Skip to main content
Glama

search_code

Read-only

Search a directory tree line by line for a JavaScript regular expression, such as a permission string or URL in decompiled output. Returns file, line, and trimmed matching text.

Instructions

Search a directory tree for a regular expression, line by line - e.g. a permission string or URL in decompiled output. Only reads files; skips files over 2 MB, and has a 10-second limit so a pathological regex errors instead of hanging. Returns { dirPath, filesScanned, matchCount, matches: [{ file, line, text, name }], truncated } where file is relative to dirPath, line is 1-based, text is the trimmed matching line (max 300 chars), and name is always "match". To look specifically for hardcoded credentials use scan_secrets instead.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
dirPathYesAbsolute path of the directory to search. Must exist.
patternYesA JavaScript regular expression tested against each line, e.g. "android\\.permission\\.[A-Z_]+". An invalid regex is rejected with an error.
workspaceNoWorkspace name (not id). Created if it doesn't exist, and this call is recorded as a job in its history. Defaults to "default".
extensionsNoOnly search files with these extensions - lowercase, with the leading dot, e.g. [".java", ".xml"]. Omit to search every file except known binary types (.apk, .dex, .zip, .jar, .so, images, fonts).
maxResultsNoStop after this many matches. Default and maximum 200.
caseSensitiveNoDefault false (case-insensitive).

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed10 schema fields changedv1.3.7
    • addedInput schema / properties / caseSensitive / default
      Added value: +false
    • addedInput schema / properties / caseSensitive / description
      Added value: +"Default false (case-insensitive)."
    • changedInput schema / properties / dirPath / description
      Previous value: -"Directory to search"New value: +"Absolute path of the directory to search. Must exist."
    • addedInput schema / properties / extensions / description
      Added value: +"Only search files with these extensions - lowercase, with the leading dot, e.g. [\".java\", \".xml\"]. Omit to search every file except known binary types (.apk, .dex, .zip, .jar, .so, images, fonts)."
    • addedInput schema / properties / maxResults / default
      Added value: +200
    • changedInput schema / properties / maxResults / description
      Previous value: -"Cap on results, default/max 200"New value: +"Stop after this many matches. Default and maximum 200."
    • addedInput schema / properties / maxResults / maximum
      Added value: +200
    • addedInput schema / properties / maxResults / minimum
      Added value: +1
    • changedInput schema / properties / pattern / description
      Previous value: -"A regular expression"New value: +"A JavaScript regular expression tested against each line, e.g. \"android\\\\.permission\\\\.[A-Z_]+\". An invalid regex is rejected with an error."
    • changedInput schema / properties / workspace / description
      Previous value: -"Workspace name (not id) - created automatically if it doesn't exist yet. Defaults to \"default\"."New value: +"Workspace name (not id). Created if it doesn't exist, and this call is recorded as a job in its history. Defaults to \"default\"."
  2. First observedv1.3.0

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only cover read-only and non-open-world; the description goes well beyond by disclosing the 2 MB file-size skip, the 10-second timeout that errors instead of hanging, and the truncation flag on results. These are exactly the operational traits an agent needs to predict failure modes.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three dense sentences front-load the purpose, then limits, then alternatives in a logical order. The return-shape sentence is packed but earns its place given there is no output schema; minor density rather than waste.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema present, the description compensates fully by spelling out the return object, the meaning of file/line/text/name fields, and the truncated flag. Nothing needed to call or interpret the tool is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so every parameter is already documented, and the description adds no new parameter-level guidance. Baseline 3 applies because the schema does the heavy lifting; the return-shape details belong to output semantics rather than parameters.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('search a directory tree for a regular expression, line by line'), and immediately differentiates from the sibling scan_secrets by routing credential searches there. An agent can place this tool precisely without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives concrete use cases ('a permission string or URL in decompiled output') and an explicit alternative with its selecting condition ('To look specifically for hardcoded credentials use scan_secrets instead'). The when-to-use is grounded and the alternative is named.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.