Command Reference
This reference covers the project API commands available to providers and clients. Your token and project permissions govern each operation. Start with configuration.
Help and global flags
galileo --help
galileo assets service --help
galileo --no-update --no-skills-update projects list| Flag | Meaning |
|---|---|
--help, -h | Show command help. |
--profile NAME | Use a named profile for this invocation. One profile is enough for the standard setup. |
--no-update | Skip the automatic binary update. |
--no-skills-update | Skip refresh of installed Claude Code files. |
Use the project identifier from projects list. Project-scoped commands accept --project / -p or the saved default. Exception: projects create -p selects the platform, not a project.
Version and update
galileo version
galileo updateversion prints the installed version; it may report a newer available release. update updates only the binary and ignores automatic-update opt-outs.
Configuration commands
galileo config set ./config.toml
galileo config profile list
galileo config profile default
galileo config profile default hashiro
galileo config profile default --unset
galileo config proxy set http://127.0.0.1:8080
galileo config proxy unsetconfig set copies a TOML file; it does not accept key/value pairs. Create the standard config first. profile default shows the current profile with no argument and changes it when given a name. --unset clears its default marker; the first profile is then used.
Project examples
galileo projects create my-project --platform pentest --tag owner=security
galileo projects list --all
galileo projects default my-project
galileo projects inscope --project my-project --type domain example.com
galileo projects outscope --project my-project --type domain excluded.example.com
galileo projects inscope --project my-project
galileo projects inscope --project my-project --rm example.comProject aliases: project, program, programs, p. list also accepts ls / l; create accepts c / add; remove accepts rm / r. Quote wildcard scope values to prevent shell expansion.
Narrative, credentials, context, and chains
galileo projects narrative --project my-project
galileo projects narrative --project my-project < narrative.md
galileo projects context --project my-project < context.md
galileo projects credentials --project my-project < credentials.md
galileo projects chains --project my-projectNo content reads the current Markdown field; arguments or stdin replace it. chains is read-only. These operations do not grant a client edit access to a provider-managed project.
Asset, URL, and service examples
galileo assets insert --project my-project app.example.com
galileo assets list --project my-project --unavailable --show-status-code
galileo assets view --project my-project app.example.com
galileo assets path --project my-project --add https://app.example.com/health
galileo assets path --project my-project https://app.example.com
galileo assets service --project my-project --asset app.example.com
galileo assets service --project my-project --json
galileo assets service --project my-project --add --asset app.example.com --port 443 --protocol tcp --state openAsset aliases: asset, domain, domains. path also accepts paths / dir; service accepts services. Asset names are positional for insert/view/remove. There is no assets insert --asset flag or assets path --path flag.
Finding examples
galileo scan add --project my-project --asset app.example.com --title "Missing security header" --severity low --description "Observed during review" --remediation "Configure the required header"
galileo scan list --project my-project --info
galileo scan list --project my-project --id FINDING_ID
galileo scan list --project my-project --jsonFinding aliases: scans, issue, issues. Use scan list --id to view a finding; there is no scan view command. scan add --raw accepts one JSON finding object through stdin. --requests-file accepts a JSON array of request/response pairs, such as [["request text","response text"]].
Templates and imports
galileo templates list --verbose
galileo templates view TEMPLATE_CODE_OR_ID
galileo import hackerone
galileo import intigritiTemplate aliases: template, t. view accepts show. Imports use separate platform credentials described in Imports.
Notifications
galileo notify FINDING_ID --discordConfigure [discord] with channel and token. Pass finding IDs as arguments or lines on stdin. The implementation uses those IDs; --id is not consumed. Slack sending is not implemented despite its visible flag.
Optional Claude Code files
galileo gen-skills ./claude-configWrites a marked section in CLAUDE.md and slash-command files in commands/. The default directory is ~/.claude. This changes local files; --no-skills-update prevents automatic refresh on later commands.
Command and flag tables
Flags below are grouped by command. Repeatable string-array flags accept separate occurrences, such as --tag owner=security --tag env=test. Integer flags accept numbers; boolean flags can be explicitly set to false.
galileo projects create NAME
Create a project. NAME is positional; -p means platform here.
| Flag | Description |
|---|---|
--platform VALUE / -p | Specify the project platform (intigriti, bugcrowd, hackerone, pentest...) |
--inactive / -i | Specify ito create project as inactive |
--type VALUE | Specify the project type, like private or public (specific to bug bounty) |
--tag VALUE / -t | Add tags to the project (multiple key=value pairs can be provided) |
--raw | Read project as raw JSON from stdin |
galileo projects list
List authorized projects.
| Flag | Description |
|---|---|
--all / -a | Show all projects, including inactive ones |
--inactive / -i | Only show inactive projects |
--tag VALUE / -t | Show only projects that contain certain tag |
--value VALUE / -v | Show only projects that contain a specific tag and value (must be used with -t) |
galileo projects remove NAME
Delete a project after confirmation.
| Flag | Description |
|---|---|
--yes / -y | Skip confirmation prompt |
galileo projects default [NAME]
Read or set the saved default project.
| Flag | Description |
|---|---|
--unset | Unset the default project |
galileo projects inscope [TARGET...]
Read, add, or remove in-scope entries.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to add asset to scope |
--rm / -r | Remove asset from inscope |
--bounty VALUE / -b | Specify if asset is elegible to bounty |
--type VALUE | Specify asset type (domain / subdomain / android / ios / source / other) |
--wildcard / -w | Show only wildcard domains |
--domains / -d | Show only wildcard domains |
--tier VALUE | Specify asset tier (numeric value) |
--issues VALUE / -i | Specify asset number of known issues |
--tag VALUE / -t | Add tags to the asset (multiple key=value pairs can be provided) |
galileo projects outscope [TARGET...]
Read, add, or remove exclusions.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to add asset to out of scope |
--bounty VALUE / -b | Specify if asset is elegible to bounty |
--rm / -r | Remove asset from out of scope |
--type VALUE | Specify asset type (domain / subdomain / android / ios / source / other) |
--wildcard / -w | Show only wildcard domains |
--domains / -d | Show only wildcard domains |
--tier VALUE | Specify asset tier (numeric value) |
--issues VALUE / -i | Specify asset number of known issues |
--tag VALUE / -t | Add tags to the asset (multiple key=value pairs can be provided) |
galileo assets insert HOST...
Insert hostnames from arguments or stdin.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to add asset |
--httpx | Automatically perform httpx |
--screenshot / -s | Take screenshot with HTTPX |
--tag VALUE / -t | Add tags to the asset (multiple key=value pairs can be provided) |
--ipaddress VALUE / -i | IP Addresses available to that asset |
--available / -a | If the asset is available (false by default!) |
--scheme VALUE | Specify asset protocol |
--port VALUE | Port of the available address |
--title VALUE | Specify page title probe |
--status-code VALUE | Specify status code probe |
--content-length VALUE | Specify status code probe |
--favicon VALUE | Specify favicon hash probe |
--lines VALUE | Specify lines count probe |
--words VALUE | Specify words count probe |
--location VALUE | Specify location header probe |
--webserver VALUE | Specify server header probe |
--body VALUE | Specify body hash probe |
--jarm VALUE | Specify JARM hash probe |
--b64screenshot VALUE | Specify base64 screenshot probe |
--cdn VALUE | Specify CDN probe |
--header VALUE | Add response headers (multiple key=value pairs can be provided) |
--wappalyzer VALUE | Specify wappalyzer probe |
galileo assets list
List available assets; include unavailable assets with --unavailable.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to list assets |
--domains / -d | Specify project to list only assets subdomains |
--unavailable / -u | Get unavailable projects as well |
--show-wappalyzer | Show wappalyzer technologies beside each asset |
--show-status-code | Show HTTP status code beside each asset |
--show-title | Show page title beside each asset |
galileo assets view HOST
Show an asset and its available screenshot.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to list assets |
galileo assets remove HOST...
Remove selected assets; --all removes every asset in the selected project.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to remove asset |
--all | Remove all assets |
--yes / -y | Skip confirmation prompt |
galileo assets path [URL...]
