Detector::Python::Cli
Detects Python command-line applications: programs that parse argv via
argparse / getopt or a CLI framework (click, typer, fire, docopt, absl-py
flags, Cleo). Gates the Python CLI analyzer, which surfaces the argv /
option / env attack surface as cli:// endpoints.
Detection is intentionally import-anchored. A bare import sys
(sys.argv) is far too common to treat as CLI evidence on its own, so it
is only honored inside the analyzer when paired with a __main__ guard.
Constants
Class methods
The tech name without needing an instance, so the registry can be read off the classes themselves rather than from a parallel list.
Instance methods
Cheap filename-only filter the detector pass uses to skip
detect on files the detector cannot possibly match. The
default true preserves prior behavior (every detector runs on
every file). Override with the same predicate the body of
detect starts with — e.g., filename.ends_with?(".py") for a
Python framework detector — so the detector loop avoids the
detect dispatch on files outside the detector's language.
On large codebases (saleor's 4255 .py files) this lifts ~100
virtual detect calls per file out of the hot loop because
most detectors' inner first-line is exactly this kind of cheap
filename check.