rg · Andrew Gallant

ripgrep Agent 使用指南

通过稳定的 JSON、glob、文件类型和上下文控制快速搜索源码树。

官方工具操作风险: R0R0verified
Agent 适配度
83/100
证据可信度
verified
文档检查日期
2026-07-10
独立测试版本
15.1.0

为 Agent 安装

选择与运行环境匹配的官方安装方式。在团队或 CI 环境中固定版本,并先运行版本检查。

Homebrew推荐
macos · linux
$ shell
brew install ripgrep
winget
windows
$ shell
winget install BurntSushi.ripgrep.MSVC
认证与最小权限
只提供任务需要的权限,凭证通过环境变量或平台密钥存储传入,不能写进提示词、仓库或日志。
无需认证支持无界面认证

无需服务凭据;仍应把文件系统和网络访问限制在任务范围内。

认证方式
none
密钥环境变量
None
凭据保存位置
此 CLI 不保存服务凭据。
Agent 与运行环境兼容性
先确认 Agent 能使用 Shell,再检查平台、网络与凭证是否可用。
claude-codecodexgemini-clicopilot-cli
Environments
local, ci, container, headless, remote
Platforms
macos, linux, windows

用于稳定自动化的结构化输出

优先使用机器可读格式,并把 stdout 作为结果、stderr 作为诊断信息分别处理。

json · text · null-delimited paths
在支持的命令中使用 --json 或 --null,并将诊断日志保留在 stderr。
--json--null

真实执行输出样例

15.1.0 · macOS 26.5.1 (arm64), local non-interactive shell

已执行命令
rg --json '"name"' package.json | jq -c 'select(.type == "match")'
捕获的 stdout · ndjson match event
{"type":"match","data":{"path":{"text":"package.json"},"lines":{"text":"  \"name\": \"clifinder-net\",\n"},"line_number":2,"absolute_offset":2,"submatches":[{"match":{"text":"\"name\""},"start":2,"end":8}]}}
样例 JSON Schema
{
  "type": "object",
  "required": [
    "type",
    "data"
  ],
  "properties": {
    "type": {
      "const": "match"
    },
    "data": {
      "type": "object",
      "required": [
        "path",
        "lines",
        "line_number",
        "submatches"
      ],
      "properties": {
        "path": {
          "type": "object"
        },
        "lines": {
          "type": "object"
        },
        "line_number": {
          "type": "integer"
        },
        "absolute_offset": {
          "type": "integer"
        },
        "submatches": {
          "type": "array"
        }
      }
    }
  }
}

R0–R3 命令风险指南

风险按单条命令判断。R0 是本地或远程只读,R1 是可逆的本地写入,R2 会改变远程状态,R3 可能造成不可逆或生产级影响。

只读不等于可公开

R0 只表示命令不更改本地或远程状态。只读命令仍可能返回令牌、身份信息、配置或生产数据;只展示完成任务所需的最少内容,不得写入日志、Prompt 或提交内容。

R0使用 JSON 事件搜索
搜索指定目录,并逐行输出 JSON 事件。
$ shell
rg --json --glob "*.ts" "pattern" src
可重复执行敏感输出
R0列出可搜索文件
列出文件并遵循忽略规则。
$ shell
rg --files --null src
可重复执行

Agent Readiness 评分依据

适配度描述 Agent 操作工具的稳定程度,不代表所有命令都安全,也不替代独立执行测试。

文档证据对应的 Agent Readiness 为 83/100;已记录 15.1.0 的有限本地 Smoke Test,使用未测试命令前仍需查看证据边界。

结构化输出
在支持的命令中使用 --json 或 --null,并将诊断日志保留在 stderr。
18/20
x
无界面运行
官方文档描述了非交互认证或执行路径。
14/15
x
安全控制
CLI Finder 将读取命令与需要确认的命令分开。
8/15
x
确定性
命令尽量使用显式参数和文档支持的输出控制。
8/10
x
认证
无需服务凭据;仍应把文件系统和网络访问限制在任务范围内。
10/10
x
文档
本条目引用了 2026-07-10 检查的官方文档。
9/10
x
安装
官方安装路径覆盖 macOS、Linux 和 Windows。
8/8
x
维护状态
条目链接了官方源码仓库,便于检查发布与维护状态。
6/7
x
Agent 产物
CLI Finder 可生成基于注册表的 Skill 和策略;该分数不假定工具自身提供这些产物。
2/5
x

生成 Skill 或 Agent 策略

选择目标 Agent 和安全模式,生成包含安装、允许命令、确认边界与证据说明的可复制产物。

生成结果预览
SKILL.md
---
name: ripgrep-agent-workflow
description: Use ripgrep for source search, pattern discovery, file type filtering with explicit command risk and evidence boundaries.
---

# ripgrep agent workflow

Use this skill when the task needs source search, pattern discovery, file type filtering, machine-readable matches.

