Skip to content

Command Reference ​

This reference covers the project API commands available to providers and clients. Your token and project permissions govern each operation. Start with configuration.

Help and global flags ​

bash
galileo --help
galileo assets service --help
galileo --no-update --no-skills-update projects list
FlagMeaning
--help, -hShow command help.
--profile NAMEUse a named profile for this invocation. One profile is enough for the standard setup.
--no-updateSkip the automatic binary update.
--no-skills-updateSkip refresh of installed Claude Code files.

Use the project identifier from projects list. Project-scoped commands accept --project / -p or the saved default. Exception: projects create -p selects the platform, not a project.

Version and update ​

bash
galileo version
galileo update

version prints the installed version; it may report a newer available release. update updates only the binary and ignores automatic-update opt-outs.

Configuration commands ​

bash
galileo config set ./config.toml
galileo config profile list
galileo config profile default
galileo config profile default hashiro
galileo config profile default --unset
galileo config proxy set http://127.0.0.1:8080
galileo config proxy unset

config set copies a TOML file; it does not accept key/value pairs. Create the standard config first. profile default shows the current profile with no argument and changes it when given a name. --unset clears its default marker; the first profile is then used.

Project examples ​

bash
galileo projects create my-project --platform pentest --tag owner=security
galileo projects list --all
galileo projects default my-project
galileo projects inscope --project my-project --type domain example.com
galileo projects outscope --project my-project --type domain excluded.example.com
galileo projects inscope --project my-project
galileo projects inscope --project my-project --rm example.com

Project aliases: project, program, programs, p. list also accepts ls / l; create accepts c / add; remove accepts rm / r. Quote wildcard scope values to prevent shell expansion.

Narrative, credentials, context, and chains ​

bash
galileo projects narrative --project my-project
galileo projects narrative --project my-project < narrative.md
galileo projects context --project my-project < context.md
galileo projects credentials --project my-project < credentials.md
galileo projects chains --project my-project

No content reads the current Markdown field; arguments or stdin replace it. chains is read-only. These operations do not grant a client edit access to a provider-managed project.

Asset, URL, and service examples ​

bash
galileo assets insert --project my-project app.example.com
galileo assets list --project my-project --unavailable --show-status-code
galileo assets view --project my-project app.example.com
galileo assets path --project my-project --add https://app.example.com/health
galileo assets path --project my-project https://app.example.com
galileo assets service --project my-project --asset app.example.com
galileo assets service --project my-project --json
galileo assets service --project my-project --add --asset app.example.com --port 443 --protocol tcp --state open

Asset aliases: asset, domain, domains. path also accepts paths / dir; service accepts services. Asset names are positional for insert/view/remove. There is no assets insert --asset flag or assets path --path flag.

Finding examples ​

bash
galileo scan add --project my-project --asset app.example.com --title "Missing security header" --severity low --description "Observed during review" --remediation "Configure the required header"
galileo scan list --project my-project --info
galileo scan list --project my-project --id FINDING_ID
galileo scan list --project my-project --json

Finding aliases: scans, issue, issues. Use scan list --id to view a finding; there is no scan view command. scan add --raw accepts one JSON finding object through stdin. --requests-file accepts a JSON array of request/response pairs, such as [["request text","response text"]].

Templates and imports ​

bash
galileo templates list --verbose
galileo templates view TEMPLATE_CODE_OR_ID
galileo import hackerone
galileo import intigriti

Template aliases: template, t. view accepts show. Imports use separate platform credentials described in Imports.

Notifications ​

bash
galileo notify FINDING_ID --discord

Configure [discord] with channel and token. Pass finding IDs as arguments or lines on stdin. The implementation uses those IDs; --id is not consumed. Slack sending is not implemented despite its visible flag.

Optional Claude Code files ​

bash
galileo gen-skills ./claude-config

Writes a marked section in CLAUDE.md and slash-command files in commands/. The default directory is ~/.claude. This changes local files; --no-skills-update prevents automatic refresh on later commands.

Command and flag tables ​

Flags below are grouped by command. Repeatable string-array flags accept separate occurrences, such as --tag owner=security --tag env=test. Integer flags accept numbers; boolean flags can be explicitly set to false.

galileo projects create NAME ​

Create a project. NAME is positional; -p means platform here.

