Boring Infra Co.

Pico Quick Start

Install Pico and run your first workspace scan.


Install

curl -fsSL https://boringinfra.company/pico/install.sh | sh

Pico installs to ~/.pico/bin.

Initialize

pico init

This creates .pico/pico.db in your current directory and applies schema migrations.

Run a scan

pico scan

The foundation release records the scan lifecycle. Agent and provider discovery will populate the security graph in upcoming releases.

View history

pico history --json

Compare scans

pico diff --json

See the JSON output documentation for the v1 schema.

What to expect

Pico is early. Today you can:

  • Initialize a local security database
  • Record scan lifecycles
  • Export history and diffs as JSON

Coming soon:

  • Agent and MCP server discovery
  • Tool and permission mapping
  • Attack path analysis with findings
  • MCP integration for coding agents

Next steps