

Magical shell history

$ anc audit atuin --json

notable Rust atuinsh/atuin
MUST 17 / 28SHOULD 13 / 211 failing18 warningsaudited 2026-06-01 · anc 0.5.0
69pass rate
2/8principles met

human-tui Scored as a TUI: the non-interactive audits (P1) and the SIGPIPE audit (P6) have been suppressed — TUI apps intercept the TTY by design and install their own signal handlers.

This is an informational signal, not an authoritative verdict — see methodology. The per-audit evidence below is the ground truth.

Eight principles, scored

Behavioral and source checks. Every non-pass row carries a copy-paste remediation prompt.

  1. P1
    Non-Interactive by Default

    2 flag(s) found in --help but no `[env: NAME]` bindings advertised · no default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention).

    Remediation · P1
    Make atuin satisfy P1 (Non-Interactive by Default) from the agent-native CLI standard. Address:
    - Flags advertise env-var bindings in --help (2 flag(s) found in --help but no `[env: NAME]` bindings advertised)
    - `--help` advertises default values for flags (no default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention).)
    Requirements: https://anc.dev/p1
    warn
  2. P2
    Structured, Parseable Output

    --output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs) · no --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.

    Remediation · P2
    Make atuin satisfy P2 (Structured, Parseable Output) from the agent-native CLI standard. Address:
    - Structured output support (--output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs))
    - --json / --jsonl short aliases for --output (no --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.)
    - `--raw` flag for pipe-safe unformatted output (no `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools.)
    Requirements: https://anc.dev/p2
    warn
  3. P3
    Progressive Help Discovery

    no `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text. · `-h` and `--help` produce byte-identical output. SHOULD-tier — clap renders the short summary on `-h` and the full description on `--help` when `long_about` is set; collapsing them gives agents no concise list-level grep target.

    Remediation · P3
    Make atuin satisfy P3 (Progressive Help Discovery) from the agent-native CLI standard. Address:
    - `examples` subcommand or `--examples` flag for curated usage patterns (no `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text.)
    - Short `-h` summary differs from `--help` long form (`-h` and `--help` produce byte-identical output. SHOULD-tier — clap renders the short summary on `-h` and the full description on `--help` when `long_about` is set; collapsing them gives agents no concise list-level grep target.)
    - Each subcommand's `--help` ships at least one invocation example (subcommands missing example invocations in their `--help`: setup, history, import, stats, search, sync, login, logout, register, key, status, account, kv, store, dotfiles, scripts, init, info, doctor, wrapped, daemon, default-config, config, ai, pty-proxy, uuid, contributors, gen-completions. Examples teach agents the call shape faster than option tables; use clap's `after_help` or a dedicated `Examples:` block.)
    - Help text pairs human and `--output json` example invocations (no paired text + `--output json` example found within 5 lines in top-level or any subcommand `--help`. Pairing keeps agents from reverse-engineering the JSON invocation from the text one.)
    Requirements: https://anc.dev/p3
    fail
  4. P4pass
  5. P5
    Safe Retries & Mutation Boundaries

    read-pattern subcommand(s) present (search) but no write-pattern surface detected. If the CLI is read-only by design the MUST is satisfied vacuously; otherwise the write surface needs an agent-recognizable verb (create/add/update/set/delete/…).

    Remediation · P5
    Make atuin satisfy P5 (Safe Retries & Mutation Boundaries) from the agent-native CLI standard. Address:
    - Read and write surfaces are both visible in subcommand list (read-pattern subcommand(s) present (search) but no write-pattern surface detected. If the CLI is read-only by design the MUST is satisfied vacuously; otherwise the write surface needs an agent-recognizable verb (create/add/update/set/delete/…).)
    Requirements: https://anc.dev/p5
    warn
  6. P6
    Composable, Predictable Command Structure

    11/30 subcommand(s) follow standard verb names. Non-standard: setup, hook, import, stats, register, key, account, kv, store, dotfiles, scripts, wrapped, daemon, default-config, ai, pty-proxy, uuid, contributors, gen-completions. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs. · no `--color` flag advertised. MAY-tier — `auto|always|never` lets agents and pipelines override the TTY-based default.

