Files
pbakaus_impeccable/README.npm.md
T
bd6964c35b Trust the OS certificate store for engine HTTPS requests (#757) (#759)
The engine verified TLS against the Mozilla roots bundled through
webpki-roots only, so behind a TLS-inspecting proxy (Aikido, Zscaler,
Netskope) whose root lives in the OS trust store, `impeccable update`
and `install` failed with `invalid peer certificate: UnknownIssuer`
while curl and npm on the same machine succeeded.

crates/context/src/http.rs builds one rustls ClientConfig per process:
the OS trust store (rustls-native-certs: Keychain, Windows store, the
OpenSSL paths on Linux) merged with the bundled roots. A union, not a
replacement, so a container without ca-certificates or a store that
fails to load still verifies exactly as before. SSL_CERT_FILE and
SSL_CERT_DIR replace the OS store the way they do for OpenSSL and curl.
Every HTTPS call site (bundle and signature downloads, /api/version,
/api/commands, the roll API, image generation) builds its agent from
this module; the plain-HTTP live-server calls on localhost are
untouched.

Verified against a local HTTPS server signed by a throwaway CA: trusted
through SSL_CERT_FILE the update check reaches it; without it the same
server is rejected as UnknownIssuer; with SSL_CERT_FILE pointing at that
CA or at a missing file, impeccable.style still verifies through the
bundled roots. cargo test --workspace and the oracle corpus (832) pass.

Written with AI assistance (Claude Code).

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-07 13:15:18 -07:00

3.8 KiB

Impeccable CLI

Detect UI anti-patterns and design quality issues from the command line, and install the Impeccable design skill into your AI coding harness. The detector scans HTML, CSS, JSX, TSX, Vue, and Svelte files for 61 deterministic rules, including AI-generated UI tells, accessibility violations, and general design quality problems.

The npm package is a small launcher. It runs the impeccable engine binary for your platform, installed alongside it as an optional dependency (@impeccable/cli-<os>-<arch>), and falls back to a per-user cache or a one-time download when that package is missing.

Quick Start

# Install skills into your AI harness (Claude, Cursor, Gemini, etc.)
npx impeccable install

# Non-interactive install for a specific scope
npx impeccable install -y --providers=claude,codex --scope=project

# First command to run inside your AI harness
/impeccable init

# Update skills to the latest version
npx impeccable update

# Install or update skills without hook manifests
npx impeccable install --no-hooks

# Link skills from a Git submodule checkout
npx impeccable link --source=.impeccable --providers=claude,cursor

# List all available commands
npx impeccable help

# Scan files or directories for anti-patterns
npx impeccable detect src/

# Scan a live URL (uses an installed Chrome, Chromium, or Edge)
npx impeccable detect https://example.com

# JSON output for CI/tooling
npx impeccable detect --json src/

npx impeccable skills <command> is the legacy namespace and still works.

What It Detects

AI Slop Tells: patterns that scream "AI generated this":

  • Side-tab accent borders, gradient text on headings
  • Purple/violet gradients and cyan-on-dark palettes
  • Dark mode with glowing accents, border + border-radius clashes

Typography Issues: overused fonts (Inter, Roboto), flat type hierarchy, single font families

Color & Contrast: WCAG AA violations, gray text on colored backgrounds, pure black/white

Layout & Composition: nested cards, monotonous spacing, everything-centered layouts

Motion: bounce/elastic easing, layout property transitions

Quality: tiny body text, cramped padding, long line lengths, small touch targets

61 deterministic detector rules in total. See the full catalog at impeccable.style/slop.

Exit Codes

  • 0: scan completed with no primary findings (advisories may still be listed)
  • 1: at least one requested target could not be scanned
  • 2: scan completed with primary findings

Operational failure takes precedence when a multi-target scan is partial. In JSON mode, stdout remains a findings array and diagnostics are written to stderr.

Options

impeccable detect [options] [file-or-dir-or-url...]

  --json      Output findings as JSON
  --scope     Only report rules in a design domain (type, layout)
  --help      Show help

Requirements

  • Node.js 22.18+ to run npx impeccable. The engine itself is a self-contained binary and needs no runtime; the skill installed into your harness calls it directly.
  • For URL scans, an installed Chrome, Chromium, or Edge (set IMPECCABLE_BROWSER to point at one).
  • Behind a TLS-inspecting proxy, downloads trust your OS certificate store as well as the bundled Mozilla roots. Set SSL_CERT_FILE or SSL_CERT_DIR to use a specific CA bundle instead.

Binary lookup order: IMPECCABLE_BIN, the platform package, ~/.impeccable/bin/<version>/, then a download of the pinned version into that cache. Set IMPECCABLE_BIN to a local build to skip all of that.

Part of Impeccable

This CLI is part of Impeccable, a cross-provider design skill pack for AI-powered development tools. The full suite includes 23 commands for Claude, Cursor, GitHub Copilot, Gemini, Codex, Hermes Agent, Veto, and more.

License

Apache 2.0