Skip to main content
Glama

Cartograph

Agenten-native Code-Intelligenz. Verwandle jedes Repository in einen abfragbaren Code-Graphen und stelle ihn Code-Agenten über MCP bereit — damit ein Agent fragen kann: „Was bricht, wenn ich das ändere?“ statt zu greppen und zu hoffen.

tree-sitter + SQLite. Keine Embeddings, kein Vektor-Store, keine API-Schlüssel, kein Server, keine Kosten.

→ Live-Demo — generiert aus einem echten Index dieses Repos bei jedem Push.

CI Python 3.11+ License MIT


Das Problem

Gib einem Code-Agenten ein großes, unbekanntes Repo und beobachte, was es tut: grep, eine Datei lesen, nochmal grep, eine andere Datei lesen. Es verbrennt Kontext, um eine Struktur zu rekonstruieren, die ein Parser in einem einzigen Aufruf hätte liefern können – und es übersieht trotzdem den Aufrufer drei Module weiter, den seine Änderung gerade kaputt gemacht hat.

Die übliche Lösung ist RAG: Codebasis einbetten, „ähnliche“ Chunks abrufen. Aber „Wer ruft diese Funktion auf?“ ist keine Ähnlichkeitsfrage. Sie hat eine exakte Antwort, und diese Antwort lebt im Call-Graphen.

Cartograph baut den Graphen und gibt Agenten dann zehn Werkzeuge, die darauf zugeschnitten sind, wie sie tatsächlich arbeiten.

$ cartograph blast src/cartograph/graph/store.py

## Blast radius — file `src/cartograph/graph/store.py`

17 dependent file(s), 31 affected symbol(s), 7 test file(s).

**Tests to run first**
- `tests/test_cli.py`
- `tests/test_docs.py`
- `tests/test_incremental.py`
- `tests/test_mcp.py`
- `tests/test_resolver.py`
- `tests/test_traversal.py`
- `tests/test_views.py`

**Dependent files** (by import distance)
- `src/cartograph/graph/resolver.py` · d1
- `src/cartograph/indexer/pipeline.py` · d1
- `src/cartograph/service.py` · d1
- `src/cartograph/cli.py` · d2
…

Ein einziger Aufruf, vor der Bearbeitung. Nicht sieben Greps, nachdem die Testsuite rot wird.


Related MCP server: codeweave-mcp

Schnellstart

uv tool install cartograph-mcp     # or: pipx install cartograph-mcp

cartograph index ~/code/my-repo    # builds .cartograph/cartograph.db
cartograph arch                    # modules, layers, cycles, hotspots
cartograph blast src/auth/token.py # what a change here could break
cartograph callers validate_token  # reverse call tree

Binde es in einen Agenten ein

Claude Code:

claude mcp add cartograph -- cartograph serve /path/to/repo

Oder einen beliebigen MCP-Client über mcp.json:

{
  "mcpServers": {
    "cartograph": {
      "command": "cartograph",
      "args": ["serve", "/path/to/repo"]
    }
  }
}

serve indexiert beim ersten Lauf, wenn noch kein Index existiert. Frag dann deinen Agenten „Was würde brechen, wenn ich den Token-Validator ändere?“ und er wird blast_radius aufrufen, statt zu raten.


Die zehn Werkzeuge

Werkzeug

Antworten

find_symbol

Wo ist X definiert? (nach struktureller Wichtigkeit eingestuft)

search_code

Volltext über Namen, Signaturen, Docstrings (BM25)

get_symbol

Ein Symbol: Signatur, Doku, Member, Aufrufer, Aufgerufene, Quelle

who_calls

Rückwärts-Aufrufbaum – bevor du eine Signatur änderst

what_it_calls

Vorwärts-Aufrufbaum – Code verstehen, ohne jede Datei zu lesen

blast_radius

Was eine Änderung brechen könnte, und welche Tests ausgeführt werden sollten

related_symbols

„Was sollte ich sonst noch lesen?“ per personalisiertem PageRank

file_summary

Was eine Datei definiert, importiert und wer sie importiert

architecture_overview

Module, Schichtung, Importzyklen, Hotspots, Einstiegspunkte

index_stats

Index-Gesundheit und die Aufschlüsselung der Kantenauflösung nach Regel

Plus MCP-Ressourcen (cartograph://architecture, cartograph://stats) und einen orient-Prompt für einen graph-zentrierten ersten Durchgang durch ein unbekanntes Repo.

