ruff
An extremely fast Python linter and code formatter
$ anc audit ruff --json
Eight principles, scored
Behavioral and source checks. Every non-pass row carries a copy-paste remediation prompt.
- P1Non-Interactive by Defaultwarn
8 flag(s) found in --help but no `[env: NAME]` bindings advertised · no default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention).
Remediation · P1Make ruff satisfy P1 (Non-Interactive by Default) from the agent-native CLI standard. Address: - Flags advertise env-var bindings in --help (8 flag(s) found in --help but no `[env: NAME]` bindings advertised) - `--help` advertises default values for flags (no default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention).) Requirements: https://anc.dev/p1
- P2Structured, Parseable Outputwarn
--output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs) · no --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.
Remediation · P2Make ruff satisfy P2 (Structured, Parseable Output) from the agent-native CLI standard. Address: - Structured output support (--output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs)) - --json / --jsonl short aliases for --output (no --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.) - `--raw` flag for pipe-safe unformatted output (no `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools.) Requirements: https://anc.dev/p2
- P3Progressive Help Discoveryfail
no `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text. · subcommands missing example invocations in their `--help`: check, rule, config, linter, clean, format, server, analyze, version. Examples teach agents the call shape faster than option tables; use clap's `after_help` or a dedicated `Examples:` block.
Remediation · P3Make ruff satisfy P3 (Progressive Help Discovery) from the agent-native CLI standard. Address: - `examples` subcommand or `--examples` flag for curated usage patterns (no `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text.) - Each subcommand's `--help` ships at least one invocation example (subcommands missing example invocations in their `--help`: check, rule, config, linter, clean, format, server, analyze, version. Examples teach agents the call shape faster than option tables; use clap's `after_help` or a dedicated `Examples:` block.) - Help text pairs human and `--output json` example invocations (no paired text + `--output json` example found within 5 lines in top-level or any subcommand `--help`. Pairing keeps agents from reverse-engineering the JSON invocation from the text one.) Requirements: https://anc.dev/p3
- P4Fail-Fast, Actionable Errorspass
All 3 checks pass.
- P5Safe Retries & Mutation Boundariesfail
destructive subcommand(s) without `--force` or `--yes`: clean, format. Irreversible operations must require explicit confirmation so they can't be invoked accidentally. · write-pattern subcommand(s) present (clean, format) but no read-pattern surface detected. If the CLI is write-only by design the MUST is satisfied vacuously; otherwise expose the read surface with agent-recognizable verbs (list/get/show/query/find/search).
Remediation · P5Make ruff satisfy P5 (Safe Retries & Mutation Boundaries) from the agent-native CLI standard. Address: - Destructive subcommands require `--force` or `--yes` (destructive subcommand(s) without `--force` or `--yes`: clean, format. Irreversible operations must require explicit confirmation so they can't be invoked accidentally.) - Read and write surfaces are both visible in subcommand list (write-pattern subcommand(s) present (clean, format) but no read-pattern surface detected. If the CLI is write-only by design the MUST is satisfied vacuously; otherwise expose the read surface with agent-recognizable verbs (list/get/show/query/find/search).) Requirements: https://anc.dev/p5
- P6Composable, Predictable Command Structurewarn
4/10 subcommand(s) follow standard verb names. Non-standard: check, rule, linter, format, server, analyze. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs. · input-accepting subcommand present but `--help` does not mention stdin or `-` as a path placeholder. SHOULD-tier — agents piping data into the tool expect stdin to work when no file arg is provided.
Remediation · P6Make ruff satisfy P6 (Composable, Predictable Command Structure) from the agent-native CLI standard. Address: - Subcommand verbs follow community-standard names (4/10 subcommand(s) follow standard verb names. Non-standard: check, rule, linter, format, server, analyze. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs.) - Input-accepting commands read from stdin when no file is given (input-accepting subcommand present but `--help` does not mention stdin or `-` as a path placeholder. SHOULD-tier — agents piping data into the tool expect stdin to work when no file arg is provided.) Requirements: https://anc.dev/p6
- P7Bounded, High-Signal Responsespass
All 6 checks pass.
- P8Discoverable Through Agent Skill Bundlespass
All 3 checks pass.