FlagDescription
--platform VALUE / -pSpecify the project platform (intigriti, bugcrowd, hackerone, pentest...)
--inactive / -iSpecify ito create project as inactive
--type VALUESpecify the project type, like private or public (specific to bug bounty)
--tag VALUE / -tAdd tags to the project (multiple key=value pairs can be provided)
--rawRead project as raw JSON from stdin

galileo projects list ​

List authorized projects.

FlagDescription
--all / -aShow all projects, including inactive ones
--inactive / -iOnly show inactive projects
--tag VALUE / -tShow only projects that contain certain tag
--value VALUE / -vShow only projects that contain a specific tag and value (must be used with -t)

galileo projects remove NAME ​

Delete a project after confirmation.

FlagDescription
--yes / -ySkip confirmation prompt

galileo projects default [NAME] ​

Read or set the saved default project.

FlagDescription
--unsetUnset the default project

galileo projects inscope [TARGET...] ​

Read, add, or remove in-scope entries.

FlagDescription
--project VALUE / -pSpecify project to add asset to scope
--rm / -rRemove asset from inscope
--bounty VALUE / -bSpecify if asset is elegible to bounty
--type VALUESpecify asset type (domain / subdomain / android / ios / source / other)
--wildcard / -wShow only wildcard domains
--domains / -dShow only wildcard domains
--tier VALUESpecify asset tier (numeric value)
--issues VALUE / -iSpecify asset number of known issues
--tag VALUE / -tAdd tags to the asset (multiple key=value pairs can be provided)

galileo projects outscope [TARGET...] ​

Read, add, or remove exclusions.

FlagDescription
--project VALUE / -pSpecify project to add asset to out of scope
--bounty VALUE / -bSpecify if asset is elegible to bounty
--rm / -rRemove asset from out of scope
--type VALUESpecify asset type (domain / subdomain / android / ios / source / other)
--wildcard / -wShow only wildcard domains
--domains / -dShow only wildcard domains
--tier VALUESpecify asset tier (numeric value)
--issues VALUE / -iSpecify asset number of known issues
--tag VALUE / -tAdd tags to the asset (multiple key=value pairs can be provided)

galileo assets insert HOST... ​

Insert hostnames from arguments or stdin.

FlagDescription
--project VALUE / -pSpecify project to add asset
--httpxAutomatically perform httpx
--screenshot / -sTake screenshot with HTTPX
--tag VALUE / -tAdd tags to the asset (multiple key=value pairs can be provided)
--ipaddress VALUE / -iIP Addresses available to that asset
--available / -aIf the asset is available (false by default!)
--scheme VALUESpecify asset protocol
--port VALUEPort of the available address
--title VALUESpecify page title probe
--status-code VALUESpecify status code probe
--content-length VALUESpecify status code probe
--favicon VALUESpecify favicon hash probe
--lines VALUESpecify lines count probe
--words VALUESpecify words count probe
--location VALUESpecify location header probe
--webserver VALUESpecify server header probe
--body VALUESpecify body hash probe
--jarm VALUESpecify JARM hash probe
--b64screenshot VALUESpecify base64 screenshot probe
--cdn VALUESpecify CDN probe
--header VALUEAdd response headers (multiple key=value pairs can be provided)
--wappalyzer VALUESpecify wappalyzer probe

galileo assets list ​

List available assets; include unavailable assets with --unavailable.

FlagDescription
--project VALUE / -pSpecify project to list assets
--domains / -dSpecify project to list only assets subdomains
--unavailable / -uGet unavailable projects as well
--show-wappalyzerShow wappalyzer technologies beside each asset
--show-status-codeShow HTTP status code beside each asset
--show-titleShow page title beside each asset

galileo assets view HOST ​

Show an asset and its available screenshot.

FlagDescription
--project VALUE / -pSpecify project to list assets

galileo assets remove HOST... ​

Remove selected assets; --all removes every asset in the selected project.

FlagDescription
--project VALUE / -pSpecify project to remove asset
--allRemove all assets
--yes / -ySkip confirmation prompt

galileo assets path [URL...] ​

List paths by default; use --add, --rm, or --rm-all to change them. Pass full URLs.