Sprachen: Python, TypeScript, TSX, JavaScript, Go.


Designentscheidungen, über die sich streiten lässt

1. Konfidenz ist eine erstklassige Spalte

Ohne Typchecker kannst du nicht wissen, dass store.who_calls() GraphStore.who_calls bedeutet. Du kannst Hypothesen nur einstufen. Statt also so zu tun, als wäre es eindeutig, zeichnet jede Kante die Regel auf, die sie erzeugt hat, plus eine Konfidenz:

Regel

Konfidenz

Intuition

same-file

0.95

die Definition ist direkt im Scope vorhanden

import

0.90

die Datei hat diesen Namen explizit importiert

receiver-type

0.85

Foo.bar(), wobei Foo ein bekannter Container ist

same-module

0.75

Geschwisterdatei im selben Paket

unique-global

0.60

genau ein Repo-Symbol hat diesen Namen, nackter Aufruf

name-only

0.45

eine Übereinstimmung, aber auf einem untypisierten Empfänger

ambiguous

≤0.40

N Kandidaten, als N Kanten zu je 1/N behalten

external

0.00

an einem Drittanbieter-/Stdlib-Import verwurzelt

unresolved

0.00

wirklich unbekannt (dynamisch oder eine typisierte Methode)

Die Aufrufer wählen dann ihren eigenen Arbeitspunkt. who_calls hat standardmäßig ≥0,5 – Präzision zuerst, weil ein Agent auf die Antwort handelt. blast_radius geht auf 0,3 herunter – Recall zuerst, denn ein übersehener betroffener Test ist der teure Fehler, und ein falsch Positives kostet einen Reviewer nur einen Blick.

Diese name-only-Stufe existiert wegen eines echten Bugs. seen.add(...) auf einem eingebauten set wurde der add-Methode einer Repo-Klasse zugeordnet, nur weil der Name zufällig eindeutig war – und es tauchte als Aufrufer mit hoher Konfidenz auf. Ein Methodenname auf einem Empfänger, den du nicht typisieren kannst, ist kein Beleg, also landet er jetzt unterhalb der Präzisionslinie. (test)

external existiert, um bei den Metriken ehrlich zu sein: In den meisten Repos wird der „unresolved“-Eimer von typer.Option und sqlite3.execute dominiert. Wenn man sie dazurechnet, sieht die Abdeckung viel schlechter aus, als sie ist. Deshalb meldet Cartograph die interne Auflösung – von den Aufrufstellen, die ein Repo-Symbol treffen könnten, wie viele es getan haben.

2. Parsing ist inkrementell; Auflösung nie

Eine Datei wird nur neu geparst, wenn sich ihr sha256 ändert. Aber rohe Referenzen werden als Fakten in einer refs-Tabelle gespeichert, und edges wird als reine Funktion von (refs × symbols) neu berechnet, wenn sich etwas geändert hat.

Das macht „nach jeder Bearbeitung neu indexieren“ vertrauenswürdig. Wenn die Auflösung ebenfalls inkrementell wäre, könnte das Bearbeiten einer Datei eine Kante in einer anderen Datei hinterlassen, die auf ein verschobenes Symbol zeigt. Globale Neuauflösung macht das strukturell unmöglich. (test)

Die Kosten sind real, daher gibt es genau eine sichere Abkürzung: Wenn keine Datei hinzugefügt, neu geparst oder entfernt wurde, sind beide Eingabetabellen unverändert und die Auflösung ist nachweislich identisch – also wird sie übersprungen. Das hat einen No-op-Reindex von Django von 7,5s auf 0,67s reduziert, mit einem byte-identischen Graphen.

