CLI Scanner
The scanner is not installable today. @controlzero/scanner has never been
published, to the Control Zero registry or to npmjs.org, so every npx command
below fails with E404 Not Found until it ships:
npm error code E404
npm error 404 Not Found - GET https://npm.controlzero.ai/@controlzero%2fscanner
npm error 404 '@controlzero/scanner@*' is not in this registry.
This page documents the interface implemented in the scanner source. What is missing is distribution: no runnable package has been published. Do not add these commands to a CI pipeline yet — they will fail the build.
The Control Zero CLI scanner analyzes your codebase and identifies AI tool calls that lack governance. It produces a governance grade and actionable findings you can address before shipping.
What It Does
The scanner statically analyzes your project to find:
- AI tool calls that are not wrapped by a Control Zero SDK client
- MCP tool invocations without policy enforcement
- Direct API calls to LLM providers that bypass governance
- Missing or misconfigured policy bundles
Planned usage
Once a package is published, no installation will be required — it runs directly with npx. Configure the Control Zero registry once: add @controlzero:registry=https://npm.controlzero.ai to your .npmrc (or run npm config set @controlzero:registry https://npm.controlzero.ai). It applies to npm install and npx for the whole @controlzero scope.
npx @controlzero/scanner
The scanner auto-detects your project structure and scans all relevant source files.