List paths by default; use --add, --rm, or --rm-all to change them. Pass full URLs.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to list assets |
--add | Add path's to the asset |
--rm | Remove path's to the asset |
--rm-all | Remove all asset paths |
--httpx | Automatically perform httpx |
--source VALUE / -s | Specify source from this path. (e.g.: ffuf) |
--tag VALUE / -t | Add tags to the asset (multiple key=value pairs can be provided) |
--title VALUE | Specify page title probe |
--status-code VALUE | Specify status code probe |
--content-length VALUE | Specify status code probe |
--favicon VALUE | Specify favicon hash probe |
--lines VALUE | Specify lines count probe |
--words VALUE | Specify words count probe |
--location VALUE | Specify location header probe |
--webserver VALUE | Specify server header probe |
--body VALUE | Specify body hash probe |
--jarm VALUE | Specify JARM hash probe |
--b64screenshot VALUE | Specify base64 screenshot probe |
--cdn VALUE | Specify CDN probe |
--header VALUE | Add response headers (multiple key=value pairs can be provided) |
--wappalyzer VALUE | Specify wappalyzer probe |
galileo assets service [HOST]
List recorded services; --add writes a service record. This command does not perform a port scan.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to list assets |
--asset VALUE / -a | Specify asset to list services |
--add | Add service to the asset |
--list / -l | List services (default when no other action specified) |
--port VALUE | Port of the available address |
--protocol VALUE | Specify protocol of the available address |
--banner VALUE | Specify service banner/description |
--state VALUE | Specify port state: open, closed, filtered |
--script VALUE / -s | Add scripts to the asset |
--tag VALUE / -t | Add tags to the asset (multiple key=value pairs can be provided) |
--hosts | Show all alive hosts |
--services | Show services in hostname:port service format |
--service VALUE | Filter by service name |
--ports | Show consolidated list of open ports |
--port-filter VALUE | Filter by port(s) (comma-separated) |
--json | Output in JSON format |
--csv | Output in CSV format |
galileo scan add
Create a finding using flags or one JSON object on stdin with --raw.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to add scan |
--notify | Auto notify vulnerabilities when adding them |
--severity VALUE | Specify scan severity (default unknown) |
--asset VALUE | Affected asset in the issue |
--title VALUE | Scan result title |
--description VALUE | Scan result description |
--notified | Mark if it was already notified (default false) |
--fp | Mark if it was a false positive (default false) |
--source VALUE | Scan result source |
--cve VALUE | Inform issue CVE |
--reference VALUE | Add references to the scan |
--tag VALUE | Add tags to the scan (key=value pairs) |
--template VALUE | Scan template identifier |
--demonstration VALUE | Steps to demonstrate the finding |
--observation VALUE | Observation / context |
--type VALUE | Scan type (e.g. vulnerability type) |
--category VALUE | Scan category |
--remediation VALUE | Remediation guidance |
--retest-demonstration VALUE | Steps for retest demonstration |
--requests-file VALUE | Path to JSON file with request/response pairs: [["req","resp"],...] |
--raw | Read scan as raw JSON from stdin and send to server (project via -p) |
galileo scan list
List findings; --id selects one finding and --json produces structured output.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project to list scans |
--title VALUE | Show scans by title |
--id VALUE | Show scan result from specific id |
--asset VALUE | Filter by asset |
--severity VALUE | Specify severity to view scans |
--info | Include informative severity in list |
--json | Output findings as a JSON array (id/title/asset/severity/scope/status/source) |
galileo scan remove ID...
Delete finding IDs passed as arguments or stdin.
| Flag | Description |
|---|---|
--project VALUE / -p | Specify project |
--yes / -y | Skip confirmation prompt |
galileo templates list
List vulnerability templates available to your account.
| Flag | Description |
|---|---|
--verbose / -v | Show template details (type, category, CVSS) |
galileo templates view CODE_OR_ID
View a template by code or ID.
galileo notify ID...
Notify findings by ID through Discord. Slack is not implemented.
| Flag | Description |
|---|---|
--slack | Notify scan on slack |
--discord | Notify scan on discord |
--id VALUE | Scan ID to notify |
Inputs, outputs, and errors
Text commands accept newline-delimited stdin where described. --raw expects one JSON object, not an array. Use scan list --json and assets service --json for structured output. Do not assume all output is JSON or every validation error yields a nonzero exit code; inspect error messages. Deletions prompt for confirmation unless --yes is used. Check the project and IDs before bulk actions.