3. PageRank statt Embeddings

„Welchen get meintest du?“ ist eine strukturelle Frage. Der get, von dem vierzig Aufrufstellen abhängen, ist der, den der Agent will, und der Call-Graph weiß das bereits. Daher ist das Symbol-Ranking ein gewichteter PageRank über den Call-Graphen – stabil, erklärbar und kostenlos. Kein Modell, kein Indexaufbau, kein Vektor-Store.

related_symbols erweitert dieselbe Idee: personalisierter PageRank, der mit einem Symbol gestartet wird, wobei der Graph als ungerichtet behandelt wird, denn wenn du eine Funktion ändern willst, sind sowohl ihre Aufrufer als auch ihre aufgerufenen Funktionen relevanter Kontext. Es ist das strukturelle Gegenstück zur semantischen Suche und benötigt keine Embeddings.

4. Werkzeuge liefern Markdown, nicht JSON, unter einem Token-Budget

Der Konsument ist ein Kontextfenster. Ein JSON-Array mit 40 Symbolen verbraucht Tausende von Token für geschweifte Klammern und wiederholte Schlüssel, und das Modell formatiert es ohnehin neu. Jede Ansicht hier ist kompaktes Markdown mit einem harten Token-Budget.

Entscheidend ist, dass jede Kürzung angekündigt wird. Ein Agent, dem 20 von 87 Aufrufern ohne Marker übergeben werden, wird zuversichtlich schlussfolgern, dass die anderen 67 nicht existieren, und dann etwas löschen.

5. Traversierung läuft in SQLite, nicht in Python

who_calls auf Tiefe 4 ist ein rekursiver CTE, sodass die gesamte Traversierung in der C-Schleife von SQLite bleibt. Bei Djangos Graphen mit 252k Kanten sind das ~5ms. Die Kantentabelle nach Python zu holen, um sie zu durchlaufen, wäre das nicht.


Benchmarks

Echte Repositories, M-Serie-Laptop, einzelner Prozess. Kalt = vollständiger Index von Grund auf; warm = No-op-Reindex.

Repo

Dateien

KLOC

Symbole

Kanten

Kalt

Warm

DB

Interne Auflösung

django

2,973

534

45,394

252,441

11.9s

0.67s

80 MB

83.2%

gin (Go)

98

24

1,610

9,179

0.32s

0.03s

2.5 MB

88.1%

flask

83

18

1,624

4,271

0.21s

0.03s

1.7 MB

87.4%

Abfragelatenz (Median von 5, warm):

Repo

find_symbol

who_calls d3

blast_radius

architecture_overview

django

12.3ms

5.1ms

5.6ms

68.5ms

gin

0.4ms

0.4ms

0.5ms

1.2ms

flask

0.5ms

1.1ms

1.3ms

1.8ms

Reproduzierbar mit scripts/bench.py.


Architektur

flowchart LR
  subgraph index["cartograph index"]
    W[walker<br/>git ls-files] --> P[tree-sitter<br/>+ .scm queries]
    P --> X[extract<br/>defs · refs · imports]
  end
  X --> DB[(SQLite<br/>symbols · refs<br/>edges · FTS5)]
  DB --> R[resolver<br/>rule cascade]
  R --> DB
  DB --> RK[PageRank<br/>Tarjan SCC]
  RK --> DB
  DB --> S[service facade]
  S --> V[views<br/>token-budgeted MD]
  V --> M[MCP server<br/>10 tools]
  V --> C[CLI]
  M --> A((coding agent))

Modul

Verantwortung

indexer/walker.py

Dateierkennung – verlässt sich auf git ls-files für korrekte .gitignore-Semantik

indexer/languages.py

Ein Adapter pro Sprache: Erweiterungen, Queries, Docstrings, Modulschlüssel, Importauflösung

indexer/extract.py

AST → Symbole/Referenzen/Importe, sprachunabhängig

queries/*.scm

tree-sitter-Capture-Muster – das sprachspezifische Wissen als Daten

graph/schema.sql

Der Graph: files, symbols, refs, edges, imports, FTS5

graph/resolver.py

Die Konfidenz-Kaskade

graph/algorithms.py

PageRank, personalisierter PageRank, iteratives Tarjan-SCC, Schichtung

graph/store.py

Rekursive-CTE-Traversierung, rangierte Suche, Aggregate

service.py

Eine Fassade, damit CLI und MCP-Server nicht auseinanderdriften

views.py

Markdown mit Token-Budget

Scoping ohne kombinatorische Queries

Der Trick, der queries/*.scm klein hält: Der Scope wird nie in der Query kodiert. Jede erfasste Definition wird über ihre tree-sitter-Node-ID indexiert, und das umgebende Symbol einer Referenz wird gefunden, indem man ihre parent-Kette entlanggeht, bis man auf eines trifft. Das ist O(Baumtiefe) pro Referenz und handhabt Closures, Methoden, innere Klassen und Pfeilfunktionen kostenlos – keine Muster pro Form.

