ax-check rule
AXC-C008: No dry-run flag documented
Help documents no --dry-run or equivalent, so an agent cannot rehearse a change before making it.
ax-check is a checker being prepared for release. This page documents the rule ahead of that release; see all 50 rules.
| Severity | info |
| Kind | Heuristic. A pattern match: a prompt to look, not a verdict. |
| Mode | ax-check probe-cli |
| Applies to | Command-line programs, run as a subprocess |
| Pattern tags | dry-run, approval |
| Fix in one line | If the CLI changes anything, add --dry-run that prints what would happen without doing it. |
The help text documents no --dry-run or similar flag. If the command changes anything, an agent cannot rehearse the change and show a person what would happen before it happens.
What it checks
ax-check reads the help output. The rule fires when the text mentions none of: --dry-run, --dryrun, --what-if, --whatif, --plan, --preview, --noop or --simulate. If no help probe works, this rule does not run. It is an info finding because many commands only read data, and a read-only tool has nothing to preview.
Why it matters
Agents are often asked to act under human approval. A dry run gives the approver something concrete to read. The Command Line Interface Guidelines list “-n, –dry-run: Dry run. Do not run the command, but describe the changes that would occur if the command were run.” Cloudflare’s documentation for its cf CLI says: “Add –dry-run to print the request as JSON without sending it. Dry runs need no credentials.” (vendor documentation). The ability to run without credentials means an agent can prepare a change before anyone grants it access.
Our guide on approval as a workflow explains why a rehearsal step belongs in the design of agent tools, not only in the interface.
How to fix
If the CLI changes anything, add --dry-run. It should print what would change, in the same format as the real run where possible, and exit 0 without making the change. Document it in --help.
Example
Before
$ invoicer void --help
Usage: invoicer void <id>
Marks an invoice as void.
After
$ invoicer void --help
Usage: invoicer void <id> [--dry-run]
Marks an invoice as void.
Options:
--dry-run Print what would change and exit without changing it
$ invoicer void 1042 --dry-run
Would void invoice 1042 (customer: Acme Ltd, total: 120.00).
No changes made.
A Python fix:
parser.add_argument("--dry-run", action="store_true",
help="print what would change and exit without changing it")
...
if args.dry_run:
print(f"Would void invoice {inv.id} ({inv.customer}, total {inv.total}).")
print("No changes made.")
return 0
How ax-check detects it
This is a text search over the help output for the spellings above. A bare -n is not recognised, so document the long form too. It does not run a dry run, and it does not judge whether your command changes anything. A read-only CLI will therefore get this finding even though it needs no dry run. It is info severity for that reason.
Known false negatives: a help text that mentions “preview” in an unrelated sentence. Silence the rule with --disable AXC-C008 for read-only tools.
To reproduce by hand: invoicer --help </dev/null | grep -Ei 'dry-?run|what-?if|plan|preview|noop|simulate'.
Safety note: This rule reads help text only, from the default --help probe. probe-cli executes your program under your own OS account. The temporary working directory and HOME it uses are not a sandbox: the program can still read and write anything your account can, and use the network. Probe a CLI you have not reviewed only inside a container or a throwaway virtual machine. Run ax-check probe-cli --dry-run -- invoicer first to see the probes that would run, and see the “Probe safety” section of the ax-check README for what is and is not isolated.
Sources
- Guideline: Command Line Interface Guidelines, clig.dev. https://clig.dev/ . Lists
-n, --dry-runas a flag that describes the changes without making them. - Vendor documentation: Use cf with coding agents, Cloudflare, updated 2026-09-29. https://developers.cloudflare.com/cf/agents/ . Documents
--dry-runprinting the request as JSON, with no credentials needed. - Site guide: Approval is a workflow, agentexperience.tech. https://agentexperience.tech/insights/approval-is-a-workflow/ . Covers why approval needs something concrete to approve.
Related evidence
Records in the AX evidence register that share a pattern tag with this rule. A shared tag means the record is about the same pattern, not that it tests this rule. Read the evidence class before the number.
- EV-0014: Allow/ask/never policies blocked less overreach than per-action approval (Preprint). In a study of 113 people without software backgrounds (preprint), user-authored allow/ask/never policies blocked 20.1 percentage points less agent overreach than per-action approval, partly because participants chose 'ask' for 114 of 140 rules and then approved most overreach at runtime.
- EV-0015: Approvals that outlive their task raise attack success (Preprint). A preprint reports that approvals persisted beyond the context that justified them raised prompt-injection attack success by up to 35.1 percentage points on 508 AgentDojo cases, and by 24.9 points on average in live tests on three production coding agents.
- EV-0016: Approval records omit the effects a command goes on to trigger (Preprint). A preprint reports that coding-agent approval records name the approved command but omit effects its workflow exercises: across 111 approval and trace pairs, unrecorded residual effects fell from 40 with explicit fields to 17 with command semantics and 13 with decision-time metadata.
- EV-0034: Vendor claim: users approved about 93% of permission prompts (Vendor claim). Anthropic states that its telemetry showed users approved roughly 93% of Claude Code permission prompts, and that an operating-system sandbox reduced permission prompts by 84%.
- EV-0038: Dry-run output printed secrets until a fix redacted them (Independent measurement). An issue on Cloudflare's cf beta reported that --dry-run printed secret values in plain text, and Cloudflare merged a fix redacting sensitive values in dry-run output on 5 October 2026.
