Everything the platform does, from a terminal — plus orithos skill scan, an offline vetting pass for agent skills, plugins, and MCP packages that needs no account and makes zero outbound calls.
pip install orithos-cli orithos configure # or set ORITHOS_API_KEY + ORITHOS_API_URL
Environment variables override the config file: ORITHOS_API_KEY, ORITHOS_API_URL, ORITHOS_ORG_ID, ORITHOS_TIMEOUT.
Static analysis for skills, plugins, and MCP packages — seven check classes covering manifest hygiene, declared-vs-implied permissions, exfiltration-prone endpoints, shell and install hooks, credential access, obfuscation, and known-bad signatures. Every finding cites file, line, and evidence.
orithos skill scan ./my-skill orithos skill scan https://example.com/plugin.zip --format sarif --fail-on medium
--fail-on (default high) · 2 error. Formats: text, json, sarif.orithos scan run --agent-id <AGENT_ID> orithos scan status <SCAN_ID> orithos scan findings <SCAN_ID> --format sarif # summary | json | sarif | junit
Evidence packages are independently verifiable: the CLI recomputes every artifact hash and the Merkle root and compares them against the sealed manifest — no network access, no Orithos contact.
orithos verify evidence-package.json
orithos agent · mcp · compliance · connection · discovery · graph · guardrail · probes · remediation · runtime
skill scan.