Hinzufügen einer Sprache

Erstelle eine Unterklasse von LanguageAdapter (~40 Zeilen) und lege eine .scm-Datei ab. GoAdapter ist das kürzeste vollständige Beispiel. tests/test_queries.py kompiliert dann deine Queries automatisch gegen die Grammatik und stellt sicher, dass sie etwas erfassen.


Entwicklung

git clone https://github.com/GokulRaj2210/cartograph-mcp && cd cartograph-mcp
uv sync
uv run pytest -q          # 209 tests
uv run ruff check .
uv run mypy               # strict

Die CI führt die Suite auf Python 3.11/3.12/3.13 (plus macOS) aus und betreibt dann Dogfooding: Sie indexiert dieses Repo, schlägt bei Importzyklen fehl, stellt sicher, dass ein No-op-Reindex nichts neu parst, und steuert den MCP-Server über echtes stdio. Außerdem installiert sie das gebaute Wheel in eine saubere venv und indexiert damit, denn verpackte .scm-Dateien lassen sich leicht aus einem Wheel weglassen und lokal unmöglich bemerken.

Das Zyklus-Gate hat sich bereits bezahlt gemacht – es hat einen store → resolver → store-Zyklus erwischt, den ich in diesem Repo eingeführt hatte, und der behoben wurde, indem der verursachende Helfer verschoben wurde, statt das Gate zu lockern.

Bemerkenswerte Tests

  • tests/test_queries.py — jede .scm-Datei kompiliert gegen jede Grammatik, die sie lädt, und erfasst etwas. Ein in JavaScript gültiges Muster ((class_heritage (identifier))) ist in TypeScript ein unmögliches Muster, da TypeScript Supertypen in extends_clause kapselt. Diese eine Zeile erzeugte stillschweigend null TypeScript-Symbole.

  • tests/test_incremental.py — keine veralteten Kanten nach Bearbeitungen, Löschungen oder wenn ein Symbol zwischen Dateien verschoben wird.

  • tests/test_resolver.py — jede Regel greift, und keine überschätzt ihre Konfidenz.

  • tests/test_cli.py — ein Leser und ein Indexierer können die Datenbank gleichzeitig geöffnet halten.

  • tests/test_docs.py — die generierte Demoseite ist wohlgeformtes HTML mit ausbalancierten Tags, wodurch der Überkreuz-Tag-Fehler des Markdown-Renderers bei min_confidence entdeckt wurde.


Einschränkungen

Ganz offen gesagt: Ein Code-Intelligence-Tool, das seine Präzision übermäßig anpreist, ist schlimmer als nutzlos.

  • Keine Typinferenz. self.conn.execute(...) kann ohne Kenntnis des Typs von conn nicht zu einem Repo-Symbol aufgelöst werden. Diese landen in unresolved und bilden den Großteil dessen, was bei einer internen Auflösung von ~85% übrig bleibt.

  • Dynamischer Dispatch ist unsichtbar. getattr(obj, name)(), Dekorator-Registries und DI-Container erscheinen nicht als Kanten.

  • Sprachübergreifende Kanten werden nicht erfasst. Ein TypeScript-Frontend, das einen Python-Endpunkt aufruft, ergibt zwei getrennte Teilgraphen.

  • Nur Definitionen, nicht jede Referenz. Ein Symbol, das als Wert verwendet wird (als Callback übergeben), ist im Graphen schwächer als eines, das aufgerufen wird.

Roadmap: Rust- und Java-Adapter, optionale LSP-Anreicherung für exakte Auflösung, wenn ein Sprachserver verfügbar ist, und ein --changed-since <ref>-Modus für den Blast-Radius auf PR-Ebene.


Warum es das gibt

Ich wollte wissen, ob die größte Schwäche eines Coding-Agenten bei großen Repos – kein strukturelles Modell des Codes – durch statische Analyse und eine gut gestaltete Tool-Oberfläche behoben werden kann, statt durch ein größeres Modell oder eine Vektordatenbank. Größtenteils ist das möglich.

