ggshield machine doctor
Description
Check that this machine's ggshield protections are correctly set up.
ggshield machine doctor [OPTIONS]
Verifies the AI hooks and git hooks are installed, that no higher-precedence
core.hooksPath override (e.g. Husky or lefthook) shadows ggshield's git hook
in the current context, that the GitGuardian token is reachable and carries the
scopes the configured protections need (including honeytokens:write and
ai-discover:send, granted only on Business or Enterprise plans), and — when
the machine_scan plugin is installed — that the token has the endpoint scope
(also Business/Enterprise-only) and the native scanner loads.
This is read-only: it never installs, scans, or changes anything. Each failed
check prints how to fix it (hooks via ggshield machine setup — except a
shadowing core.hooksPath, which git precedence means must be integrated into
that hook manager or unset; scopes via a token that carries them; the plugin via
ggshield plugin install). Exits non-zero if any check fails, so it can gate an
MDM rollout.
Options
This command supports all ggshield global options.