
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
CSS intelligence for AI coding agents — surgical style context, fewer tool calls, faster answers. 100% local.
Surgical style context · fewer tool calls · faster answers · 100% local
When an AI agent needs to understand CSS — where is .btn-primary defined, what properties does it have, which other selectors override it — it discovers style the slow way: grep, glob, and Read, one file at a time, reconstructing the cascade by hand.
cssgraph hands the agent the exact style context it needs in one call. It's a pre-built knowledge graph of every className, CSS property, variable, and at-rule in your stylesheets — so instead of crawling files, the agent asks one question and gets back the properties, overrides, specificity, and callers in full.
npm i -g cssgraph
Requires Node.js >= 22.5.0 (for built-in node:sqlite).
cd your-project
cssgraph init
cssgraph init creates the local .cssgraph/ directory and builds the full style graph in one step.
Add to your agent's MCP server config:
{
"mcpServers": {
"cssgraph": {
"type": "stdio",
"command": "cssgraph",
"args": ["serve", "--mcp"]
}
}
}
Or run cssgraph install to auto-detect and configure supported agents.
Auto-sync is enabled by default. cssgraph watches the project and updates the graph on every file change — while your agent edits code, or you add/modify/delete CSS files. The index is never stale.
┌──────────────────────────────────────────────────────┐
│ AI Agent │
│ │
│ "What styles affect .btn-primary?" │
│ calls cssgraph_explore — one tool call │
│ │ │
└────────────────────────────┬────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────┐
│ cssgraph MCP Server │
│ │
│ explore · one call → properties + overrides + │
│ specificity + callers grouped by file │
│ │ │
│ ▼ │
│ SQLite knowledge graph │
│ classNames · properties · variables · at-rules │
│ edges · FTS5 full-text search │
└──────────────────────────────────────────────────────┘
.cssgraph/cssgraph.db) with FTS5 full-text search.contains (selector→property), nests (parent→child selector), overrides (higher specificity selector overrides lower), imports (file→imported file), references (property→CSS variable).cssgraph init [path] # Initialize a project + build its graph
cssgraph index [path] # Rebuild the full index from scratch
cssgraph query <className> # Search for className selectors and properties
cssgraph explore <query...> # One-shot: full style context for a className
cssgraph impact <className> # Analyze what is affected by changing a className
cssgraph files [path] # Show project style file structure
cssgraph status [path] # Show index statistics
cssgraph sync [path] # Incremental update
cssgraph serve --mcp # Start the MCP server
| Tool | Purpose |
|---|---|
cssgraph_explore | PRIMARY: Get full style context for a className — properties, overrides, specificity, and callers in one call |
cssgraph_search | Search for className selectors by name |
cssgraph_callers | Find JSX components that reference a className |
cssgraph_impact | Analyze the impact radius of changing a className |
cssgraph_files | List project style files from the index |
cssgraph_status | Show index statistics |
| Language | Extension | Status |
|---|---|---|
| CSS | .css | Full support |
| SCSS / Sass | .scss | Full support (nesting, & parent, variables, @use/@forward/@import) |
| Less | .less | Parse support (nesting, variables) |
| CSS Modules | .module.css, .module.scss | Source className extraction (hash reverse mapping in V2) |
| Tailwind | tailwind.config.js | Utility class → CSS property mapping table |
cssgraph works as an MCP server with any MCP-compatible agent:
Run cssgraph install to auto-detect and configure supported agents.
Zero-config by default. cssgraph auto-detects style files and excludes node_modules, dist, build, .git, .next, .cssgraph and .gitignored paths automatically.
To keep something else out, add it to .gitignore. To pull a default-excluded directory back in, add a negation — !vendor/.
.cssgraph.jsonOptional project-level config at your project root:
{
"exclude": ["static/vendor/", "**/legacy/**"],
"extensions": {
".pcss": "css"
}
}
| Platform | Architectures | Install |
|---|---|---|
| macOS | x64, arm64 | npm |
| Linux | x64, arm64 | npm |
| Windows | x64, arm64 | npm |
MIT
FAQs
CSS intelligence for AI coding agents — surgical style context, fewer tool calls, faster answers. 100% local.
The npm package cssgraph receives a total of 46 weekly downloads. As such, cssgraph popularity was classified as not popular.
We found that cssgraph demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.