Lizenz

MIT

Available Tools

10 tools
architecture_overviewA

Orient yourself in an unfamiliar repo: modules, layers, cycles, hotspots.

Start here. One call replaces a dozen exploratory file reads: you get module sizes and layering, import cycles, the highest-PageRank symbols (the risky ones to change) and the repo's entry points.

ParametersJSON Schema
NameRequiredDescriptionDefault
include_diagramNoInclude a Mermaid diagram of the module graph

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the safety/behavior burden. It discloses what the call produces and signals efficiency by replacing 'a dozen exploratory file reads', making the operation's analytic, non-mutating nature clear through the 'you get...' framing. It stops short of stating any performance or read-only caveats explicitly.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two dense sentences with no filler; the purpose is front-loaded and the supporting details (what it returns) are listed compactly. Each clause earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-optional-parameter tool with an output schema, the description covers the key contextual information: when to use it, what to expect, and why it is valuable. Nothing critical is missing for an agent to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, and the single include_diagram parameter is fully documented in the schema. The description adds no parameter-specific guidance beyond the schema, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a specific verb and resource ('Orient yourself in an unfamiliar repo') and enumerates concrete outputs (module sizes/layering, import cycles, PageRank hotspots, entry points). It clearly differentiates from symbol-level siblings like find_symbol and who_calls by positioning itself as the repo-level starting point.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'Start here' and 'one call replaces a dozen exploratory file reads' provide explicit context for when to use it: early exploration of an unfamiliar codebase. It does not explicitly state when not to use it or name an alternative, so it misses the full 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

blast_radiusA

Impact analysis: what a change here could break, and which tests to run.

Combines the reverse import graph with the reverse call graph, then highlights test files specifically. Recall-first by design (confidence >=0.3): the expensive mistake is a missed impacted test, not an extra one.

Call this before editing shared code and after finishing, to pick tests.

ParametersJSON Schema
NameRequiredDescriptionDefault
depthNoTransitive import/call depth
limitNoMax results
targetYesA file path or a symbol name/qualname

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden of behavioral disclosure. It explains the internal approach (combining reverse import graph with reverse call graph), the recall-first bias with a specific confidence threshold of >=0.3, and the rationale that missed impacted tests are worse than extra ones. It does not explicitly state that the operation is read-only or safe, but the impact-analysis framing implies it.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is short and front-loaded: the purpose is in the first sentence, methodology and behavior in the second, and usage guidance in the final sentence. Every sentence adds distinct value with no repetition or filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the output schema is present and the parameter schema fully describes the inputs, the description provides the necessary context: what the tool computes, how it prioritizes recall, what it highlights, and when to call it. An agent has enough to invoke it correctly and interpret its role relative to siblings.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, and the schema already documents target, depth, and limit with meaningful descriptions. The tool description adds no parameter-specific guidance beyond the schema, so the baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a clear purpose: 'Impact analysis: what a change here could break, and which tests to run.' It also differentiates itself from siblings by explaining it combines the reverse import graph with the reverse call graph and specifically highlights test files, which sets it apart from who_calls, what_it_calls, and related_symbols.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit context for when to use the tool: 'Call this before editing shared code and after finishing, to pick tests.' It does not explicitly name alternatives or state when not to use it, but the workflow guidance is clear and actionable.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

file_summaryA

Outline of one file: what it defines, what it imports, who imports it.

Cheaper than reading the file when you only need to know whether it is relevant, and it adds the reverse-import view that reading cannot give you.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesFile path, or any distinctive part of one

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the burden of explaining behavior. It discloses what the outline contains (definitions, imports, importers) and notes that it is cheaper than full file reading. It does not discuss edge cases like partial paths, errors, or cache behavior, but for a simple summary tool this is reasonably transparent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two compact sentences put the core purpose first and the cost/use-case benefit second. Every sentence earns its place; there is no filler or redundant restating of the tool name.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter tool with an output schema, the description explains what the result contains and why one would choose this tool. It could be slightly stronger about how this compares to adjacent sibling tools, but nothing essential is missing for a basic invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the sole parameter is already well described. The description adds no new parameter-level detail, which is acceptable since the schema fully documents the path parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly identifies the tool's scope: an outline of one file covering definitions, imports, and reverse-imports. This distinguishes it from generic search or symbol tools by naming the specific resource and output aspects.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly frames the tool as a cheaper alternative to reading a file when only relevance matters, and highlights the reverse-import advantage. It does not name sibling tools or provide explicit when-not-to-use guidance, but the intended scenario is clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

find_symbolA

Locate where a symbol is DEFINED, with its file:line, signature and doc.

