Runtime Version: v1.0.1
This document provides a comprehensive command reference for the marshal command-line executable.
Usage: marshal [--json] <command> [arguments]
| Option | Description |
|---|---|
--json |
Format output as structured JSON instead of human-readable text |
Purpose: Creates missing project policy/version defaults and initializes the private .marshal/ runtime state directory inside the current Git repository. Existing regular defaults are preserved; symlinks in their place are rejected.
marshal initOutput:
initialized /path/to/repo/.marshal
Purpose: Reports whether a newer release exists and, when asked, installs it.
marshal update # check only
marshal update install # download, verify and replace this binaryThe check reads the published release feed and changes nothing. The install
takes the same verified path install.sh does: the archive for this machine is
checked against the release's published SHA-256, and a download that fails that
check is not installed, leaving the binary in place untouched. The new binary is
put in place by a rename, so it is never half-written.
Processes already running keep the build they started with. Start MARSHAL again to use the new one.
Set MARSHAL_NO_UPDATE_CHECK=1 to stop MARSHAL contacting the release feed at
all.
Purpose: Runs system health diagnostics, checking prerequisites, Git worktree capability, database integrity, file permissions, and provider binaries.
# Standard diagnostic check
marshal doctor
# Deep provider capability probing
marshal doctor --probe-providersFlags:
--probe-providers: Perform execution probing against installed LLM provider binaries.
Purpose: Connects to the local daemon socket and displays active runtime status, database schema version, active tasks count, and registered agents count.
marshal statusOutput:
schema=72 tasks=1 agents=1
Purpose: Starts the local MARSHAL control plane daemon process in the foreground. Listens on Unix socket .marshal/runtime.sock. Automatically cleans up dead PID files on startup.
marshal daemonPurpose: Registers a new agent principal in the SQLite database with an assigned engineering role.
marshal agent register --name <NAME> --role <ROLE>Flags:
--name: Human-readable name for the agent (e.g.OperatorAgent)--role: Assigned role (architect,developer,qa,security)
Example:
marshal agent register --name CodexDeveloper --role developerPurpose: Lists all registered agents in the workspace.
marshal agentsPurpose: Imports task definitions from a JSON file into the control plane SQLite database.
marshal task import <FILE.json> [--dry-run]Flags:
--dry-run: Validate task schema without committing to SQLite
Purpose: Displays all tasks currently tracked in the workspace database.
marshal tasksPurpose: Shows detailed state, revision, lease status, and branch metadata for a single task.
marshal task show <TASK-ID>Purpose: Claims a task lease for a registered agent principal.
marshal task claim <TASK-ID> --agent <AGENT-ID> [--revision <N>]Purpose: Releases an active task lease.
marshal task release <TASK-ID>Evaluates a declarative T49 JSON policy-test suite without activating or mutating a policy-test lifecycle run. The suite is strictly decoded and bound to the exact policy digest supplied by every case.
marshal policy test policy-suite.json
marshal --json policy test policy-suite.jsonPASS exits 0. A failed case, evaluator error, malformed/unknown-field
input, or unavailable file exits non-zero. Use --json for automation; the
typed status, policy_digest, case status, reason, and stable diff are the
source of truth rather than human output parsing. Raw fixtures, evaluator
output, and backend error text are not printed.
Purpose: Executes a ready task using a specified provider adapter and sandbox environment.
marshal run <TASK-ID> --adapter <ADAPTER> [--model <MODEL>] [--agent <AGENT-ID>]Flags:
--adapter: Provider adapter name (codex,opencode,gemini,claude)--model: Optional model override (e.g.qwythos-9bfor Ollama)--agent: Optional agent ID claiming execution
Example:
marshal run TASK-001 --adapter codex
marshal run TASK-001 --adapter opencode --model qwythos-9bThese drive the Process 03–08 lifecycle merged on main. Each stage writes a
durable, versioned record bound to an exact repository state. Every command here
reads canonical state or asks the runtime service to act; none can mint a
success state directly.
Purpose: States a request and shows how MARSHAL understands it — intent, hard constraints and risk tier — before any plan or execution exists.
marshal goal <request>
marshal goal explain <request>Purpose: Creates, inspects and approves a task plan: its DAG, team assembly and verification policy.
marshal plan create SESSION-ID --file INPUT.json
marshal plan show PROJECT-ID
marshal plan approve PROJECT-ID
marshal plan cancel PROJECT-ID
marshal plan handoff SESSION-ID PROJECT-IDPurpose: Drives a governed execution run, approves a pending gate, or rolls back to a checkpoint.
