rg · Andrew Gallant
ripgrep Agent 使用指南
通过稳定的 JSON、glob、文件类型和上下文控制快速搜索源码树。
官方工具操作风险: R0–R0verified
为 Agent 安装
选择与运行环境匹配的官方安装方式。在团队或 CI 环境中固定版本,并先运行版本检查。
用于稳定自动化的结构化输出
优先使用机器可读格式,并把 stdout 作为结果、stderr 作为诊断信息分别处理。
R0–R3 命令风险指南
风险按单条命令判断。R0 是本地或远程只读,R1 是可逆的本地写入,R2 会改变远程状态,R3 可能造成不可逆或生产级影响。
只读不等于可公开
R0 只表示命令不更改本地或远程状态。只读命令仍可能返回令牌、身份信息、配置或生产数据;只展示完成任务所需的最少内容,不得写入日志、Prompt 或提交内容。
Agent Readiness 评分依据
适配度描述 Agent 操作工具的稳定程度,不代表所有命令都安全,也不替代独立执行测试。
文档证据对应的 Agent Readiness 为 83/100;已记录 15.1.0 的有限本地 Smoke Test,使用未测试命令前仍需查看证据边界。
生成 Skill 或 Agent 策略
选择目标 Agent 和安全模式,生成包含安装、允许命令、确认边界与证据说明的可复制产物。
生成结果预览
SKILL.md
---
name: ripgrep-agent-workflow
description: Use ripgrep for source search, pattern discovery, file type filtering with explicit command risk and evidence boundaries.
---
# ripgrep agent workflow
Use this skill when the task needs source search, pattern discovery, file type filtering, machine-readable matches.
## Evidence boundary
- Registry confidence: `verified`
- Documentation checked: `2026-07-10`
- Locally tested version: `15.1.0`
- Treat only the recorded executed checks as independently verified; every unlisted command remains documentation-only.
## Executed smoke checks
- `rg --version` — passed; exit 0. The recorded smoke check completed successfully.
- `rg --json --glob '*.ts' 'createFileRoute' src/routes` — passed; exit 0. The recorded smoke check completed successfully.
- `rg --json '"name"' package.json | jq -c 'select(.type == "match")'` — passed; exit 0. The NDJSON stream was reduced to the recorded match event without changing its payload.
- `rg --json 'definitely-no-clifinder-match' package.json` — expected-failure; exit 1. ripgrep returned its documented no-match exit status without writing diagnostics to stderr.
## Installation
- Homebrew (macos, linux): `brew install ripgrep`
- winget (windows): `winget install BurntSushi.ripgrep.MSVC`
## Authentication
- Methods: none
- Secret environment variables: none
- Minimum permissions: No service credential is required; restrict filesystem and network access to the task.
- Credential storage: No service credential is stored for this CLI.
- Never print, persist, or commit credential values.
## Allowed commands (read-only)
- `rg --json --glob "*.ts" "pattern" src` — R0: Searches a bounded directory and emits one JSON event per line.
- `rg --files --null src` — R0: Lists files while respecting ignore rules.
## Commands requiring explicit approval (read-only)
- None recorded.
## Forbidden commands (read-only)
- None recorded.
## Execution rules
1. Mode boundary: R0 exact commands may be used; R1, R2, and R3 commands are forbidden.
2. Confirm the selected account, project, context, database, namespace, or environment before any command.
3. Prefer structured output using `--json`, `--null`.
4. Capture the exact command, exit code, stdout, and stderr separately.
5. A generated prefix policy must prompt unless that exact prefix is explicitly marked suffix-safe; do not infer safety from the executable name.
6. Never broaden credentials or disable safety controls to make a command succeed.
## Official sources
- [ripgrep guide](https://github.com/BurntSushi/ripgrep/blob/master/GUIDE.md)
- [ripgrep guide source repository](https://github.com/BurntSushi/ripgrep)
验证记录与官方证据
CLI Finder 分开记录文档检查和真实执行。未执行过的安装、帮助、退出码与输出不能标为 Verified。