Skip to main content

Skip docs navigation
manual page/ Reference

The Suspec CLI

sourceSource: suspec/docs/reference/cli.mdModified: 2026-08-26

suspec-cli (opens in new tab) owns two isolated surfaces.

  • suspec check is a read-only deterministic checker. Facts in, diagnostics out. It runs no model or verification command, writes nothing, discovers no repository or artifact store, and renders no acceptance decision.
  • suspec setup previews, installs, checks, or removes the canonical user-level agent policy for explicit Codex, Claude Code, Kimi Code, ZCode, OpenCode, Cursor, or Antigravity targets. It owns only a neutral inline block in each normal native instruction file. Drift or ambiguous configuration blocks mutation.

The CLI repository owns commands, options, companions, path handling, output, exits, installation, and runtime behavior. See its public contract (opens in new tab).

Canon owns check meaning:

The checker must match the checks contract. Generated policy bytes match canon (opens in new tab); installed blocks differ only by target line endings and terminal-newline normalization. A parser is not a manager.

Need a starting point? Install the skills