This is the right first call for "where is X?" -- it is exact and ranked by structural importance, so if a repo has six functions called run, the one the codebase actually revolves around comes first.

Use search_code instead when you only know roughly what the thing does ("the retry logic") rather than what it is called.

ParametersJSON Schema
NameRequiredDescriptionDefault
kindNoFilter by kind: function, method, class, interface, struct, enum, type, const
langNoFilter by language: python, typescript, tsx, javascript, go
nameYesSymbol name or qualified name, exact or partial
limitNoMax results

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description carries the burden. It discloses a key behavioral trait: results are 'ranked by structural importance', illustrated with the six-run-functions example. It also mentions exactness and the output shape, though it does not discuss limitations like auth or rate limits.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences with no filler: the main purpose is front-loaded, the ranking behavior is immediately explained, and the alternative tool condition is given once. Every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists and the parameter schema is fully documented, so the description need not restate return types or parameter details. It supplies the missing context: when to use, how results are ranked, and when to switch to search_code, making it complete for an AI agent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all four parameters. The description adds little beyond contextual emphasis on exactness and ranking; it does not deepen meaning for kind, lang, name, or limit beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: 'Locate where a symbol is DEFINED', with concrete outputs (file:line, signature, doc). It also distinguishes from the sibling search_code by positioning itself as the exact lookup for known symbol names, so an agent can tell when to use it.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly says this is the right first call for 'where is X?' and names the alternative: use search_code when you only know roughly what the thing does. This gives clear selection criteria without the agent needing to infer.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_symbolA

Full detail for one symbol: signature, doc, members, callers and callees.

Prefer this over reading the whole file: you get the definition plus its immediate graph neighbourhood, which is usually all the context needed to make a safe edit. Set include_source=true when you intend to modify it.

ParametersJSON Schema
NameRequiredDescriptionDefault
depthNoCaller/callee depth to include
symbolYesSymbol id, qualified name (`module:Class.method`), `path:name`, or bare name
include_sourceNoInclude the full source text of the definition

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the burden of behavioral disclosure. It usefully states the returned artifacts (definition plus graph neighborhood) and the include_source toggle, but does not explain depth behavior, error cases, or cost of deep traversal. This is adequate but not deeply transparent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tightly packed paragraphs with no filler. The core purpose is in the first sentence, and the practical guidance follows immediately. Every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the output schema exists and parameter docs are complete, the description covers the essential context: what the tool returns, why to prefer it, and when to enable source. It doesn't cover depth semantics or error behavior, but those are partially covered in the schema and are minor for a read-only lookup tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds meaningful usage semantics for include_source ('when you intend to modify it') that goes beyond the schema, and the symbol parameter's accepted forms are already well documented in the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: 'Full detail for one symbol' with concrete contents (signature, doc, members, callers, callees). This clearly differentiates get_symbol from siblings like search_code, who_calls, and what_it_calls by scoping it to a single symbol's combined context.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives explicit usage guidance: prefer this over reading the whole file, and set include_source=true when you intend to modify the symbol. It does not explicitly name all sibling alternatives or when those would be better, but the 'prefer this over...' framing gives clear decision context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

index_statsA

Index health: size, coverage, and the edge-resolution breakdown by rule.

