The engine verified TLS against the Mozilla roots bundled through webpki-roots only, so behind a TLS-inspecting proxy (Aikido, Zscaler, Netskope) whose root lives in the OS trust store, `impeccable update` and `install` failed with `invalid peer certificate: UnknownIssuer` while curl and npm on the same machine succeeded. crates/context/src/http.rs builds one rustls ClientConfig per process: the OS trust store (rustls-native-certs: Keychain, Windows store, the OpenSSL paths on Linux) merged with the bundled roots. A union, not a replacement, so a container without ca-certificates or a store that fails to load still verifies exactly as before. SSL_CERT_FILE and SSL_CERT_DIR replace the OS store the way they do for OpenSSL and curl. Every HTTPS call site (bundle and signature downloads, /api/version, /api/commands, the roll API, image generation) builds its agent from this module; the plain-HTTP live-server calls on localhost are untouched. Verified against a local HTTPS server signed by a throwaway CA: trusted through SSL_CERT_FILE the update check reaches it; without it the same server is rejected as UnknownIssuer; with SSL_CERT_FILE pointing at that CA or at a missing file, impeccable.style still verifies through the bundled roots. cargo test --workspace and the oracle corpus (832) pass. Written with AI assistance (Claude Code). Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
3.8 KiB
Impeccable CLI
Detect UI anti-patterns and design quality issues from the command line, and install the Impeccable design skill into your AI coding harness. The detector scans HTML, CSS, JSX, TSX, Vue, and Svelte files for 61 deterministic rules, including AI-generated UI tells, accessibility violations, and general design quality problems.
The npm package is a small launcher. It runs the impeccable engine binary for your platform, installed alongside it as an optional dependency (@impeccable/cli-<os>-<arch>), and falls back to a per-user cache or a one-time download when that package is missing.
Quick Start
# Install skills into your AI harness (Claude, Cursor, Gemini, etc.)
npx impeccable install
# Non-interactive install for a specific scope
npx impeccable install -y --providers=claude,codex --scope=project
# First command to run inside your AI harness
/impeccable init
# Update skills to the latest version
npx impeccable update
# Install or update skills without hook manifests
npx impeccable install --no-hooks
# Link skills from a Git submodule checkout
npx impeccable link --source=.impeccable --providers=claude,cursor
# List all available commands
npx impeccable help
# Scan files or directories for anti-patterns
npx impeccable detect src/
# Scan a live URL (uses an installed Chrome, Chromium, or Edge)
npx impeccable detect https://example.com
# JSON output for CI/tooling
npx impeccable detect --json src/
npx impeccable skills <command> is the legacy namespace and still works.
What It Detects
AI Slop Tells: patterns that scream "AI generated this":
- Side-tab accent borders, gradient text on headings
- Purple/violet gradients and cyan-on-dark palettes
- Dark mode with glowing accents, border + border-radius clashes
Typography Issues: overused fonts (Inter, Roboto), flat type hierarchy, single font families
Color & Contrast: WCAG AA violations, gray text on colored backgrounds, pure black/white
Layout & Composition: nested cards, monotonous spacing, everything-centered layouts
Motion: bounce/elastic easing, layout property transitions
Quality: tiny body text, cramped padding, long line lengths, small touch targets
61 deterministic detector rules in total. See the full catalog at impeccable.style/slop.
Exit Codes
0: scan completed with no primary findings (advisories may still be listed)1: at least one requested target could not be scanned2: scan completed with primary findings
Operational failure takes precedence when a multi-target scan is partial. In JSON mode, stdout remains a findings array and diagnostics are written to stderr.
Options
impeccable detect [options] [file-or-dir-or-url...]
--json Output findings as JSON
--scope Only report rules in a design domain (type, layout)
--help Show help
Requirements
- Node.js 22.18+ to run
npx impeccable. The engine itself is a self-contained binary and needs no runtime; the skill installed into your harness calls it directly. - For URL scans, an installed Chrome, Chromium, or Edge (set
IMPECCABLE_BROWSERto point at one). - Behind a TLS-inspecting proxy, downloads trust your OS certificate store as well as the bundled Mozilla roots. Set
SSL_CERT_FILEorSSL_CERT_DIRto use a specific CA bundle instead.
Binary lookup order: IMPECCABLE_BIN, the platform package, ~/.impeccable/bin/<version>/, then a download of the pinned version into that cache. Set IMPECCABLE_BIN to a local build to skip all of that.
Part of Impeccable
This CLI is part of Impeccable, a cross-provider design skill pack for AI-powered development tools. The full suite includes 23 commands for Claude, Cursor, GitHub Copilot, Gemini, Codex, Hermes Agent, Veto, and more.