Skip to content

Validate in CI

Validate installed capabilities for CI. Exits 1 on any failure.

Terminal window
tuff check # check all capabilities
tuff check --global # check global capabilities only
tuff check --json # machine-readable JSON output
tuff check --ignore-failures # report failures but exit 0
tuff check --strict # also fail on policy rules recorded as not enforced

A policy installed with tuff add --accept-unenforced records each rule an agent does not enforce. tuff check prints those rules on every run and exits 0 for them. tuff check --strict exits 1 while any are recorded. See Rules an agent does not enforce.

Example output:

✓ python-uv-default skill open-agents ok
✗ dirty-skill skill open-agents modified (.agents/skills/dirty-skill/SKILL.md)

To also check that installed MCP servers actually start, add tuff mcp doctor.

Add this to your project’s .github/workflows/tuff-check.yml:

name: Tuff Check
on: [push, pull_request]
jobs:
check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Rust
uses: actions-rs/toolchain@v1
with:
toolchain: stable
- name: Build and install tuff
run: cargo install tuffcli
- name: Validate capabilities
run: tuff check --json

To also send a report of the project to a Tuff Console after the check passes, see Publishing from GitHub Actions, which needs no stored secret, and Publishing from other CI systems.

Commit tuff.lock to your repo so tuff check runs against the committed state. See The tuff.lock File for what to commit.