rg · Andrew Gallant

ripgrep for AI Agents

Search source trees quickly with stable JSON, glob, type, and context controls.

Official toolOperational risk: R0R0verified
Agent readiness
83/100
Evidence confidence
verified
Documentation checked
2026-07-10
Independently tested version
15.1.0

Install for an Agent

Choose an official installation path that matches the runtime. Pin a version for team or CI use, then record the version before the first task.

HomebrewRecommended
macos · linux
$ shell
brew install ripgrep
winget
windows
$ shell
winget install BurntSushi.ripgrep.MSVC
Authentication and Minimum Permissions
Grant only the permissions the task needs. Pass credentials through environment variables or a platform secret store, never through prompts, repositories, or logs.
No authentication requiredHeadless authentication supported

No service credential is required; restrict filesystem and network access to the task.

Methods
none
Secret environment variables
None
Credential storage
No service credential is stored for this CLI.
Agent and Environment Compatibility
Confirm shell access first, then check the platform, network boundary, and credential path.
claude-codecodexgemini-clicopilot-cli
Environments
local, ci, container, headless, remote
Platforms
macos, linux, windows

Structured Output for Reliable Automation

Prefer a machine-readable format. Treat stdout as the result channel and stderr as diagnostics so the agent can parse failures separately.

json · text · null-delimited paths
Use --json or --null where supported and keep diagnostic logs on stderr.
--json--null

Independently captured output sample

15.1.0 · macOS 26.5.1 (arm64), local non-interactive shell

Executed command
rg --json '"name"' package.json | jq -c 'select(.type == "match")'
Captured stdout · ndjson match event
{"type":"match","data":{"path":{"text":"package.json"},"lines":{"text":"  \"name\": \"clifinder-net\",\n"},"line_number":2,"absolute_offset":2,"submatches":[{"match":{"text":"\"name\""},"start":2,"end":8}]}}
Sample JSON Schema
{
  "type": "object",
  "required": [
    "type",
    "data"
  ],
  "properties": {
    "type": {
      "const": "match"
    },
    "data": {
      "type": "object",
      "required": [
        "path",
        "lines",
        "line_number",
        "submatches"
      ],
      "properties": {
        "path": {
          "type": "object"
        },
        "lines": {
          "type": "object"
        },
        "line_number": {
          "type": "integer"
        },
        "absolute_offset": {
          "type": "integer"
        },
        "submatches": {
          "type": "array"
        }
      }
    }
  }
}

R0–R3 Command Risk Guide

Risk is assigned per command. R0 is local or remote read-only, R1 is reversible local write, R2 changes remote state, and R3 can be irreversible or production-impacting.

Read-only does not mean public

R0 only means the command does not change local or remote state. A read-only command may still return secrets, identity data, configuration, or production data. Expose only the minimum needed for the task, and never place it in logs, prompts, or commits.

R0Search with JSON events
Searches a bounded directory and emits one JSON event per line.
$ shell
rg --json --glob "*.ts" "pattern" src
IdempotentSensitive output
R0List searchable files
Lists files while respecting ignore rules.
$ shell
rg --files --null src
Idempotent

How the Agent Readiness Score Is Built

Readiness describes how reliably an agent can operate the tool. It does not make every command safe and it does not replace an independent execution test.

Documentation indicates an agent-readiness score of 83/100. A bounded local smoke test is recorded for 15.1.0; review its limitations before relying on untested commands.

Structured output
Use --json or --null where supported and keep diagnostic logs on stderr.
18/20
x
Headless operation
Official documentation describes a non-interactive authentication or execution path.
14/15
x
Safety controls
CLI Finder separates read commands from commands that require confirmation.
8/15
x
Determinism
Commands use explicit arguments and documented output controls where available.
8/10
x
Authentication
No service credential is required; restrict filesystem and network access to the task.
10/10
x
Documentation
This entry cites official documentation checked on 2026-07-10.
9/10
x
Installation
Official installation paths cover macOS, Linux, and Windows.
8/8
x
Maintenance
An official source repository is linked for release and maintenance review.
6/7
x
Agent artifacts
CLI Finder can generate registry-derived skills and policies; the tool itself was not credited with shipping them.
2/5
x

Generate a Skill or Agent Policy

Choose an agent and safety mode to generate a copyable artifact with installation, allowed commands, approval boundaries, and the evidence limitation.

Generated artifact preview
SKILL.md
---
name: ripgrep-agent-workflow
description: Use ripgrep for source search, pattern discovery, file type filtering with explicit command risk and evidence boundaries.
---

# ripgrep agent workflow

Use this skill when the task needs source search, pattern discovery, file type filtering, machine-readable matches.

