CLI reference
One binary, one command surface. Run lumen-agent <command> -h for the full
flag list of any command.
| Command | What it does |
|---|---|
run | Start the daemon: loopback inspection API, and the capturing proxy when the config enables it |
status | What this machine's agent is doing: daemon, policy (with the console's enforcement ceiling), inactive rules, hooks, routed tooling, spool, last heartbeat, findings uplink health |
disable and enable | The machine-wide off switch, which needs root. See Service lifecycle |
enroll | Exchange an enrollment token for the per-device cloud credential. run does this itself on startup, so this is the manual or MDM flow |
inspect | One-shot inspection from the CLI |
policy | validate | init | show | effective a policy file |
intel | compile | check a threat-intel snapshot |
classifier | show | score | train | eval the toxicity and topic models |
mcp | Wrap a stdio MCP server behind the policy engine |
nm | Native-messaging host for the browser extension. nm install registers it for each browser (the manifests, and on Windows the registry keys that point at them; --system for every user of the machine), nm uninstall removes it (--only-published only when it allows nothing but the published builds, which is how the installers clean up) |
proxy | The local LLM API proxy, standalone |
autoconfig | status | apply | revert. Discover the AI tooling on this machine and point it at the proxy |
hook | Claude Code hook guard: reads a hook event on stdin, answers with the policy decision |
service | generate | install | uninstall the OS service. Uninstall also un-routes what autoconfig redirected |
upgrade | Replace this binary with a released version from the CDN, with --check, --to vX.Y.Z or --rollback |
version | Print the version |
The ones you will use daily
inspect, a verdict in one shot
lumen-agent inspect --text "the key is AKIAIOSFODNN7EXAMPLE"
lumen-agent inspect --stage output --intel feed.bloom --text "reset at https://sec-reset-login.example"
lumen-agent inspect --policy demo-policy.yaml --context '{"device":{"managed":false}}' --text "..."
--stage selects prompt rules with input, the default, or response rules
with output. --policy points at a policy file, and the CLI default is the
built-in policy, which only logs: it reports what matched and answers
action: log. To see a redaction or a block, write the default out with
lumen-agent policy init --out enforcing.yaml, change the rules' action:
from log to redact or block, and pass --policy enforcing.yaml.
--context feeds the access-rule engine. A block exits with code 2.
A policy from the console works as it is: Copy as JSON or Download on
any policy, or on a draft in the builder, gives a JSON file, and JSON is a valid
policy file. Downloading Recommended enforcing is the quickest way to an
enforcing policy here, and a draft can be checked with lumen-agent policy validate --policy <file> and tried with inspect --policy <file> before it is
saved. See Testing a policy before you assign it.
status, the whole picture in one screen
lumen-agent status # exit 0 answered, 3 daemon down, 1 no report
lumen-agent status --json | jq '.warnings'
Run it as the developer whose tooling you are asking about. Hook and
routed-tooling reporting is per-user. Under sudo the report resolves the
human from SUDO_USER, the same way service uninstall does.
policy effective, what is actually in force
lumen-agent policy validate --policy /etc/lumen/policy.yaml
lumen-agent policy effective --config /etc/lumen/agent.yaml
effective resolves agent.policy exactly the way run does, so it cannot
report something the daemon does not run. --json prints the same thing
machine-readably.
intel compile, threat-intel snapshots
lumen-agent intel compile --list feed.txt --out feed.bloom
Compiles an entity list into the memory-mapped bloom filter the malicious-entity detector tests against. An exact list can block. A bloom candidate only logs.