    Remediation · P6
    Make atuin satisfy P6 (Composable, Predictable Command Structure) from the agent-native CLI standard. Address:
    - Subcommand verbs follow community-standard names (11/30 subcommand(s) follow standard verb names. Non-standard: setup, hook, import, stats, register, key, account, kv, store, dotfiles, scripts, wrapped, daemon, default-config, ai, pty-proxy, uuid, contributors, gen-completions. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs.)
    - `--color` flag for explicit color control (no `--color` flag advertised. MAY-tier — `auto|always|never` lets agents and pipelines override the TTY-based default.)
    - Subcommand naming follows a consistent verb/noun convention (subcommand naming is inconsistent: 7 non-verb subcommand(s) (history, account, kv, store, daemon, config, ai) mix verb and non-verb children at the second level, so an agent cannot predict where the action lives. SHOULD-tier: pick a consistent shape (all verb-first, all noun-verb hierarchy, or any combination where each non-verb group's children are uniformly verbs). The verb list is a heuristic; inspect `--help` to confirm.)
    Requirements: https://anc.dev/p6
    warn
  7. P7
    Bounded, High-Signal Responses

    no --quiet/-q flag detected in --help output · no `--verbose` / `-v` flag advertised. SHOULD-tier — agents debugging failures need a way to escalate diagnostic detail.

    Remediation · P7
    Make atuin satisfy P7 (Bounded, High-Signal Responses) from the agent-native CLI standard. Address:
    - Quiet mode available (no --quiet/-q flag detected in --help output)
    - `--verbose` flag for diagnostic escalation (no `--verbose` / `-v` flag advertised. SHOULD-tier — agents debugging failures need a way to escalate diagnostic detail.)
    - `--limit` / `--max-results` flag for list operations (list-style subcommand present but no limit flag advertised (looked for --limit, --max-results, --max, --top, -n). SHOULD-tier — callers should be able to bound response size directly rather than scrape-then-truncate.)
    - Cursor-based pagination flags for list traversal (list-style subcommand present but no cursor/page flag advertised (looked for --after, --before, --cursor, --page, --offset). MAY-tier — cursor pagination lets agents traverse large result sets without re-scanning earlier pages.)
    - `--timeout` flag for long-running operations (long-running subcommand present but no timeout flag advertised (looked for --timeout, --deadline, --max-time). SHOULD-tier — without a bound, agents that hit a hung operation have to enforce timeouts externally.)
    - Help text advertises TTY-aware verbosity behavior (no TTY-aware language found in `--help`. MAY-tier — automatic verbosity reduction when stdout is piped or redirected lets agents skip the explicit `--quiet` flag. Behavioral probes cannot simulate a real TTY without a pty crate, so this audit relies on documented intent.)
    Requirements: https://anc.dev/p7
    warn
  8. P8pass

All Audits

P1: Non-Interactive by Default

N/A by human-tuiNon-interactive by defaultsuppressed by audit_profile: human-tui
N/A by human-tuiNon-interactive gate flag advertised in --helpsuppressed by audit_profile: human-tui
WARNFlags advertise env-var bindings in --help2 flag(s) found in --help but no `[env: NAME]` bindings advertised
PASSSecret-bearing flags expose stdin or *-file companion
WARN`--help` advertises default values for flagsno default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention).
PASSRich-TUI affordance for TTY contexts

P2: Structured, Parseable Output

WARNStructured output support--output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs)
SKIPStructured-output CLI exposes its schema at runtimeno structured-output indicator (--output / --format / json / jsonl) in --help
WARN--json / --jsonl short aliases for --outputno --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.
WARN`--raw` flag for pipe-safe unformatted outputno `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools.
SKIP`--output` advertises additional formats beyond text/jsonno `--output` or `--format` flag advertised; vacuous skip for MAY-tier extra formats.
PASSBad invocation exits with structured usage-error code (2)
SKIPErrors emit JSON envelope with `error`/`kind`/`message` under `--output json`binary does not advertise `--output json` in --help; MUST applies only to CLIs that opt into the JSON contract.
SKIPJSON success and error envelopes share their non-payload key setbinary does not advertise `--output json` in --help; envelope-consistency only applies to CLIs that opt into the JSON contract.

P3: Progressive Help Discovery

PASSHelp flag produces useful output
PASSVersion flag works (`--version` plus short alias)
PASSVersion flag works (`--version` plus short alias)
WARN`examples` subcommand or `--examples` flag for curated usage patternsno `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text.
WARNShort `-h` summary differs from `--help` long form`-h` and `--help` produce byte-identical output. SHOULD-tier — clap renders the short summary on `-h` and the full description on `--help` when `long_about` is set; collapsing them gives agents no concise list-level grep target.
FAILEach subcommand's `--help` ships at least one invocation examplesubcommands missing example invocations in their `--help`: setup, history, import, stats, search, sync, login, logout, register, key, status, account, kv, store, dotfiles, scripts, init, info, doctor, wrapped, daemon, default-config, config, ai, pty-proxy, uuid, contributors, gen-completions. Examples teach agents the call shape faster than option tables; use clap's `after_help` or a dedicated `Examples:` block.
WARNHelp text pairs human and `--output json` example invocationsno paired text + `--output json` example found within 5 lines in top-level or any subcommand `--help`. Pairing keeps agents from reverse-engineering the JSON invocation from the text one.