## Evidence boundary

- Registry confidence: `verified`
- Documentation checked: `2026-07-10`
- Locally tested version: `15.1.0`
- Treat only the recorded executed checks as independently verified; every unlisted command remains documentation-only.

## Executed smoke checks

- `rg --version` — passed; exit 0. The recorded smoke check completed successfully.
- `rg --json --glob '*.ts' 'createFileRoute' src/routes` — passed; exit 0. The recorded smoke check completed successfully.
- `rg --json '"name"' package.json | jq -c 'select(.type == "match")'` — passed; exit 0. The NDJSON stream was reduced to the recorded match event without changing its payload.
- `rg --json 'definitely-no-clifinder-match' package.json` — expected-failure; exit 1. ripgrep returned its documented no-match exit status without writing diagnostics to stderr.

## Installation

- Homebrew (macos, linux): `brew install ripgrep`
- winget (windows): `winget install BurntSushi.ripgrep.MSVC`

## Authentication

- Methods: none
- Secret environment variables: none
- Minimum permissions: No service credential is required; restrict filesystem and network access to the task.
- Credential storage: No service credential is stored for this CLI.
- Never print, persist, or commit credential values.

## Allowed commands (read-only)

- `rg --json --glob "*.ts" "pattern" src` — R0: Searches a bounded directory and emits one JSON event per line.
- `rg --files --null src` — R0: Lists files while respecting ignore rules.

## Commands requiring explicit approval (read-only)

- None recorded.

## Forbidden commands (read-only)

- None recorded.

## Execution rules

1. Mode boundary: R0 exact commands may be used; R1, R2, and R3 commands are forbidden.
2. Confirm the selected account, project, context, database, namespace, or environment before any command.
3. Prefer structured output using `--json`, `--null`.
4. Capture the exact command, exit code, stdout, and stderr separately.
5. A generated prefix policy must prompt unless that exact prefix is explicitly marked suffix-safe; do not infer safety from the executable name.
6. Never broaden credentials or disable safety controls to make a command succeed.

## Official sources

- [ripgrep guide](https://github.com/BurntSushi/ripgrep/blob/master/GUIDE.md)
- [ripgrep guide source repository](https://github.com/BurntSushi/ripgrep)

CLI vs MCP vs API for This Task

CLI
Use the CLI on a developer machine, in CI, or in a container when the task should reuse existing shell state, credentials, and scripts and remain directly observable.
MCP
Consider MCP when the agent benefits from controlled tool definitions, delegated identity, or centrally governed server-side access.
API
Use the direct API for persistent application integrations, high-volume requests, or event-driven work where starting a process adds unnecessary overhead.
Read the full CLI vs MCP guide

Verification History and Official Evidence

CLI Finder records documentation review separately from real execution. Installation, help, exit codes, and output cannot be called Verified until they were run.

Current evidence boundary
Version output, repository search, NDJSON event output, one extracted match event, and the no-match exit path were executed locally. Installation paths, other platforms, binary files, encoding edge cases, and out-of-scope directories were not tested.
Evidence confidence
verified
Independently tested version
15.1.0 · 2026-07-10
Test environment
macOS 26.5.1 (arm64), local non-interactive shell

Executed checks

  • PassedExit code: 0
    rg --version

    The recorded smoke check completed successfully.

    stdout excerpt

    ripgrep 15.1.0
  • PassedExit code: 0
    rg --json --glob '*.ts' 'createFileRoute' src/routes

    The recorded smoke check completed successfully.

  • PassedExit code: 0
    rg --json '"name"' package.json | jq -c 'select(.type == "match")'

    The NDJSON stream was reduced to the recorded match event without changing its payload.

  • Expected failure pathExit code: 1
    rg --json 'definitely-no-clifinder-match' package.json

    ripgrep returned its documented no-match exit status without writing diagnostics to stderr.

Official sources
Open the official material to confirm the current version and command behavior.

Alternatives and Related Paths

Find, parse, validate, and transform files and structured data locally.
Discover files predictably with clear filters, ignore handling, and null-delimited output.
Collect PR metadata, inspect the patch locally, and report blockers before posting or merging anything.
Give Claude Code a small local-first stack, then add authenticated tools only for the repository task at hand.
Choose ripgrep for new agent workflows and modern repository search; keep ag where an existing environment or script depends on it.

Questions About ripgrep for AI Agents