marshal exec start --session SESSION-ID --project PROJECT-ID
marshal exec run RUN-ID
marshal exec status RUN-ID
marshal exec approve APPROVAL-ID
marshal exec rollback CHECKPOINT-ID
marshal exec handoff RUN-IDPurpose: Runs independent verification and issues a digest-bound completion attestation. A run that exited zero is not a verified run; completion requires every mandatory criterion met and critical evidence from independent sources.
marshal review start SESSION.json
marshal review status VERIFICATION-ID
marshal review evaluate VERIFICATION-ID
marshal review attest VERIFICATION-ID --bundle ENVELOPE.json --provenance TEXTPurpose: Queries evidence-gated durable memory. Results carry their claim state, freshness and contradiction signals, so a stale or contested claim is returned marked unusable rather than silently omitted.
marshal learning search --project ID [--general] [--terms A,B] [--stale]
marshal learning show MEMORY-COMMIT-ID
marshal learning history ITEM-ID
marshal learning trust [TASK-CLASS]
marshal learning fingerprints --project ID
marshal learning playbooks --project ID
marshal learning export --project IDNotes:
trustreports measured routing outcomes including failures, blocked runs and routes that were never selected, alongside a selection-bias flag. An unmeasured cost prints asunmeasured, never as zero.playbookslists candidates only. A playbook never self-activates.
Purpose: Inspects optimization cycles, counterfactual route evaluations, benchmark manifests and bounded canaries.
marshal optimization start INPUT.json
marshal optimization show CYCLE-ID
marshal optimization candidates CYCLE-ID
marshal optimization counterfactuals CYCLE-ID
marshal optimization manifests CYCLE-ID
marshal optimization canaries CYCLE-IDNotes:
- A counterfactual is refused where the original run performed a destructive external effect, because re-running it would repeat that effect.
- Promotion, canary and rollback are runtime-service operations. This surface is read-only.
Purpose: Displays stdout/stderr execution logs, generated artifacts, and timeline events for a task.
marshal logs <TASK-ID>Purpose: Gracefully cancels an active task execution.
marshal cancel <TASK-ID>Purpose: Displays all registered provider adapters, discovered binary paths, and availability status.
marshal adaptersSample Output:
=== MARSHAL Provider Adapters ===
codex AVAILABLE binary=/home/user/.local/bin/codex version=codex-cli 0.146.0
gemini AVAILABLE binary=/usr/bin/gemini version=0.50.0
claude AVAILABLE binary=/home/user/.local/bin/claude version=2.1.218 (Claude Code)
opencode AVAILABLE binary=/home/user/.local/bin/opencode version=1.18.16
Purpose: Probes a specific provider adapter by name to test flags and binary responses.
marshal adapter probe <NAME>Purpose: Generates a high-entropy Bearer authentication token for MCP or A2A clients.
marshal auth token create --name <NAME>Output:
Created Token ID: TOKEN-e6eeb825c43740c7
Plaintext Token: marshal_token_6e86f061e255da6d5b075084e...
(Keep this token secret; it will not be shown again)
Purpose: Lists all active and revoked Bearer tokens.
marshal auth token listPurpose: Revokes a Bearer authentication token by Token ID.
marshal auth token revoke --id <TOKEN-ID>Purpose: Runs the Model Context Protocol (MCP 2026-07-28) server endpoint or checks server status.
# Start MCP HTTP server
marshal mcp serve [--listen ADDR]
# Check MCP status
marshal mcp statusPurpose: Runs the Agent-to-Agent (A2A 1.0) protocol server endpoint or checks server status.
# Start A2A HTTP server
marshal a2a serve [--listen ADDR]
# Check A2A status
marshal a2a statusPurpose: Displays the chronological audit log of workspace events.
marshal eventsPurpose: Lists all execution artifacts stored in .marshal/artifacts.
marshal artifactsPurpose: Runs repository verification commands against current code state.
marshal verify [-- command args...]Purpose: Reconciles workspace task state against file state.
marshal reconcile --file-state state.jsonPurpose: Launches the MARSHAL TUI v2 interactive multi-agent command center and control plane. When executed in an interactive terminal, running marshal without arguments also automatically opens the TUI.
# Launch interactive TUI
marshal tui
# Launch with specific options
marshal tui --session dev-session --theme high-contrast --no-animationFlags:
--session <id>: Attach to or resume a specific session ID (default:default)--theme <name>: Color theme:default,monochrome,high-contrast,no-color--no-animation: Disable micro-animations (spinners, pulse glyphs) for reduced-motion or low-bandwidth environments--no-color: Disable all ANSI terminal colors
For keyboard shortcuts, contextual autocomplete (Tab, @, #), Command Palette (Ctrl+P), diff viewer (d), and full slash command reference, see MARSHAL TUI v2 Documentation.