Skip to main content
Glama
papyruslabs-ai

Seshat

Official
README.md
# Seshat — structural code intelligence for AI agents

**Your agent reconstructs your codebase from likelihood. Seshat compiles it.**

Seshat turns a repository into a typed symbol graph (every function, class, route, and
table, with its *real* dependency edges, data flow, and constraints) and serves it to your
agent over MCP. So before your agent edits a function, it can ask what will actually break
instead of guessing.

Backed by a compiled intermediate representation, not text search or embeddings: if Seshat
says a function has three callers, it has exactly three.

## Why

AI coding agents are fast but structurally blind. When an agent changes one function, it
often cannot see everything that depends on it, so it silently breaks callers it never
looked at. A large share of AI-introduced regressions come from exactly this. Seshat gives
the agent the map.

## Try it first (no install, no login)

Paste any public repo at **https://seshat.papyruslabs.ai/try** and watch it trace what a
change would break.

## Install

```
npx -y @papyruslabsai/seshat-mcp setup <your-key>
```

Get a free key at **https://seshat.papyruslabs.ai** (first extraction is free). The setup
command writes your MCP config and stores the key.

Or configure manually (Claude Code, Cursor, or any MCP client):

```json
{
  "mcpServers": {
    "seshat": {
      "command": "npx",
      "args": ["-y", "@papyruslabsai/seshat-mcp"],
      "env": { "SESHAT_API_KEY": "your-key" }
    }
  }
}
```

## Tools

Point your agent at a repo with `sync_project`, then it investigates the way a senior
engineer does: orient, trace, verify.

**Orient**
- `list_projects` — what is synced
- `list_modules` — how the codebase is organized, by layer or module
- `query_entities` — find functions, classes, and routes by name, layer, or module
- `find_entry_points` — routes, exports, and the public API surface

**Investigate a symbol**
- `get_entity` — signature, callers, callees, data flow, side effects, and tables touched
- `get_dependencies` — the real call chain, callers and callees
- `get_blast_radius` — everything that breaks if you change it, transitively
- `get_data_flow` — what a function reads, returns, and mutates
- `get_optimal_context` — the minimal, ranked set of files to read before editing
- `find_by_constraint` — every function that touches a given table (or carries a given trait)
- `find_dead_code` — unreachable symbols, safe to delete

**Read the history** (from the repo's commit record, backfilled on first sync)
- `get_lineage` — how one function has actually changed: each commit typed by what moved
  (body, calls, data, signature), CI pass/fail and reverts, what changes alongside it, and
  what last forced a change here. Ask it before touching anything load-bearing.
- `get_hotspots` — where development happens and where it fails: the most-changed code,
  thrash spots where changes keep getting reverted or landing on red CI, and heavily used
  code nobody has touched (stability pressure)
- `get_co_change_clusters` — the hidden modules: code that changes together across files
  even when no import connects it, so a change to one member usually means the rest

Every answer comes from the compiled graph and discloses the coverage behind it. History
is commit-resolution correlation and says so; it never claims causation it can't show.

> Cross-cutting audit tools (test coverage, topology, semantic clones) are being hardened
> and will be added to this list as they land.

## Privacy

Analysis runs in the Papyrus Labs cloud, by design: the compiled graph is the product's
moat, and keeping extraction server-side is how that stays protected. Public repos are
cloned from GitHub; private repos require you to connect your GitHub account. Source is
processed to build the graph and cached to serve queries. See the privacy policy at
seshat.papyruslabs.ai.

## Pricing

First extraction is free. $0.03 per query after a free tier; a typical investigation is 5
to 15 queries. Details at https://seshat.papyruslabs.ai.

MIT licensed server. Named for the goddess who kept the records, built so your agent can
read them.

TDQS

A4/5.0

Scored across 27 tools

Disambiguation4/5

Tools have clearly distinct purposes, and descriptions actively cross-reference complementary tools (e.g., get_data_flow vs trace_data_path, query_traits vs find_by_constraint, get_dependencies vs get_blast_radius). A few pairs still require careful reading to distinguish—such as dependency tracing, blast radius, and optimal context—but the boundaries are explicitly stated.

Naming Consistency5/5

Every tool follows a consistent snake_case verb_noun pattern: get_, list_, find_, query_, sync_, trace_. No mixed conventions or vague names appear.

Tool Count3/5

27 tools is heavy for a single MCP server, though the deep code-intelligence domain justifies many specialized analyses. Several tools could likely be consolidated or grouped (e.g., multiple history and impact tools), but each addresses a distinct question.

Completeness4/5

Coverage is broad across structure, dependencies, data flow, history, architecture, security, testing, and dead code. Minor gaps exist for project lifecycle management (delete/update) and raw text/file search, but core analysis workflows are well covered.