Worth a call when graph answers look thin -- a low resolution rate or a stale indexed_at tells you the index needs rebuilding rather than the code being unusual.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the burden of behavioral disclosure. It explains what the tool reports, including size, coverage, resolution breakdown, and indexed_at, and adds diagnostic meaning beyond a simple field list. It does not explicitly state that the tool is read-only, but for a stats tool this is strongly implied by the content described.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and front-loaded: the first sentence states exactly what the tool reports, and the second sentence gives actionable usage guidance. Every sentence earns its place with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a zero-parameter tool with an output schema available, the description provides everything needed to decide when and how to use it. It explains the tool's purpose, the data it returns, and the diagnostic scenario in which it is useful, leaving no meaningful gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so there are no parameter meanings to clarify. The description still adds conceptual value by naming the key output dimensions (size, coverage, edge-resolution breakdown, indexed_at), which is appropriate for a parameterless tool.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly identifies the resource and content ('Index health: size, coverage, and the edge-resolution breakdown by rule'), which immediately distinguishes it from the symbol-focused sibling tools. However, it lacks an explicit verb like 'reports' or 'returns', so it falls just short of the strongest purpose clarity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives an explicit trigger: 'Worth a call when graph answers look thin'. It also explains how to interpret results ('low resolution rate or a stale indexed_at tells you the index needs rebuilding rather than the code being unusual'), which is excellent practical guidance for when this tool is the right choice.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

search_codeA

Full-text search across symbol names, signatures and docstrings (BM25).

Use when you know the intent but not the identifier. Results are re-ranked by call-graph importance, so central symbols outrank incidental mentions.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMax results
queryYesFree-text query over names, signatures and docstrings

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations are absent, so the description carries full behavioral disclosure. It discloses that search uses BM25 and that results are re-ranked by call-graph importance, which is valuable non-obvious behavior. It could mention pagination or query-syntax details, but the core operation and ordering semantics are transparent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences with no filler: the first defines scope, the second states when to use it, and the third explains ranking behavior. Every sentence earns its place, and the key use-case guidance is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the output schema and only two straightforward parameters, the description is nearly complete. It covers the tool's purpose, use case, searchable content, and result ordering. It does not explicitly state exclusions or name the exact-identifier sibling, but the sibling context and 'not the identifier' phrasing make the intended boundary clear.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema describes both parameters completely, so the baseline is 3. The description reinforces that `query` is free-text and explains why certain matches outrank others, but it does not add per-parameter syntax or formatting detail beyond what the schema already provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb ('Full-text search') and a precise resource scope ('symbol names, signatures and docstrings'). The phrase 'Use when you know the intent but not the identifier' clearly distinguishes it from exact-identifier lookup tools such as find_symbol.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives an explicit usage condition: use it when the intent is known but the identifier is not. It does not name the alternative tool directly, but the contrast with exact-lookup siblings is strongly implied by the wording and the sibling list.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

what_it_callsA

Forward call tree: what this symbol depends on, transitively.

Use it to understand an unfamiliar function without reading every file it touches, and to spot the layer a piece of code really sits in.

ParametersJSON Schema
NameRequiredDescriptionDefault
depthNoTransitive callee depth
limitNo
symbolYesSource symbol (name, qualname or id)
min_confidenceNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the behavioral burden. It discloses the transitive, graph-walking nature of the tool, but does not mention performance characteristics, result size limits, or other runtime behavior beyond what the schema hints at.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and front-loaded, with the core definition in the first sentence and practical guidance in the second. No filler or redundant restatement of the tool name.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description provides enough context for an agent to understand the tool's purpose and basic invocation. Some gaps remain around parameter semantics and explicit sibling differentiation, but the output schema and schema constraints partially fill those gaps.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 50%: symbol and depth are documented, but limit and min_confidence lack descriptions. The tool description does not compensate by explaining these parameters or clarifying their units/purpose.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: build a forward call tree of what a symbol transitively depends on. This distinguishes it from reverse-call tools like who_calls, though it does not explicitly name siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides concrete use cases: understanding an unfamiliar function without reading every file, and identifying the layer a piece of code sits in. It gives clear context but does not state when to prefer an alternative tool or when not to use this one.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

who_callsA

Reverse call tree: everything that reaches this symbol, transitively.

The tool to use before changing a signature, tightening a validation, or deleting anything. Each edge reports the rule that produced it; treat sub-0.5 edges as leads rather than facts.

ParametersJSON Schema
NameRequiredDescriptionDefault
depthNoTransitive caller depth
limitNoMax results
symbolYesTarget symbol (name, qualname or id)
min_confidenceNoMinimum edge confidence (0.5 = precision-first)

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the behavioral burden. It discloses that each edge reports the rule that produced it and warns that sub-0.5 edges are leads rather than facts. It does not discuss cost or traversal size, but the output schema covers result shape.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three compact sentences deliver the definition, the trigger scenario, and the confidence caveat. The description is front-loaded with the core purpose and every sentence adds distinct value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only analysis tool with a full output schema and fully documented parameters, the description covers what the tool computes, when to use it, and how to interpret weak results. Nothing essential is missing for selecting and invoking it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

All four parameters already have schema descriptions, so the baseline is 3. The description adds meaningful semantics for min_confidence, explicitly saying sub-0.5 edges should be treated as leads, and implies that depth and limit control transitive expansion.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action and resource: 'Reverse call tree: everything that reaches this symbol, transitively.' This clearly distinguishes it from forward-call tools like what_it_calls without needing extra inference.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives concrete guidance on when to use the tool: 'The tool to use before changing a signature, tightening a validation, or deleting anything.' It does not explicitly list exclusions or alternatives, but the use-case framing is clear and actionable.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 10 tool updatesv0.1.0
    • First observedarchitecture_overview
    • First observedblast_radius
    • First observedfile_summary
    • First observedfind_symbol
    • First observedget_symbol
    • First observedindex_stats
    • First observedrelated_symbols
    • First observedsearch_code
    • First observedwhat_it_calls
    • First observedwho_calls

TDQS

A4/5.0

Scored across 10 tools

Disambiguation4/5

Tool purposes are largely distinct and descriptions explicitly route agents to the right one, but find_symbol/get_symbol and who_calls/blast_radius have adjacent responsibilities that could occasionally cause misselection. Overall, the overlap is minor and well-documented.

Naming Consistency3/5

All names are readable snake_case, but the set mixes verb-object names (find_symbol, search_code, get_symbol), question-style names (who_calls, what_it_calls), and noun-phrase names (blast_radius, file_summary, architecture_overview). This is not chaotic, but it lacks a single consistent naming pattern.

Tool Count5/5

Ten tools is a well-scoped surface for a code-graph analysis server. Each tool addresses a distinct job—search, symbol detail, call trees, impact analysis, overview, index health—without redundancy or bloat.

Completeness4/5

The toolchain covers symbol discovery, detailed lookup, dependency analysis, impact assessment, file outlining, architecture orientation, and index health, giving strong coverage of the code-understanding workflow. Minor gaps like direct raw-file access or listing all symbols in a file must be worked around via file_summary and get_symbol.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

  • Code intelligence platform for AI agents. 20 tools for architecture, security & impact analysis.

  • Codebase graphs, caller impact analysis, and recorded project context for AI coding agents.

  • The Cortex MCP server provides read-only access to real-time engineering context from the Cortex developer portal, allowing AI coding assistants to answer natural language questions about your organization's catalog (microservices, libraries, domains, teams, infrastructure), scorecards (engineering standards and best practices), initiatives (goals and deadlines), and Engineering Intelligence metrics. It includes tools for querying documentation, tracking personal entities, and accessing AI-assisted insights across the entire Cortex ecosystem.

  • Coding agents in multi-service codebases routinely rebuild existing helpers, trust stale type definitions, and modify API contracts without knowing who consumes them. Carrick solves this by indexing your entire TypeScript ecosystem across service and repository boundaries. By integrating deeply with the TypeScript compiler, Carrick traces every route, type, and cross-service call while recording function behaviour so agents search by intent rather than name. Delivered via MCP for AI agents and LSP for IDEs, Carrick ensures models see existing endpoints and utilities before generating new code. The scanner is source-available and runs from your CLI or CI pipeline.

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    RepoNova is an MCP server that builds a persistent knowledge graph of your codebase, enabling AI agents to query code structure, dependencies, and semantics through 11 specialized tools.
    174 npm
    7
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    An MCP server that gives AI agents structured code understanding and precise code intelligence via local indexing of AST, call graphs, and semantic search.
    147 npm
    4
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server that generates ranked, token-budgeted code structure maps using Tree-sitter AST analysis and PageRank, enabling AI agents to quickly understand unfamiliar codebases.
    2
    20 npm
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    MCP server for local-first code intelligence, providing structural code graph, semantic search, and impact analysis to AI agents.
    2
    MIT