Knox CLI Reference
The Knox CLI is the command-line interface that ships with the Knox Claude Code Plugin. After Knox is installed, use the CLI as:uvx install path for Knox. Development builds can run the CLI from the plugin repo with node bin/knox <command>.
The CLI does not replace hooks. Hooks are what intercept Claude Code actions before and after execution. The CLI lets developers inspect status, test policy decisions, review audit logs, export policy, and manage local rules. See Knox Hooks and Events for the hook execution model.
Status
Show the active preset, audit path, denial counts, webhook status, and disabled checks.Test A Command
Dry-run a command against the active policy.- allow
- sanitize
- block
Verify
Run built-in safety test vectors.Audit
Review recent audit log entries.- seeing what the agent attempted
- explaining why an action was blocked
- reviewing tool usage after a session
- collecting product screenshots for the Developer Safety Pack
Report
Summarize Knox activity over a time window.Policy List
Show active policy rules.Export Policy
Export readable policy for docs, review, or security teams.List Check Categories
Show toggleable check categories.- read path protection
- write path protection
- script inspection
- MCP inspection
- sudo sanitization
- injection detection
- cron inspection
- escalation tracking
