Skip to main content

CLI reference

One binary, one command surface. Run lumen-agent <command> -h for the full flag list of any command.

CommandWhat it does
runStart the daemon: loopback inspection API, and the capturing proxy when the config enables it
statusWhat this machine's agent is doing: daemon, policy (with the console's enforcement ceiling), inactive rules, hooks, routed tooling, spool, last heartbeat, findings uplink health
disable and enableThe machine-wide off switch, which needs root. See Service lifecycle
enrollExchange an enrollment token for the per-device cloud credential. run does this itself on startup, so this is the manual or MDM flow
inspectOne-shot inspection from the CLI
policyvalidate | init | show | effective a policy file
intelcompile | check a threat-intel snapshot
classifiershow | score | train | eval the toxicity and topic models
mcpWrap a stdio MCP server behind the policy engine
nmNative-messaging host for the browser extension. nm install registers it for each browser (the manifests, and on Windows the registry keys that point at them; --system for every user of the machine), nm uninstall removes it (--only-published only when it allows nothing but the published builds, which is how the installers clean up)
proxyThe local LLM API proxy, standalone
autoconfigstatus | apply | revert. Discover the AI tooling on this machine and point it at the proxy
hookClaude Code hook guard: reads a hook event on stdin, answers with the policy decision
servicegenerate | install | uninstall the OS service. Uninstall also un-routes what autoconfig redirected
upgradeReplace this binary with a released version from the CDN, with --check, --to vX.Y.Z or --rollback
versionPrint the version

The ones you will use daily​

inspect, a verdict in one shot​

lumen-agent inspect --text "the key is AKIAIOSFODNN7EXAMPLE"
lumen-agent inspect --stage output --intel feed.bloom --text "reset at https://sec-reset-login.example"
lumen-agent inspect --policy demo-policy.yaml --context '{"device":{"managed":false}}' --text "..."

--stage selects prompt rules with input, the default, or response rules with output. --policy points at a policy file, and the CLI default is the built-in policy, which only logs: it reports what matched and answers action: log. To see a redaction or a block, write the default out with lumen-agent policy init --out enforcing.yaml, change the rules' action: from log to redact or block, and pass --policy enforcing.yaml. --context feeds the access-rule engine. A block exits with code 2.

A policy from the console works as it is: Copy as JSON or Download on any policy, or on a draft in the builder, gives a JSON file, and JSON is a valid policy file. Downloading Recommended enforcing is the quickest way to an enforcing policy here, and a draft can be checked with lumen-agent policy validate --policy <file> and tried with inspect --policy <file> before it is saved. See Testing a policy before you assign it.

status, the whole picture in one screen​

lumen-agent status # exit 0 answered, 3 daemon down, 1 no report
lumen-agent status --json | jq '.warnings'

Run it as the developer whose tooling you are asking about. Hook and routed-tooling reporting is per-user. Under sudo the report resolves the human from SUDO_USER, the same way service uninstall does.

policy effective, what is actually in force​

lumen-agent policy validate --policy /etc/lumen/policy.yaml
lumen-agent policy effective --config /etc/lumen/agent.yaml

effective resolves agent.policy exactly the way run does, so it cannot report something the daemon does not run. --json prints the same thing machine-readably.

intel compile, threat-intel snapshots​

lumen-agent intel compile --list feed.txt --out feed.bloom

Compiles an entity list into the memory-mapped bloom filter the malicious-entity detector tests against. An exact list can block. A bloom candidate only logs.