🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

weavatrix

Package Overview
Dependencies
Maintainers
1
Versions
44
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

weavatrix

Native repository intelligence for coding agents: 42 read-only MCP operations backed by typed evidence graphs, impact, architecture, APIs, Git, search, semantics, and memory.

latest
Source
npmnpm
Version
1.2.0
Version published
Weekly downloads
761
-45.76%
Maintainers
1
Weekly downloads
 
Created
Source

Weavatrix — native MCP repository intelligence

CI npm engine MIT

Give your coding agent repository evidence before it starts guessing.

Weavatrix is the native MCP product for repository intelligence. It gives Codex, Claude Code, and other coding agents 42 read-only operations over one revision-bound evidence graph: impact, architecture, APIs, Git history, duplicates, dead code, search, semantic links, and temporal memory.

It does not answer from a larger grep or an invented confidence score. Every bounded result can carry the repository revision, file, line, extractor, evidence kind, and confidence that produced it.

This npm package is the convenient prebuilt distribution of the same native product published on crates.io as weavatrix. It is not a separate JavaScript engine; both registry packages run the same Rust adapter and engine. The separately versioned weavatrix-js package is a legacy compatibility implementation and is not bundled here.

Install in 30 seconds

npx -y weavatrix mcp .

Or install the same native MCP product through Cargo:

cargo install weavatrix
weavatrix mcp .

Codex

[mcp_servers.weavatrix]
command = "npx"
args = ["-y", "weavatrix", "mcp", "."]

Claude Code

claude mcp add weavatrix -- npx -y weavatrix mcp .

Profiles expose bounded views of the same engine:

npx -y weavatrix mcp . --profile=all
npx -y weavatrix mcp . --profile=code
npx -y weavatrix mcp . --profile=seo

The package contains native binaries for Windows x64/arm64, macOS x64/arm64, and glibc Linux x64/arm64. It has no install script and performs no runtime download.

What an agent can ask

What breaks if I change src/auth/middleware.ts?
Trace POST /api/orders through this backend and its clients.
Which production symbols are dead, and what evidence proves it?
Show duplicate implementations but suppress router boilerplate.
Which dependency violates .weavatrix/architecture.json?
Find every GraphQL, gRPC, Kafka, RabbitMQ, NATS, JMS, SQS, or SNS
contract affected by this branch.
Build the smallest source bundle needed to edit this symbol safely.

The 42 read-only operations

WorkflowOperations
Graph orientationgraph_stats, get_node, get_neighbors, query_graph, god_nodes, shortest_path, get_community, list_communities, module_map, build_graph
Change impactget_dependents, change_impact, select_tests, verified_change, prepare_change, graph_diff
Exact source contextsearch_code, read_source, inspect_symbol, context_bundle, map_stacktrace
Health and qualityfind_duplicates, find_dead_code, run_audit, coverage_map, hot_path_review
APIs and transportslist_endpoints, trace_endpoint, trace_api_contract
Architectureget_architecture_contract, verify_architecture, explain_architecture_violation, propose_architecture_exception
Git and repositoriesgit_history, cross_repo_git, open_repo, list_known_repos, rebuild_graph
Native extensionsvector_search, semantic_link, seo_link_suggestions, memory_context

Every operation is read-only with respect to the analyzed repository. Pagination and explicit limits bound large neighborhoods, histories, searches, and contract inventories.

24 repository surfaces

GroupSurfaces
CodeRust; JavaScript/JSX; TypeScript/TSX; Python; Go; Java; C#; C; C++; SQL; Bash/Zsh; Swift; Solidity
Contracts and configurationGraphQL; Protobuf/gRPC; JSON/JSONC; YAML/Kubernetes; Terraform/HCL; XML
Documents and UIHTML/Vue/Svelte; CSS/SCSS/Sass/Less; Markdown/MDX; reStructuredText; AsciiDoc

Cross-surface analysis connects HTTP, GraphQL, gRPC, Kafka, RabbitMQ/AMQP, JMS, NATS, SQS, and SNS evidence. Dynamic dispatch that cannot be proved stays unresolved; static reachability is never presented as measured coverage.

Product and engine are separate

coding agent
    |
    | MCP over stdio
    v
weavatrix 1.2.0
    profile catalog · refresh · watcher · MCP framing
    |
    v
weavatrix-rust 2.1.1
    typed graph · analysis · 42 read-only operations

This npm product owns MCP transport and native distribution. The weavatrix-rust crate is the reusable protocol-independent engine; it is not an MCP server. Its standalone diagnostic therefore reports weavatrix-rust <engine-version>, while this MCP product reports both its product and embedded-engine identities.

Engine 2.1.1 adds map_stacktrace, select_tests, build_graph, token_budget on the source-context operations, and dependency-injection type evidence, and keeps find_duplicates families internally consistent after filtering and top_n truncation.

Release evidence

The installed-package benchmark packs both products, installs them into isolated npm roots, starts fresh MCP processes with empty caches, and validates identity, advertised operations, results, and cleanup.

The packaged 1.2.0 product (weavatrix-rust 2.1.1) was measured on 2026-08-03 against installed weavatrix-js 0.3.15 on a real JavaScript service repository: paired cold-boundary median 32.06x (spawn to first tool result: 157.34 ms vs 5,068.22 ms) and warm tools/call median 36.85x (7.94 ms vs 292.55 ms), passing the 24x cold and 30x warm release thresholds and sitting slightly above the 30.34x recorded for the 1.0.0 baseline.

Full evidence and methodology: benchmarks.

Safety

  • read-only MCP surface;
  • no repository-code execution or source writes;
  • no network path in analysis;
  • no npm install script or runtime binary download;
  • bounded inputs, outputs, histories, and pagination;
  • stable ordering and revision provenance;
  • unsafe Rust forbidden in first-party engine crates;
  • MIT licensed.

License

MIT.

Keywords

mcp

FAQs

Package last updated on 03 Aug 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts