🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

topos-mcp

Package Overview
Dependencies
Maintainers
0
Versions
16
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

topos-mcp

Topos MCP server — structural code-quality tools (SIMPLE/COMPOSABLE/SECURE/NAVIGABLE) for AI coding agents.

pipPyPI
Version
0.5.1
Weekly downloads
518
11.16%
Maintainers
0
Weekly downloads
 
Created

Topos

the agent harness for structural code quality

Topos measures complexity, coupling, risky data flows, and agent cognitive load, then gives your agent a concrete target—from SLOP to PLATINUM.

Topos self-evaluation: SIMPLE, COMPOSABLE, SECURE, NAVIGABLE results for the core crates Install Topos MCP in VS Code PyPI License Topos MCP server ClawHub

Install · What it checks · Under the hood · Docs · Issues

Why Topos

Coding agents produce working code quickly. The harder question is whether the result is still easy to understand, safe to change, and well-fitted to the rest of the repository. Quality is the new currency.

Topos computes that signal from program structure—not from an LLM review or a style opinion—and returns concrete failure locations and next actions. It is fast enough to sit inside the agent loop: measure, edit, verify, repeat.

Tests check behavior. Topos checks whether the implementation is built to keep changing.

Grounded in category theory, written in Rust.

Install and Quick Start

One binary. Every supported agent harness. A clean way back out.

1. Install the CLI

Use the verified release installer:

curl -fsSL https://docs.krv.ai/topos/install.sh | bash

Or install with Homebrew:

brew install krv-labs/tap/topos

[!TIP] Prefer an editor-managed install? In VS Code or Cursor, search @mcp topos in the Extensions view or choose Install MCP server. This is an alternative to topos install: your editor installs and manages the Topos MCP server for you.

2. Connect your coding agents

topos install detects every supported MCP harness and lets you configure any—or all—of them from one interactive checklist:

topos install
┌  Which agent integrations do you want to configure?
│
│  ↑↓ move · space toggle · a all · enter confirm · esc cancel
│
│ ❯ ○ Claude Code          (detected)
│   ○ Claude Desktop       (detected)
│   ● Codex CLI            (✓ active)
│   ● Gemini CLI           (✓ active)
│   ○ GitHub Copilot CLI   (detected)
│   ○ Cursor               (detected)
│   ○ VS Code              (detected)
│   ○ Google Antigravity   (detected)
└

Restart the agents you configured, then ask:

"Use Topos to find this repository's worst structural problem, make one focused improvement, and verify the result."

[!IMPORTANT] Too many tools spray MCP servers across agent JSON files, scatter symlinks around your machine, then leave you to burn half a Claude session untangling the mess—or pull your own hair out doing it. Topos does not play that game. We follow a leave-no-trace policy: topos status shows every registration, while topos uninstall opens the same selector, previews exactly what will change, and removes everything Topos installed. If Topos makes it easy to do, it should be just as easy to undo.

topos status
topos uninstall

See the agent setup guide for permissions, manual configuration, and troubleshooting.

3. Evaluate from the terminal

topos evaluate . -r

Topos discovers Python, Rust, JavaScript, TypeScript, C++, and Go automatically. Pass --language only when you want to narrow the run.

See Installation for platform support and alternative install paths.

What Topos checks

Every file gets four independent verdicts:

  • SIMPLE — avoids unnecessary complexity using AST entropy and control-flow complexity.
  • COMPOSABLE — limits a file's outward dependency burden; broader coupling and stability metrics remain available for diagnosis.
  • SECURE — avoids dangerous API reachability and taint paths in the code property graph.
  • NAVIGABLE — stays shallow enough for an agent to read and change in one pass, using depth-weighted nesting divergence over the AST scope tree.

Those verdicts roll up into one memorable quality medal without hiding which pillar failed:

MedalCriteria
🏆 PLATINUMPasses all 4
🥇 GOLDPasses 3 of 4
🥈 SILVERPasses 2 of 4
🥉 BRONZEPasses 1 of 4
SLOPPasses 0, or fails to parse

See the full metrics reference. Refactor guidance also surfaces control-flow cycles, load-bearing dependency edges, process bottlenecks, and optional Graphify knowledge-graph findings.

How the medal system is derived

The four pillars are pairwise incomparable and form a sixteen-element evaluation lattice (a 4-cube); PLATINUM is their intersection. Labels below abbreviate the pillars as Simple, Composable, Sc = Secure, Navigable.

The full evaluation lattice — SLOP at the bottom, four single-pillar BRONZE states, six two-pillar SILVER states, four three-pillar GOLD states, and IDEAL (PLATINUM) at the top.

Measures · Category-theory foundations

Under the hood

Topos is a self-contained Rust CLI and MCP server. Analysis runs locally; your source code is not sent to an external model or hosted analysis service.

ComponentRole
tree-sitterParses six languages and powers the native AST, CFG, CPG, PDG, and UAST representations.
GitNexusSupplies the repository dependency graph scored by COMPOSABLE (topos depgraph generate). Requires npm install -g gitnexus@1.6.8.
SighthoundEmbedded in the MCP server for supplementary security findings; native CPG probes remain the SECURE scoring source.
GraphifyOptional advisory orphan and fragile-edge detection via topos graphify / topos_refactor(target="graphify"); does not affect the medal. Requires pip install graphifyy.

The result is one agent-facing contract over several structural lenses: one score to optimize, explicit evidence for each failure, and a verification loop that can tell a real improvement from cosmetic churn.

More ways to use Topos

Distribution

Topos ships four ways:

  • GitHub Releases — the topos CLI binary (macOS/Linux), via install.sh or a direct release download.
  • PyPItopos-mcp, a thin bin-wheel bundling the MCP server binary (pip install topos-mcp / uvx topos-mcp), zero Python runtime.
  • VS Code Marketplace — the Topos extension, bundling platform binaries.
  • Docker — a container image for Glama and other MCP-registry hosting.

Crate layout and adapter details: docs.krv.ai/topos/architecture.

Contributing

Topos is used internally at Krv Labs to manage AI-agent code output. We welcome bugs, ideas, and contributions.

Full documentation · Measures and metrics · Engineering notes

Made by Krv Labs   Topos lattice verdict

Keywords

code-quality

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts