Skip to main content

Knox CLI Reference

The Knox CLI is the command-line interface that ships with the Knox Claude Code Plugin. After Knox is installed, use the CLI as:
It is mainly used for visibility, testing, policy review, local developer workflow, and audit review. For Claude Code hook enforcement, install Knox through the Claude Code plugin marketplace:
See the Knox Claude Code Plugin page for the full install flow, local development fallback, and plugin behavior. There is no uvx install path for Knox. Development builds can run the CLI from the plugin repo with node bin/knox <command>. The CLI does not replace hooks. Hooks are what intercept Claude Code actions before and after execution. The CLI lets developers inspect status, test policy decisions, review audit logs, export policy, and manage local rules. See Knox Hooks and Events for the hook execution model.

Status

Show the active preset, audit path, denial counts, webhook status, and disabled checks.
Use this first when verifying that Knox is installed and active.

Test A Command

Dry-run a command against the active policy.
Possible outcomes:
  • allow
  • sanitize
  • block
This is the fastest way to check how Knox would treat an action.

Verify

Run built-in safety test vectors.
Use this after install, upgrade, or policy changes.

Audit

Review recent audit log entries.
Audit is useful for:
  • seeing what the agent attempted
  • explaining why an action was blocked
  • reviewing tool usage after a session
  • collecting product screenshots for the Developer Safety Pack

Report

Summarize Knox activity over a time window.
Reports include total events, denials, allow rate, and top blocked rules.

Policy List

Show active policy rules.

Export Policy

Export readable policy for docs, review, or security teams.

List Check Categories

Show toggleable check categories.
Examples of check categories:
  • read path protection
  • write path protection
  • script inspection
  • MCP inspection
  • sudo sanitization
  • injection detection
  • cron inspection
  • escalation tracking
Core blocklist and self-protection checks are not meant to be disabled.

Add A Custom Block Rule

Add a local custom block rule.
Example:

Add A Custom Allow Rule

Add a local custom allow rule.
Custom allow rules cannot override core dangerous blocklist behavior.

Add An Allowed Package

Allow a package name in local policy.
Use this when a package is expected in the project and should not be treated as suspicious by package-related checks.

Remove A Custom Rule

Remove a custom policy entry by id or label.

Lint Policy

Validate a Knox policy file.

Disable Or Enable A Check

Disable a check category locally:
Disable a check at the project level:
Re-enable a check:
Use disable operations carefully. They are intended for development/debugging, not as a default team posture.

Install Or Uninstall Hooks

Wire Knox hooks into Claude Code settings:
Remove Knox hook entries:

Upgrade

Upgrade the installed plugin.

Common Developer Flow