FlagDescription
--project VALUE / -pSpecify project to list assets
--addAdd path's to the asset
--rmRemove path's to the asset
--rm-allRemove all asset paths
--httpxAutomatically perform httpx
--source VALUE / -sSpecify source from this path. (e.g.: ffuf)
--tag VALUE / -tAdd tags to the asset (multiple key=value pairs can be provided)
--title VALUESpecify page title probe
--status-code VALUESpecify status code probe
--content-length VALUESpecify status code probe
--favicon VALUESpecify favicon hash probe
--lines VALUESpecify lines count probe
--words VALUESpecify words count probe
--location VALUESpecify location header probe
--webserver VALUESpecify server header probe
--body VALUESpecify body hash probe
--jarm VALUESpecify JARM hash probe
--b64screenshot VALUESpecify base64 screenshot probe
--cdn VALUESpecify CDN probe
--header VALUEAdd response headers (multiple key=value pairs can be provided)
--wappalyzer VALUESpecify wappalyzer probe

galileo assets service [HOST] ​

List recorded services; --add writes a service record. This command does not perform a port scan.

FlagDescription
--project VALUE / -pSpecify project to list assets
--asset VALUE / -aSpecify asset to list services
--addAdd service to the asset
--list / -lList services (default when no other action specified)
--port VALUEPort of the available address
--protocol VALUESpecify protocol of the available address
--banner VALUESpecify service banner/description
--state VALUESpecify port state: open, closed, filtered
--script VALUE / -sAdd scripts to the asset
--tag VALUE / -tAdd tags to the asset (multiple key=value pairs can be provided)
--hostsShow all alive hosts
--servicesShow services in hostname:port service format
--service VALUEFilter by service name
--portsShow consolidated list of open ports
--port-filter VALUEFilter by port(s) (comma-separated)
--jsonOutput in JSON format
--csvOutput in CSV format

galileo scan add ​

Create a finding using flags or one JSON object on stdin with --raw.

FlagDescription
--project VALUE / -pSpecify project to add scan
--notifyAuto notify vulnerabilities when adding them
--severity VALUESpecify scan severity (default unknown)
--asset VALUEAffected asset in the issue
--title VALUEScan result title
--description VALUEScan result description
--notifiedMark if it was already notified (default false)
--fpMark if it was a false positive (default false)
--source VALUEScan result source
--cve VALUEInform issue CVE
--reference VALUEAdd references to the scan
--tag VALUEAdd tags to the scan (key=value pairs)
--template VALUEScan template identifier
--demonstration VALUESteps to demonstrate the finding
--observation VALUEObservation / context
--type VALUEScan type (e.g. vulnerability type)
--category VALUEScan category
--remediation VALUERemediation guidance
--retest-demonstration VALUESteps for retest demonstration
--requests-file VALUEPath to JSON file with request/response pairs: [["req","resp"],...]
--rawRead scan as raw JSON from stdin and send to server (project via -p)

galileo scan list ​

List findings; --id selects one finding and --json produces structured output.

FlagDescription
--project VALUE / -pSpecify project to list scans
--title VALUEShow scans by title
--id VALUEShow scan result from specific id
--asset VALUEFilter by asset
--severity VALUESpecify severity to view scans
--infoInclude informative severity in list
--jsonOutput findings as a JSON array (id/title/asset/severity/scope/status/source)

galileo scan remove ID... ​

Delete finding IDs passed as arguments or stdin.

FlagDescription
--project VALUE / -pSpecify project
--yes / -ySkip confirmation prompt

galileo templates list ​

List vulnerability templates available to your account.

FlagDescription
--verbose / -vShow template details (type, category, CVSS)

galileo templates view CODE_OR_ID ​

View a template by code or ID.

galileo notify ID... ​

Notify findings by ID through Discord. Slack is not implemented.

FlagDescription
--slackNotify scan on slack
--discordNotify scan on discord
--id VALUEScan ID to notify

Inputs, outputs, and errors ​

Text commands accept newline-delimited stdin where described. --raw expects one JSON object, not an array. Use scan list --json and assets service --json for structured output. Do not assume all output is JSON or every validation error yields a nonzero exit code; inspect error messages. Deletions prompt for confirmation unless --yes is used. Check the project and IDs before bulk actions.

Hashiro. Continuous Threat Exposure Management.