P4: Fail-Fast, Actionable Errors

PASSRejects invalid arguments
PASSError messages include a hint or remediation phrase
SKIP`--output json` produces JSON-formatted errorsbinary does not advertise `--output json` in --help; SHOULD applies only to CLIs that opt into the JSON contract.

P5: Safe Retries & Mutation Boundaries

SKIPDestructive subcommands require `--force` or `--yes`no destructive subcommands detected; MUST applies conditionally to CLIs with destructive operations.
WARNRead and write surfaces are both visible in subcommand listread-pattern subcommand(s) present (search) but no write-pattern surface detected. If the CLI is read-only by design the MUST is satisfied vacuously; otherwise the write surface needs an agent-recognizable verb (create/add/update/set/delete/…).

P6: Composable, Predictable Command Structure

N/A by human-tuiHandles SIGPIPE gracefullysuppressed by audit_profile: human-tui
SKIPPager-using CLI ships --no-pager escape hatchno pager signal (less/more/$PAGER/--pager) in --help
PASSRespects NO_COLOR
WARNSubcommand verbs follow community-standard names11/30 subcommand(s) follow standard verb names. Non-standard: setup, hook, import, stats, register, key, account, kv, store, dotfiles, scripts, wrapped, daemon, default-config, ai, pty-proxy, uuid, contributors, gen-completions. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs.
WARN`--color` flag for explicit color controlno `--color` flag advertised. MAY-tier — `auto|always|never` lets agents and pipelines override the TTY-based default.
SKIPInput-accepting commands read from stdin when no file is givenno input-accepting subcommand detected (process/parse/convert/transform/analyze/validate/format/lint/audit); vacuous skip for the conditional SHOULD.
WARNSubcommand naming follows a consistent verb/noun conventionsubcommand naming is inconsistent: 7 non-verb subcommand(s) (history, account, kv, store, daemon, config, ai) mix verb and non-verb children at the second level, so an agent cannot predict where the action lives. SHOULD-tier: pick a consistent shape (all verb-first, all noun-verb hierarchy, or any combination where each non-verb group's children are uniformly verbs). The verb list is a heuristic; inspect `--help` to confirm.
PASSOperations are subcommands, not verb-shaped flags

P7: Bounded, High-Signal Responses

WARNQuiet mode availableno --quiet/-q flag detected in --help output
WARN`--verbose` flag for diagnostic escalationno `--verbose` / `-v` flag advertised. SHOULD-tier — agents debugging failures need a way to escalate diagnostic detail.
WARN`--limit` / `--max-results` flag for list operationslist-style subcommand present but no limit flag advertised (looked for --limit, --max-results, --max, --top, -n). SHOULD-tier — callers should be able to bound response size directly rather than scrape-then-truncate.
WARNCursor-based pagination flags for list traversallist-style subcommand present but no cursor/page flag advertised (looked for --after, --before, --cursor, --page, --offset). MAY-tier — cursor pagination lets agents traverse large result sets without re-scanning earlier pages.
WARN`--timeout` flag for long-running operationslong-running subcommand present but no timeout flag advertised (looked for --timeout, --deadline, --max-time). SHOULD-tier — without a bound, agents that hit a hung operation have to enforce timeouts externally.
WARNHelp text advertises TTY-aware verbosity behaviorno TTY-aware language found in `--help`. MAY-tier — automatic verbosity reduction when stdout is piped or redirected lets agents skip the explicit `--quiet` flag. Behavioral probes cannot simulate a real TTY without a pty crate, so this audit relies on documented intent.

P8: Discoverable Through Agent Skill Bundles

PASSSkill bundle has install path (`tool skill install [<host>]`)
PASS`skill install --all` for multi-runtime install
PASS`skill update` / `skill upgrade` for bundle refresh

Details

Version scored
18.16.1
Audit date
2026-06-01 17:36:45 UTC
Duration
460ms
Platform
linux/x86_64
Mode
command
Anc build
0.5.0
Install
brew install atuin

Embed the badge

The badge floor is 70%; this scorecard is at 69% (1 point below). Once the score clears the floor, the embed snippet will appear here. The top issues above are the place to start.

Reproduce this scorecard for atuin locally and inspect the failing audits:

anc audit --command atuin --audit-profile human-tui --output json

Install anc first if you don't have it. Add --output json to get the same JSON shape committed under scorecards/.