Validate in CI
tuff check
Section titled “tuff check”Validate installed capabilities for CI. Exits 1 on any failure.
tuff check # check all capabilitiestuff check --global # check global capabilities onlytuff check --json # machine-readable JSON outputtuff check --ignore-failures # report failures but exit 0tuff check --strict # also fail on policy rules recorded as not enforcedA policy installed with tuff add --accept-unenforced records each rule an agent does not enforce. tuff check prints those rules on every run and exits 0 for them. tuff check --strict exits 1 while any are recorded. See Rules an agent does not enforce.
Example output:
✓ python-uv-default skill open-agents ok✗ dirty-skill skill open-agents modified (.agents/skills/dirty-skill/SKILL.md)To also check that installed MCP servers actually start, add tuff mcp doctor.
CI with GitHub Actions
Section titled “CI with GitHub Actions”Add this to your project’s .github/workflows/tuff-check.yml:
name: Tuff Checkon: [push, pull_request]
jobs: check: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4
- name: Install Rust uses: actions-rs/toolchain@v1 with: toolchain: stable
- name: Build and install tuff run: cargo install tuffcli
- name: Validate capabilities run: tuff check --jsonTo also send a report of the project to a Tuff Console after the check passes, see Publishing from GitHub Actions, which needs no stored secret, and Publishing from other CI systems.
Commit tuff.lock to your repo so
tuff check runs against the committed state. See The tuff.lock File
for what to commit.