DEVELOPER DOCS

SDK

The opexia CLI

On this page

Installed with the package as the opexia console script.

code
usage: opexia <command> [options]

commands:
  shipcheck    pre-merge check for prompt/model/config changes (no LLM, no re-run)
  audit        local, zero-egress security audit + relational map of an agentic app
  live         live terminal dashboard of pxcore token/$ savings (local, zero-egress)

Run `opexia <command> --help` for its options.

opexia shipcheck

A pre-merge gate for prompt, model, and config changes. Runs no LLM and re-runs nothing — it compares the candidate against recorded baseline telemetry, so it is fast and deterministic enough for every pull request.

Shell
opexia shipcheck --help

Policy is read from .opexia/shipcheck.yml (needs the shipcheck extra for YAML) or an equivalent JSON file, which needs no extra.

YAML
# .opexia/shipcheck.yml
gates:
  cost_increase_pct: 15        # fail if projected cost rises more than 15%
  latency_increase_pct: 20
  grade_regression: true       # fail on any reliability grade regression

GitHub Actions:

YAML
name: Ship Check
on: pull_request

jobs:
  shipcheck:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with: { python-version: "3.12" }
      - run: pip install 'opexia-trace[shipcheck]'
      - run: opexia shipcheck
        env:
          OPEXIA_API_KEY: ${{ secrets.OPEXIA_API_KEY }}

Ship Check's Gate 3 runs opexia audit automatically — see below.

The underlying REST endpoint is POST /v1/observ/shipcheck/candidate.

opexia audit

A local security audit and relational map of an agentic application.

100% local, zero egress. No network call, no LLM call, no process spawned — and nothing it finds ever leaves the machine. Findings are a disclosure, so they must not travel.

Shell
opexia audit --help
opexia audit --tree          # terminal tree instead of the HTML map

It reads the repo's declarations — .mcp.json and other MCP configs, .claude/agents, skills, hooks, in-code tool definitions — reconstructs the agent topology plus a relational layer (capabilities, datastores, external endpoints, secrets by name), and audits it against the NSA MCP Security Design Considerations CSI.

What it checks:

  • Tool-description injection, including hidden Unicode
  • Blanket OAuth scopes
  • Unpinned npx / uvx boot-time code execution
  • Shell-spawning servers
  • Tool-name collisions
  • Cleartext credentials — shape only, the value is never emitted
  • Source → sink exfiltration paths

The headline output is .opexia/agentmap.lock — commit it. It turns a silent capability change (a "rug pull") into a reviewable diff in a pull request.

It also renders a self-contained local HTML map that loads nothing from the network.

When run inside shipcheck, only the verdict and finding categories reach the shared PR comment. Evidence stays on stdout and in the local run.

opexia live

A live terminal dashboard of pxcore token and dollar savings. Local and zero-egress by default, with an opt-in backend plane.

Shell
pip install 'opexia-trace[live]'
opexia live

Requires the live extra (rich). Falls back to ASCII on terminals without Unicode box-drawing support.