CLI Reference

Complete reference for every nitpik command and flag.


Global Flags

These flags apply to all subcommands:

FlagDescription
--no-telemetryDisable anonymous usage telemetry for this run.
--versionPrint version string and exit.
--helpPrint help for the current command.

nitpik review

Run a code review.

Input Flags (exactly one required)

FlagDefaultDescription
--diff-base <REF>—Branch, tag, or commit to diff against using git diff.
--diff-file <PATH>—Pre-computed unified diff file.
--diff-stdinfalseRead unified diff from stdin.
--scan <PATH>—Review a file or directory directly (no git required).

Repository

FlagDefaultDescription
--path <DIR>.Repository or working directory path.

Profile Selection

FlagDefaultDescription
--profile <NAMES>autoComma-separated list of profile names, file paths, or auto. Built-in: backend, frontend, architect, security, general. The default auto picks reviewers from the diff via heuristics — see --auto-mode.
--profile-dir <DIR>—Directory to resolve bare profile names from.
--tag <TAGS>—Comma-separated tags. All profiles (built-in and custom) whose tags match are included. Combines with --profile.
--auto-mode <MODE>hybridHow --profile auto picks reviewers: heuristic (rules only, no LLM call), llm (always ask the model), hybrid (heuristics first, fall back to LLM when inconclusive).
--multi-wavefalseRun reviewers in waves. Profiles whose frontmatter declares wave: 2 run after wave 1 and receive the wave-1 findings as context. Capped at 2 waves.

Output

FlagDefaultDescription
--format <FORMAT>terminalOutput format: terminal, json, github, gitlab, bitbucket, checkstyle, forgejo.
--fail-on <SEVERITY>errorExit non-zero if any finding meets this severity: error, warning, info.
--no-failfalseNever exit non-zero on findings, even when --fail-on or config is set.
-q, --quietfalseSuppress banner, progress display, and informational messages. Only findings and errors are shown.
--no-tokensfalseSuppress the per-run token usage summary printed after the review. Only affects terminal output.

Verification

FlagDefaultDescription
--verifyfalseRun a critic pass after the main review that votes keep/drop on each finding to suppress probable false positives. Adds one extra LLM call per run with findings.
--show-droppedfalsePrint findings the critic dropped (with rationale) to stderr. No effect without --verify.

Agentic Mode

FlagDefaultDescription
--agentfalseEnable agentic mode — lets the LLM use tools to explore the codebase.
--max-turns <N>10Max LLM round-trips (tool call → response) per file×agent task.
--max-tool-calls <N>10Max tool invocations per file×agent task.

Secret Scanning

FlagDefaultDescription
--scan-secretsfalseEnable secret detection and redaction before LLM calls.
--secrets-rules <PATH>—Additional gitleaks-format TOML rules file.
--secrets-severity <LEVEL>warningSeverity level for detected secrets (error, warning, or info). Set error to block merges on secrets; set info for legacy codebases.

Threat Scanning

FlagDefaultDescription
--scan-threatsfalseEnable threat pattern detection (obfuscation, dangerous APIs, supply chain, backdoors) with optional LLM triage.
--threat-rules <PATH>—Additional threat rules file (TOML format). Loaded alongside the 44 built-in rules.

Caching

FlagDefaultDescription
--no-cachefalseDisable result caching. Every file is re-reviewed.
--no-prior-contextfalseSkip injecting previous findings into the prompt on cache invalidation.
--max-prior-findings <N>unlimitedCap the number of prior findings included in the prompt.

Context

FlagDefaultDescription
--no-project-docsfalseSkip auto-detected project documentation files.
--exclude-doc <NAMES>—Comma-separated filenames to exclude from project docs (e.g. AGENTS.md,CONTRIBUTING.md).
--no-commit-contextfalseSkip injecting commit summaries into the review prompt. Only affects --diff-base mode.

Performance

FlagDefaultDescription
--max-concurrent <N>5Max concurrent LLM calls.
--timeout <SECONDS>300Per-attempt timeout for each file × agent review call (wraps the whole agentic loop, including all turns and tool roundtrips). On timeout the call is treated as a retryable error; each retry gets a fresh budget. Set to 0 to disable.

Audit Log

FlagDefaultDescription
--audit-log <PATH>—Write a structured JSON audit log to PATH after the run. Records per-task status, tool calls, retries, token usage, critic decisions, and final findings. Useful as a CI build artifact for after-the-fact debugging. Also configurable via NITPIK_AUDIT_LOG env var or [review].audit_log in .nitpik.toml.

nitpik profiles

List all available profiles (built-in and custom).

FlagDescription
--profile-dir <DIR>Directory to scan for additional custom profiles.

nitpik validate <FILE>

Validate a custom agent profile definition. Checks YAML frontmatter structure, required fields, and tool definitions.

Argument: path to the profile Markdown file.


nitpik cache

Manage the result cache.

Subcommands

SubcommandDescription
nitpik cache clearRemove all cached review results and sidecar metadata.
nitpik cache statsShow cache entry count and total size.
nitpik cache pathPrint the cache directory path.

nitpik license

Manage the commercial license key.

Subcommands

SubcommandDescription
nitpik license activate <KEY>Store a license key in ~/.config/nitpik/config.toml.
nitpik license statusShow current license status (customer, expiry).
nitpik license deactivateRemove the license key from global config.

nitpik update

Update nitpik to the latest release from GitHub.

FlagDescription
--forceRe-download even if already on the latest version.

Downloads the release archive for your platform, verifies its SHA256 checksum, and atomically replaces the running binary.


nitpik version

Print detailed build metadata: version, git commit, build date, and target triple.

nitpik 0.2.0
commit:     a1b2c3d
built:      2026-02-14
target:     x86_64-unknown-linux-gnu

Contact Us

Have a question or feedback? Send us a message and we'll get back to you.