## Evidence boundary

- Registry confidence: `verified`
- Documentation checked: `2026-07-10`
- Locally tested version: `15.1.0`
- Treat only the recorded executed checks as independently verified; every unlisted command remains documentation-only.

## Executed smoke checks

- `rg --version` — passed; exit 0. The recorded smoke check completed successfully.
- `rg --json --glob '*.ts' 'createFileRoute' src/routes` — passed; exit 0. The recorded smoke check completed successfully.
- `rg --json '"name"' package.json | jq -c 'select(.type == "match")'` — passed; exit 0. The NDJSON stream was reduced to the recorded match event without changing its payload.
- `rg --json 'definitely-no-clifinder-match' package.json` — expected-failure; exit 1. ripgrep returned its documented no-match exit status without writing diagnostics to stderr.

## Installation

- Homebrew (macos, linux): `brew install ripgrep`
- winget (windows): `winget install BurntSushi.ripgrep.MSVC`

## Authentication

- Methods: none
- Secret environment variables: none
- Minimum permissions: No service credential is required; restrict filesystem and network access to the task.
- Credential storage: No service credential is stored for this CLI.
- Never print, persist, or commit credential values.

## Allowed commands (read-only)

- `rg --json --glob "*.ts" "pattern" src` — R0: Searches a bounded directory and emits one JSON event per line.
- `rg --files --null src` — R0: Lists files while respecting ignore rules.

## Commands requiring explicit approval (read-only)

- None recorded.

## Forbidden commands (read-only)

- None recorded.

## Execution rules

1. Mode boundary: R0 exact commands may be used; R1, R2, and R3 commands are forbidden.
2. Confirm the selected account, project, context, database, namespace, or environment before any command.
3. Prefer structured output using `--json`, `--null`.
4. Capture the exact command, exit code, stdout, and stderr separately.
5. A generated prefix policy must prompt unless that exact prefix is explicitly marked suffix-safe; do not infer safety from the executable name.
6. Never broaden credentials or disable safety controls to make a command succeed.

## Official sources

- [ripgrep guide](https://github.com/BurntSushi/ripgrep/blob/master/GUIDE.md)
- [ripgrep guide source repository](https://github.com/BurntSushi/ripgrep)

这个任务该用 CLI、MCP 还是 API

CLI
适合在开发机、CI 或容器里复用现有 Shell、凭证和脚本,尤其适合短时、可观察的任务。
MCP
当 Agent 需要受控工具定义、委托身份或由服务端集中治理访问时,MCP 可能更合适。
API
当工作流是应用内长期集成、批量调用或事件驱动时,直接 API 往往比启动进程更稳定。
查看 CLI 与 MCP 完整对比

验证记录与官方证据

CLI Finder 分开记录文档检查和真实执行。未执行过的安装、帮助、退出码与输出不能标为 Verified。

当前证据边界
已在本地执行版本输出、仓库搜索、NDJSON 事件输出、单个 Match 事件提取和无匹配退出路径;未测试安装路径、其他平台、二进制文件、编码边界或任务范围外目录。
证据可信度
verified
独立测试版本
15.1.0 · 2026-07-10
测试环境
macOS 26.5.1 (arm64), local non-interactive shell

真实执行项

  • 通过退出码: 0
    rg --version

    已记录的 Smoke Check 成功完成。

    stdout 摘要

    ripgrep 15.1.0
  • 通过退出码: 0
    rg --json --glob '*.ts' 'createFileRoute' src/routes

    已记录的 Smoke Check 成功完成。

  • 通过退出码: 0
    rg --json '"name"' package.json | jq -c 'select(.type == "match")'

    NDJSON 流被筛选为已记录的 Match 事件,事件内容未被改写。

  • 预期失败路径退出码: 1
    rg --json 'definitely-no-clifinder-match' package.json

    ripgrep 在无匹配时返回了文档约定的退出状态,且未向 stderr 写入诊断信息。

官方来源
打开官方资料确认当前版本和命令。

替代工具与相关入口

在本地查找、解析、校验和转换文件与结构化数据。
通过清晰筛选、忽略规则和空字符分隔输出可预测地查找文件。
收集 PR 元数据并在本地检查补丁,先报告 blocker,不自动评论或合并。
先给 Claude Code 配置小而稳定的本地工具,再按当前仓库任务加入认证工具。
新 Agent 工作流和现代仓库搜索优先 ripgrep;已有环境或脚本依赖 ag 时可保留。

Agent 使用 ripgrep 的常见问题