mirror of
https://github.com/pbakaus/impeccable.git
synced 2026-09-12 06:06:37 +03:00
The engine verified TLS against the Mozilla roots bundled through webpki-roots only, so behind a TLS-inspecting proxy (Aikido, Zscaler, Netskope) whose root lives in the OS trust store, `impeccable update` and `install` failed with `invalid peer certificate: UnknownIssuer` while curl and npm on the same machine succeeded. crates/context/src/http.rs builds one rustls ClientConfig per process: the OS trust store (rustls-native-certs: Keychain, Windows store, the OpenSSL paths on Linux) merged with the bundled roots. A union, not a replacement, so a container without ca-certificates or a store that fails to load still verifies exactly as before. SSL_CERT_FILE and SSL_CERT_DIR replace the OS store the way they do for OpenSSL and curl. Every HTTPS call site (bundle and signature downloads, /api/version, /api/commands, the roll API, image generation) builds its agent from this module; the plain-HTTP live-server calls on localhost are untouched. Verified against a local HTTPS server signed by a throwaway CA: trusted through SSL_CERT_FILE the update check reaches it; without it the same server is rejected as UnknownIssuer; with SSL_CERT_FILE pointing at that CA or at a missing file, impeccable.style still verifies through the bundled roots. cargo test --workspace and the oracle corpus (832) pass. Written with AI assistance (Claude Code). Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
95 lines
3.8 KiB
Markdown
95 lines
3.8 KiB
Markdown
# Impeccable CLI
|
|
|
|
Detect UI anti-patterns and design quality issues from the command line, and install the Impeccable design skill into your AI coding harness. The detector scans HTML, CSS, JSX, TSX, Vue, and Svelte files for 61 deterministic rules, including AI-generated UI tells, accessibility violations, and general design quality problems.
|
|
|
|
The npm package is a small launcher. It runs the `impeccable` engine binary for your platform, installed alongside it as an optional dependency (`@impeccable/cli-<os>-<arch>`), and falls back to a per-user cache or a one-time download when that package is missing.
|
|
|
|
## Quick Start
|
|
|
|
```bash
|
|
# Install skills into your AI harness (Claude, Cursor, Gemini, etc.)
|
|
npx impeccable install
|
|
|
|
# Non-interactive install for a specific scope
|
|
npx impeccable install -y --providers=claude,codex --scope=project
|
|
|
|
# First command to run inside your AI harness
|
|
/impeccable init
|
|
|
|
# Update skills to the latest version
|
|
npx impeccable update
|
|
|
|
# Install or update skills without hook manifests
|
|
npx impeccable install --no-hooks
|
|
|
|
# Link skills from a Git submodule checkout
|
|
npx impeccable link --source=.impeccable --providers=claude,cursor
|
|
|
|
# List all available commands
|
|
npx impeccable help
|
|
|
|
# Scan files or directories for anti-patterns
|
|
npx impeccable detect src/
|
|
|
|
# Scan a live URL (uses an installed Chrome, Chromium, or Edge)
|
|
npx impeccable detect https://example.com
|
|
|
|
# JSON output for CI/tooling
|
|
npx impeccable detect --json src/
|
|
```
|
|
|
|
`npx impeccable skills <command>` is the legacy namespace and still works.
|
|
|
|
## What It Detects
|
|
|
|
**AI Slop Tells**: patterns that scream "AI generated this":
|
|
- Side-tab accent borders, gradient text on headings
|
|
- Purple/violet gradients and cyan-on-dark palettes
|
|
- Dark mode with glowing accents, border + border-radius clashes
|
|
|
|
**Typography Issues**: overused fonts (Inter, Roboto), flat type hierarchy, single font families
|
|
|
|
**Color & Contrast**: WCAG AA violations, gray text on colored backgrounds, pure black/white
|
|
|
|
**Layout & Composition**: nested cards, monotonous spacing, everything-centered layouts
|
|
|
|
**Motion**: bounce/elastic easing, layout property transitions
|
|
|
|
**Quality**: tiny body text, cramped padding, long line lengths, small touch targets
|
|
|
|
61 deterministic detector rules in total. See the full catalog at [impeccable.style/slop](https://impeccable.style/slop).
|
|
|
|
## Exit Codes
|
|
|
|
- `0`: scan completed with no primary findings (advisories may still be listed)
|
|
- `1`: at least one requested target could not be scanned
|
|
- `2`: scan completed with primary findings
|
|
|
|
Operational failure takes precedence when a multi-target scan is partial. In JSON mode, stdout remains a findings array and diagnostics are written to stderr.
|
|
|
|
## Options
|
|
|
|
```
|
|
impeccable detect [options] [file-or-dir-or-url...]
|
|
|
|
--json Output findings as JSON
|
|
--scope Only report rules in a design domain (type, layout)
|
|
--help Show help
|
|
```
|
|
|
|
## Requirements
|
|
|
|
- Node.js 22.18+ to run `npx impeccable`. The engine itself is a self-contained binary and needs no runtime; the skill installed into your harness calls it directly.
|
|
- For URL scans, an installed Chrome, Chromium, or Edge (set `IMPECCABLE_BROWSER` to point at one).
|
|
- Behind a TLS-inspecting proxy, downloads trust your OS certificate store as well as the bundled Mozilla roots. Set `SSL_CERT_FILE` or `SSL_CERT_DIR` to use a specific CA bundle instead.
|
|
|
|
Binary lookup order: `IMPECCABLE_BIN`, the platform package, `~/.impeccable/bin/<version>/`, then a download of the pinned version into that cache. Set `IMPECCABLE_BIN` to a local build to skip all of that.
|
|
|
|
## Part of Impeccable
|
|
|
|
This CLI is part of [Impeccable](https://impeccable.style), a cross-provider design skill pack for AI-powered development tools. The full suite includes 23 commands for Claude, Cursor, GitHub Copilot, Gemini, Codex, Hermes Agent, Veto, and more.
|
|
|
|
## License
|
|
|
|
[Apache 2.0](https://github.com/pbakaus/impeccable/blob/main/LICENSE)
|