
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
karst
Advanced tools
Code context for AI dev tools — graph-grounded, pack-scoped retrieval over MCP. 60% fewer tokens, audit-grade citations.
Know what your change breaks — without your code leaving your machine.
karst gives any AI coding tool — Cursor, Claude Desktop, a custom agent — a local
map of your codebase. It answers questions with exact file:line citations and
walks a real call / import / inheritance graph to compute the blast radius of a
change — "what else breaks if I touch this?" — the question plain search and
agentic grep can't answer.
It runs 100% locally, speaks MCP (so it drops into any agent), and never calls an LLM itself — your source code never leaves the box. As a bonus, pack-scoped retrieval cuts ~60% of the input tokens per question.
Regulated, air-gapped, or IP-sensitive team? karst is built for the environments cloud coding tools structurally can't enter — fully offline, no telemetry, source you can audit. Start with the Compliance & Air-Gap Pack (attestation, network-egress table, pre-filled security questionnaire, offline install).
uv tool install karst # recommended — fast, and puts `karst` on PATH for you
# or
pipx install karst # isolated install, also handles PATH
# or
pip install karst # if `karst` isn't found after, use `python -m karst …`
uvandpipxare the cleanest because they put thekarstcommand on your PATH automatically. With plainpip --user(notably Microsoft Store Python) the command may not be on PATH — in that casepython -m karst …always works, no PATH setup required.
Most "chat with your codebase" tools dump tens of thousands of vaguely-related tokens into the model on every question. You can't see what was loaded, you can't scope it, and the bill arrives at the end of the month. karst inverts that:
file:line. Verify, don't trust.Measured on a real 246-file NestJS + Next.js repo: 906 chunks indexed, re-index 343s → 2.3s incremental, ~$0.019 per question on Sonnet 4.6 (shown before the call), 60% fewer tokens with packs attached.
karstcommand not found? Your Python Scripts dir isn't on PATH (common with Microsoft Store Python). Everything below works the same withpython -m karst …— no PATH setup. (Or install viauv/pipx, which putkarston PATH for you.)
cd your-project
# one command: index + call/import graph + suggested packs
karst quickstart # or: python -m karst quickstart
# ask questions about the code (defaults to this folder's index)
karst ask "how does checkout charge the user?" --no-llm # cited code, no API key
karst ask -i # interactive: ask many questions
# what breaks if I change a function?
karst impact --target checkout --graph-path ~/.karst/indexes/your-project/graph.pkl
# review a diff with severity-tagged, cited findings
karst review --staged --storage ~/.karst/indexes/your-project
karst examples # a copy-paste cheatsheet of everything
karst quickstart prints the exact follow-up commands with your index path
filled in. karst ask writes an LLM answer when ANTHROPIC_API_KEY /
OPENAI_API_KEY is set; otherwise add --no-llm for cited chunks (no key). The
MCP server below needs no key either — your IDE supplies the model.
karst ships an MCP server (karst-mcp) exposing five tools — search_code,
find_impact, list_packs, index_status, index_repository — over stdio.
Claude Desktop (claude_desktop_config.json) or Cursor
(.cursor/mcp.json) — pick whichever launcher you have:
{
"mcpServers": {
"karst": { "command": "uvx", "args": ["--from", "karst", "karst-mcp"] }
}
}
uvx needs nothing pre-installed — it fetches and runs karst on demand. Already
installed it? { "command": "karst-mcp" } works too. No PATH at all? Use
{ "command": "python", "args": ["-m", "karst.mcp_server"] }.
Restart the host, then ask normally — it calls karst's tools when useful and gets back scoped, cited context. Full setup is in docs/MCP.md.
New here? Start with whichever fits you:
CALLS / IMPORTS / CONTAINS /
IMPLEMENTS edges powers impact analysis ("what depends on this?" — including
which classes implement an interface or extend a base).auth,
billing). A query loads only its pack.file:line-cited chunks; your
host's model reasons over them.Everything is local and offline-capable (FastEmbed/ONNX embeddings, Qdrant local mode, sqlite caches — no Docker, no daemon).
Live: AST chunking (6 languages), call/import graph + impact analysis,
pack-scoped retrieval, token + cost meter, incremental indexing + embedding
cache, diff code review with inline PR posting (review --pr --post-to-pr), and
the MCP server over both stdio and remote Streamable-HTTP (karst-mcp --http).
Coming next: hosted indexing, team-shared pack libraries, an autonomous GitHub
PR review bot, and OAuth for browser connectors (claude.ai / ChatGPT).
Apache-2.0. See LICENSE.
FAQs
Code context for AI dev tools — graph-grounded, pack-scoped retrieval over MCP. 60% fewer tokens, audit-grade citations.
The pypi package karst receives a total of 58 weekly downloads. As such, karst popularity was classified as not popular.
We found that karst demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.