🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

tokennuke

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

tokennuke

Intelligent code indexing MCP server. Tree-sitter AST extraction, hybrid search (FTS5 + vector), call graphs, 10 languages, incremental indexing. Save 99% of tokens.

pipPyPI
Version
1.3.0
Weekly downloads
25
-3.85%
Maintainers
1
Weekly downloads
 

TokenNuke

Intelligent code indexing MCP server. 15 tools, 10 languages, tree-sitter AST extraction, hybrid search (FTS5 + vector), call graphs, remote repo indexing, incremental indexing.

Save 99% of tokens — get exact function source via byte-offset seek instead of reading entire files.

Formerly codemunch-pro. Same code, better name.

Install

pip install tokennuke

Quick Start

Claude Desktop / Cline

Add to your MCP client config:

{
  "mcpServers": {
    "tokennuke": {
      "command": "tokennuke"
    }
  }
}

HTTP Server

tokennuke --transport streamable-http --port 5002

15 MCP Tools

ToolDescription
index_folderIndex a local directory (incremental, SHA-256 based)
index_repoIndex a GitHub/GitLab repo (tarball download, no git needed)
list_reposList all indexed repositories with stats
invalidate_cacheForce re-index a repository
file_treeGet directory tree with file counts
file_outlineList symbols in a single file
repo_outlineList all symbols in repo (summary)
get_symbolGet full source of one symbol (O(1) byte seek)
get_symbolsBatch get multiple symbols
search_symbolsHybrid search (FTS5 + vector RRF)
search_textFull-text search in file contents
get_calleesWhat does this function call?
get_callersWho calls this function?
diff_symbolsWhat changed since last index? (PR review)
dependency_mapWhat does this file depend on? What depends on it?

10 Languages

Python, JavaScript, TypeScript, Go, Rust, Java, C, C++, C#, Ruby

All via tree-sitter-language-pack — zero compilation, pre-built binaries.

Key Features

O(1) Symbol Retrieval

Every symbol stores its byte offset and length. get_symbol seeks directly to the function source — no reading entire files. A 200-byte function from a 40KB file = 99.5% token savings.

Incremental Indexing

Files are hashed (SHA-256). Only changed files are re-parsed. Re-indexing a 10K file repo after changing one file takes milliseconds.

Hybrid Search (FTS5 + Vector)

Combines BM25 keyword matching with semantic vector similarity using Reciprocal Rank Fusion. Search "authentication middleware" and find auth_middleware, verify_token, and login_handler.

Call Graphs

Traces function calls through the AST. get_callees("main") shows what main calls. get_callers("authenticate") shows who calls authenticate. Supports depth traversal.

Remote Repo Indexing

Index any public GitHub or GitLab repo by URL — no git binary needed. Downloads the tarball via API, extracts, and indexes. Cached locally with SHA-based freshness checks. Supports private repos with auth tokens and sparse paths.

Search raw file contents — string literals, TODO comments, config values, error messages. Not just symbol names.

How It Works

  • Parse — tree-sitter builds an AST for each source file
  • Extract — Walk AST to find functions, classes, methods, types, interfaces
  • Store — SQLite database per repo with FTS5 virtual tables
  • Embed — FastEmbed (ONNX, CPU-only) generates 384-dim vectors for semantic search
  • Graph — Call expressions extracted from function bodies, edges stored and resolved
  • Serve — FastMCP exposes 15 tools via stdio or HTTP

Architecture

~/.tokennuke/
├── myproject_a1b2c3d4e5f6.db    # Per-repo SQLite database
├── otherproject_7890abcdef.db
└── ...

Each DB contains:
├── files          # Indexed files with SHA-256 hashes
├── symbols        # Functions, classes, methods, types
├── symbols_fts    # FTS5 full-text search index
├── symbols_vec    # sqlite-vec 384-dim vector index
├── call_edges     # Call graph (caller → callee)
└── file_content_fts  # Raw file content search

Use Cases

  • AI Coding Agents: Give your agent surgical access to codebases without burning context
  • Code Review: Find all callers of a function before changing its signature
  • Onboarding: Search symbols semantically — "where is error handling?" finds relevant code
  • Refactoring: Map call graphs before moving functions between modules
  • Documentation: Extract all public APIs with signatures and docstrings

License

MIT

Keywords

ast

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts