Getting started
Review your last commit in two minutes
All you need is a Git repository with at least two commits. The first run needs no configuration, no Docker and no API key, and it never executes your code.
This page covers Probe for code, the command-line tool. Watching Word, Excel or PowerPoint files? See Probe Desktop.
-
Install the binary
Probe is a single executable. Git must be installed; nothing else is required for this guide. Download the archive for your operating system and processor, then extract it. Follow the steps for your system below.
Open a terminal in the extracted folder containing
probe. On macOS, first remove the browser download quarantine withxattr -d com.apple.quarantine probe.sudo install probe /usr/local/bin/ probe versionNo
sudo? Install to~/.local/bininstead, provided it exists and is on yourPATH.In File Explorer, create
%LOCALAPPDATA%\Programs\probeand copy the extractedprobe.exeinto it. Then open PowerShell:$env:Path += ";$env:LOCALAPPDATA\Programs\probe" probe versionThis sets
PATHfor the current terminal. For future terminals, add the same folder to your userPathin Windows Environment Variables.The last command prints the installed version, for example
probe v0.5.1. To check the archive against the published checksums, see Verify a download. -
Compare your last commit with the previous one
Go to any Git repository and ask Probe what changed between
HEAD~1andHEAD:cd path/to/your/repository probe lint HEAD~1..HEADlintis the static half of Probe. It compares the two commits, collects risk signals and writes a report. It never executes repository code, never calls an AI provider and needs no.probe.json: without one, the built-in defaults for the detected language apply.Only committed files are analyzed. Uncommitted edits and untracked files are ignored, so commit your work first, for example on a scratch branch. To keep reports out ofgit statuswithout touching.gitignore, runecho .probe/ >> .git/info/exclude. -
Read the report
Open
.probe/CONFIDENCE_REPORT.mdin your editor. Start with Suggested Human Review, a list of file and line ranges ranked by severity, each with the reason it was flagged:## Suggested Human Review - **high** auth/auth.go:7–7 (new): Authentication or authorization function body changed - **high** payment/refund.go (whole file): Lines added and removed in a sensitive file; No nearby test file changed - **high** payment/refund.go:21–21 (old): Possible input validation removed(new) points to a line in the candidate commit and (old) to a removed line in the base. (whole file) marks a signal about the file itself, such as a sensitive path, rather than about one of its lines. Review Surface tells you how many changed lines those ranges cover. The same data, with commit IDs and signal evidence, is in
confidence-report.jsonfor scripts and CI.Signals are reasons to look, not confirmed bugs. The signal reference explains each one.
-
Choose what to compare
Any two revisions work. A few common choices:
Command Compares probe lint HEAD~5..HEADYour last five commits taken together. probe lint --base mainYour current branch against main, from their merge base, like a pull request. Use--base masterif that is your default branch.probe lint --base origin/main --head featureAnother branch against the remote default branch, without checking it out. probe lint main..featureThe two exact commits, with no merge base ( main...featureuses the merge base).probe lint --base main --ciSame as above, but exits with code 2when human review is required, for scripts and CI. -
Optional: run your checks in a sandbox
reviewdoes everythinglintdoes, then runs the repository's test, typecheck, build and coverage commands in disposable, network-less Docker containers. It needs Docker with Linux containers and a preloaded image containing your toolchain: Probe never pulls images or installs dependencies itself. For a Go project with no third-party dependencies, the default image is enough:docker pull golang:1.26-bookworm probe review HEAD~1..HEAD --reviewer=falseFor Node.js, Python and Rust projects, stock images do not contain your dependencies: build an image that does and point
sandbox.imageat it in a policy (next step), or let the trusted policy build that layer with aprepareobject. If Docker or the image is missing, Probe stops with exit code4and never falls back to running code on your machine. -
Adopt it in your repository
Run
probe initto generate.probe.jsonfor your detected language. Review its commands and sandbox image, then try the policy locally:probe review --base main --config .probe.jsonCommit
.probe.jsonto your base branch. Subsequent reviews read that trusted policy. On your feature branch, run:probe review --base main --ciWorking with a coding agent? Adopt the plan-first process: the agent runs
probe plan --intent-file task.md --cibefore writing code (a flagged plan goes to a human), implements the plan, and CI runsprobe review --plan .probe/PLAN.json --ci. Exit0means the change conforms to a low-risk plan and passed its checks, so it can merge without a human review; exit2lists why a human must look (plan gate).Next steps: every flag, exit code and policy key is in the reference. To let an AI reviewer try to reproduce issues, configure a provider as described in AI reviewer. For GitHub Actions, see the CI integration guide.
If something goes wrong
| Message | What to do |
|---|---|
base: git rev-parse … Needed a single revision | A revision does not exist. The repository may have a single commit (so there is no HEAD~1), or its default branch is not main: pass --base master or an explicit range. |
| The report misses your latest edits | They are not committed yet. Probe only analyzes commits; commit them, then run it again. |
Exit code 2 | Not an error: with --ci, it means human review is required. See exit codes. |
Exit code 4 during review | Docker is not running or the sandbox image is not present locally. Pull it first, or use lint. |
reviewer.model must be configured… | --reviewer was requested without a model. Drop it, or configure a provider. |