
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@sylphx/repomap
Advanced tools
A map of your codebase for AI agents: code graph, search, call paths and change impact. No API key.
Code graph · hybrid search · call paths · change impact · an interactive graph UI.
One Rust binary. Local. No API key. MIT.
Live demo · Docs · Quickstart · Tools · Graph UI · Benchmarks · Compare
The real UI on excalidraw (687 files, indexed in under half a second): search, a symbol's code and callers, then the blast radius of a change. Try it in your browser, no install needed.
npx -y @sylphx/repomap setup # add repomap to Claude Code, Codex, Cursor, VS Code, Claude Desktop, Windsurf, Gemini CLI
npx -y @sylphx/repomap serve # open the graph UI for the current repo
That's it. Add --claude-hooks to also enrich Claude Code's Grep and Glob. setup detects the clients you have, writes their MCP config, and prints every change it made. Run it again and nothing changes. Then ask your agent: "Use repomap to map this repo."
{
"mcpServers": {
"repomap": { "command": "npx", "args": ["-y", "@sylphx/repomap", "mcp"] }
}
}
Claude Code: claude mcp add repomap -- npx -y @sylphx/repomap mcp
Claude Desktop, one click: download repomap-<version>.mcpb from the latest release, open it, and pick your project folder.
Claude Code plugin: /plugin marketplace add SylphxAI/repomap, then /plugin install repomap@repomap
Codex (~/.codex/config.toml):
[mcp_servers.repomap]
command = "npx"
args = ["-y", "@sylphx/repomap", "mcp"]
Docker (stdio, amd64/arm64):
{ "mcpServers": { "repomap": { "command": "docker", "args": ["run", "-i", "--rm", "-v", "/path/to/repo:/workspace:ro", "ghcr.io/sylphxai/repomap"] } } }
The server indexes the client's workspace root (or its working directory, or REPOMAP_ROOT). Every tool also takes root.
Agents burn most of their context on grep, ls and reading whole files just to work out where things are. repomap gives them the map up front:
parseConfig.file:line.git diff before you commit.All of it comes from a local index: tree-sitter parsing, a resolved import and call graph, PageRank, Louvain communities, BM25 over AST chunks, and a small static code embedding model (33 MB, downloaded once from Hugging Face, then offline). Nothing leaves your machine, and no API is called.
Six tools, each with an obvious job:
| Tool | Ask it | Returns |
|---|---|---|
map | "Give me the lay of the land" / focus: "src/server" | Modules, central files, key symbols, entry points; an outline with line numbers when focused |
search | "where are failed requests retried", "parseConfig" | Ranked file:line ranges (functions, methods, classes) by keywords, names and meaning, with the matching lines |
context | SessionStore.refresh, src/auth/token.ts, token.ts:42 | Code, callers (with call sites), callees, subtypes, members, imports, importers, tests |
trace | from: handleRequest, to: db.query | Shortest call path, or the call tree above/below a symbol |
impact | target: verifyToken or changed: true | Risk level, callers by depth, importing files, modules, tests to run |
db | table: users, or url_env: DATABASE_URL for a live database | Tables, keys, indexes, and the code (file:line) that queries each table |
Answers are compact text that cites file:line, so they cost few tokens. Pass format: "json" for structured output.
> impact target=decode
# Impact (LOW risk)
Changing: function decode (src/auth/token.ts:14)
1 direct caller, 3 symbols affected in total across 3 files and 2 modules; 1 file importing the changed files; no tests reach this.
## Direct callers (will break if the contract changes)
- function verifyToken — src/auth/token.ts:8
## Indirect (depth 2)
- method SessionStore.refresh — src/auth/session.ts:5
## Indirect (depth 3)
- function handleRefresh — src/api/router.ts:6
## Importing files
- src/auth/session.ts
The same commands work in your terminal: repomap map, repomap search "…", repomap context X, repomap trace A B, repomap impact --changed, repomap db.
npx -y @sylphx/repomap serve # live, with code preview
npx -y @sylphx/repomap export # repomap.html: one self-contained file you can publish
![]() | ![]() |
| Impact. Select a file and press i: everything that depends on it lights up by depth, with a list you can click through. | Code. Click a symbol to see its source, callers and callees. Open ↗ jumps to your editor or to GitHub. |
export writes one HTML file with deep links (#path/to/file) and GitHub links pinned to your commit. It's a good fit for a README, a wiki or a design review.npx -y @sylphx/repomap db # from migrations / Prisma / Drizzle / SQLAlchemy / Diesel
npx -y @sylphx/repomap db --url-env DATABASE_URL # live Postgres, MySQL or SQLite, read-only
npx -y @sylphx/repomap db users # one table: columns, indexes, who references it, where it is queried
npx -y @sylphx/repomap db --serve # the same graph UI, for tables and foreign keys
repomap reads your schema from the repository: SQL migrations (applied in order, with down migrations skipped), schema.prisma, Drizzle pgTable/mysqlTable/sqliteTable, SQLAlchemy and Flask-SQLAlchemy models, and Diesel table!. It can also introspect a live database. Each table is linked to the code that queries it: raw SQL (FROM users), Prisma (prisma.user.findMany), Diesel (users::table), and ORM models or tables used by files that import them.
Live connections are strictly read-only:
READ ONLY transaction that the server must confirm.START TRANSACTION READ ONLY transaction.query_only.Only catalog metadata is read, never table rows. The connection string comes from an argument or an environment variable, and it is never stored or printed. Agents get the same data through the db MCP tool; pass url_env rather than the URL itself.
npx -y @sylphx/repomap score
The score rates how well an AI agent can work in the repository, from 0 to 100. It covers eight checks:
Each check that falls short comes with a concrete fix, and the score ends with a badge line for your README. For CI, use --min 70; --update-readme README.md refreshes the badge.
Keep the badge fresh with the GitHub Action:
# .github/workflows/agent-ready.yml
on: { push: { branches: [main] } }
permissions: { contents: write }
jobs:
score:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: SylphxAI/repomap@v1
with:
update-readme: true # replaces the agent-ready badge (or inserts one under the title)
min-score: 0 # set e.g. 70 to fail below a bar
npx -y @sylphx/repomap setup --claude-hooks
This is opt-in and safe to run again; setup --remove takes it out. It installs a PreToolUse hook: whenever Claude Code runs Grep or Glob, repomap adds where the symbol is defined, who calls it and which module it belongs to. It answers in tens of milliseconds and never blocks the search.
repomap (code map) for this search:
- function `compose` defined at src/compose.ts:15 (module router); 3 callers: Hono.route (src/hono-base.ts:228), Hono.#dispatch (src/hono-base.ts:452), every (src/middleware/combine/index.ts:102)
Parsed with tree-sitter for symbols, calls, imports and inheritance: TypeScript, TSX, JavaScript, Python, Go, Rust, Java, Kotlin, Swift, C, C++, C#, Ruby, PHP. Search also covers Markdown, YAML, TOML, JSON, SQL, shell, Protobuf, GraphQL, HTML/CSS, Vue, Svelte, Scala and more.
Modules are found among your core code only. Tests, examples, docs and benchmarks are grouped separately, so they never name or blur a module.
Import resolution understands relative paths, @/ aliases, npm workspace packages, Python packages and relative imports, Go modules, Rust mod/use/workspace crates, Java/PHP namespaces, C/C++ includes and Ruby require. .gitignore is respected, and so is .repomapignore.
On semble's public code-search benchmark (63 repositories, 19 languages, 1,251 questions), repomap's search scores NDCG@10 0.851. semble, a tool built only for search, also scores 0.851 on the same runner. The 137M-parameter CodeRankEmbed model scores 0.839 and plain BM25 0.673. repomap 1.2 scored 0.685.
This needs no GPU, no vector database and no API key. A 33 MB static code model runs on the CPU, next to BM25 and symbol names.
The index is built in parallel and cached per file, so after the first run only changed files are parsed again. The MCP server keeps the graph in memory and refreshes it when files change.
Measured on a 4 vCPU GitHub-hosted runner (method and full table):
| Repository | Code files | Cold index | Warm index | search p50 | impact p50 |
|---|---|---|---|---|---|
| kubernetes | 11,710 | 13.0 s | 1.9 s | 73 ms | 6 ms |
| vscode | 6,126 | 9.2 s | 1.4 s | 16 ms | 8 ms |
| django | 2,271 | 2.6 s | 0.4 s | 24 ms | 1 ms |
| rust-analyzer | 1,512 | 2.1 s | 0.4 s | 7 ms | 2 ms |
| repomap | GitNexus | Serena | claude-context | Aider repo map | |
|---|---|---|---|---|---|
| Licence | MIT | PolyForm Noncommercial | MIT | MIT | Apache-2.0 (inside Aider) |
| Setup | npx … setup, one binary, or a one-click .mcpb | npx, Node | Python + language servers | Vector DB + embedding API key | Part of Aider |
| API key / network | None (model downloaded once) | None for the graph | None | Required (embeddings) | None |
| Code graph (calls, imports, inheritance) | ✅ | ✅ | Via LSP references | — | Ranking only |
| Change impact / blast radius | ✅ incl. git diff | ✅ | — | — | — |
| Call path between two symbols | ✅ | ✅ | — | — | — |
| Search | ✅ names + BM25 + local embeddings | ✅ | ✅ symbols | Semantic (vectors) | — |
| Interactive graph UI | ✅ local + static export | ✅ | — | — | — |
| Claude Code Grep/Glob hook | ✅ opt-in | ✅ | — | — | — |
| Database schema map linked to code | ✅ live (read-only) + migrations/ORMs | — | — | — | — |
| Agent-readiness score + badge | ✅ + GitHub Action | — | — | — | — |
| Module detection | ✅ Louvain | ✅ | — | — | — |
| Edits code | — (read-only) | — | ✅ | — | ✅ |
| Engine | Rust | TypeScript | Python | TypeScript | Python |
Pick Serena if you want LSP-precise refactoring edits. repomap is for understanding and navigating a codebase with zero setup, including semantic search without a vector database or an API key, and a licence you can use at work. Search quality is measured on public benchmarks in Benchmarks.
repomap setup [--client cursor,codex] [--claude-hooks] [--dry-run] [--remove]
repomap serve [dir] [--port 7878] [--no-open]
repomap export [dir] [--out repomap.html] [--json]
repomap map [dir-to-focus] [-C root] [--json]
repomap search <query> [--path src/] [--kind function] [--limit 10]
repomap context <target> [--code-lines 60]
repomap trace <from> [to] [--callers] [--depth 3]
repomap impact [targets…] [--changed] [--base main]
repomap db [table] [--url-env VAR | --url URL] [--serve | --out db.html] [--json]
repomap score [dir] [--json] [--min N] [--update-readme README.md [--insert]]
repomap index [dir] [--no-cache] [--json]
repomap mcp [--root dir]
Binaries for macOS (arm64, x64), Linux glibc (x64, arm64) and Windows x64 ship as npm optional dependencies. They're also attached to each GitHub release. From source: cargo install --git https://github.com/SylphxAI/repomap repomap.
@sylphx/spine, @sylphx/locus and @sylphx/coderag are thin aliases of @sylphx/repomap, and their old tool names still work until 2.0. See the migration guide for the name mapping and how to switch.
cargo test --workspace # engine + CLI tests
bun install && bun run build:ui # rebuild the UI bundle (ui/ -> crates/repomap/assets/)
cargo run -p repomap -- serve .
Issues and PRs are welcome, and new language support is especially useful: add a grammar and a query in crates/repomap-core/src/lang.rs.
anymd turns any file into clean Markdown for your AI agent: PDF, Word, PowerPoint, Excel, EPUB, HTML, images, and audio/video. Like repomap, it runs locally, needs no API key, and is MIT licensed.
MIT © Sylphx
FAQs
A map of your codebase for AI agents: code graph, search, call paths and change impact. No API key.
The npm package @sylphx/repomap receives a total of 2,018 weekly downloads. As such, @sylphx/repomap popularity was classified as popular.
We found that @sylphx/repomap demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.