All Audits
P1: Non-Interactive by Default
| PASS | Non-interactive by default | |
| SKIP | Non-interactive gate flag advertised in --help | target satisfies P1 via alternative gate (help-on-bare or stdin-primary) |
| WARN | Flags advertise env-var bindings in --help | 8 flag(s) found in --help but no `[env: NAME]` bindings advertised |
| PASS | Secret-bearing flags expose stdin or *-file companion | |
| WARN | `--help` advertises default values for flags | no default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention). |
| PASS | Rich-TUI affordance for TTY contexts |
P2: Structured, Parseable Output
| WARN | Structured output support | --output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs) |
| SKIP | Structured-output CLI exposes its schema at runtime | no structured-output indicator (--output / --format / json / jsonl) in --help |
| WARN | --json / --jsonl short aliases for --output | no --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum. |
| WARN | `--raw` flag for pipe-safe unformatted output | no `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools. |
| SKIP | `--output` advertises additional formats beyond text/json | no `--output` or `--format` flag advertised; vacuous skip for MAY-tier extra formats. |
| PASS | Bad invocation exits with structured usage-error code (2) | |
| SKIP | Errors emit JSON envelope with `error`/`kind`/`message` under `--output json` | binary does not advertise `--output json` in --help; MUST applies only to CLIs that opt into the JSON contract. |
| SKIP | JSON success and error envelopes share their non-payload key set | binary does not advertise `--output json` in --help; envelope-consistency only applies to CLIs that opt into the JSON contract. |
P3: Progressive Help Discovery
| PASS | Help flag produces useful output | |
| PASS | Version flag works (`--version` plus short alias) | |
| PASS | Version flag works (`--version` plus short alias) | |
| WARN | `examples` subcommand or `--examples` flag for curated usage patterns | no `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text. |
| PASS | Short `-h` summary differs from `--help` long form | |
| FAIL | Each subcommand's `--help` ships at least one invocation example | subcommands missing example invocations in their `--help`: check, rule, config, linter, clean, format, server, analyze, version. Examples teach agents the call shape faster than option tables; use clap's `after_help` or a dedicated `Examples:` block. |
| WARN | Help text pairs human and `--output json` example invocations | no paired text + `--output json` example found within 5 lines in top-level or any subcommand `--help`. Pairing keeps agents from reverse-engineering the JSON invocation from the text one. |
P4: Fail-Fast, Actionable Errors
| PASS | Rejects invalid arguments | |
| PASS | Error messages include a hint or remediation phrase | |
| SKIP | `--output json` produces JSON-formatted errors | binary does not advertise `--output json` in --help; SHOULD applies only to CLIs that opt into the JSON contract. |
P5: Safe Retries & Mutation Boundaries
| FAIL | Destructive subcommands require `--force` or `--yes` | destructive subcommand(s) without `--force` or `--yes`: clean, format. Irreversible operations must require explicit confirmation so they can't be invoked accidentally. |
| WARN | Read and write surfaces are both visible in subcommand list | write-pattern subcommand(s) present (clean, format) but no read-pattern surface detected. If the CLI is write-only by design the MUST is satisfied vacuously; otherwise expose the read surface with agent-recognizable verbs (list/get/show/query/find/search). |
P6: Composable, Predictable Command Structure
| PASS | Handles SIGPIPE gracefully | |
| SKIP | Pager-using CLI ships --no-pager escape hatch | no pager signal (less/more/$PAGER/--pager) in --help |
| PASS | Respects NO_COLOR | |
| WARN | Subcommand verbs follow community-standard names | 4/10 subcommand(s) follow standard verb names. Non-standard: check, rule, linter, format, server, analyze. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs. |
| PASS | `--color` flag for explicit color control | |
| WARN | Input-accepting commands read from stdin when no file is given | input-accepting subcommand present but `--help` does not mention stdin or `-` as a path placeholder. SHOULD-tier — agents piping data into the tool expect stdin to work when no file arg is provided. |
| PASS | Subcommand naming follows a consistent verb/noun convention | |
| PASS | Operations are subcommands, not verb-shaped flags |
P7: Bounded, High-Signal Responses
| PASS | Quiet mode available | |
| PASS | `--verbose` flag for diagnostic escalation | |
| SKIP | `--limit` / `--max-results` flag for list operations | no list-style subcommand detected (list/ls/search/query/find/show/get); vacuous skip for the list-only SHOULD. |
| SKIP | Cursor-based pagination flags for list traversal | no list-style subcommand detected; vacuous skip for the list-only MAY. |
| SKIP | `--timeout` flag for long-running operations | no long-running subcommand detected (serve/daemon/watch/tail/monitor/follow/run/start/stream); vacuous skip for the conditional SHOULD. |
| PASS | Help text advertises TTY-aware verbosity behavior |
P8: Discoverable Through Agent Skill Bundles
| PASS | Skill bundle has install path (`tool skill install [<host>]`) | |
| PASS | `skill install --all` for multi-runtime install | |
| PASS | `skill update` / `skill upgrade` for bundle refresh |
Reproduce this scorecard for ruff locally and inspect the failing audits:
anc audit --command ruff --output jsonInstall anc first if you don't have it. Add --output json to get the same JSON shape committed under scorecards/.