codeweb
An MCP server that maps code symbol relationships and provides tools for impact analysis, caller lookup, and duplicate detection to help coding agents understand codebases efficiently.
README
<div align="center">
<img src="assets/brand/banner.png" alt="codeweb — your coding agents grep. codeweb knows." width="100%">
Free & MIT-licensed. Runs entirely on your machine — no account, no server, no telemetry. Reads your code; never executes it.
Website · See it in action · Install · Use · For agents (MCP: Model Context Protocol) · How it works · Changelog
</div>
Your agents break less code and burn fewer tokens.
npx -y @ghostlygawd/codeweb .
<div align="center"> <a href="https://ghostlygawd.github.io/codeweb/downloads.html"><img src="assets/metrics/npm-downloads.svg" alt="Latest seven-day npm download total with a line chart of completed daily downloads for @ghostlygawd/codeweb, generated from the public npm downloads API" width="100%"></a> <br><sub>The large number is the latest seven completed days; the line shows daily downloads. Package downloads are retrievals, not a count of users. Select the chart for the live data and reporting cutoff.</sub> </div>
codeweb reads your code. It maps each function and the calls between functions. It maps 3,000 symbols in approximately 3 seconds. Static analysis produces the same map from the same code. No LLM is in the mapping loop.
Your coding agents query the map instead of using grep. In measured tests, agents that used grep missed more than half of a function's real callers (see the measurements). An incomplete caller list can cause an agent to break code that it did not inspect.
- Give agents structural data: The Model Context Protocol (MCP) server provides 27 tools,
including
codeweb_impact,codeweb_callers, andcodeweb_find_similar. - Keep answers small: Each query returns a bounded structural answer. Your agents can use their remaining context for implementation work.
- Inspect the same data: The interactive report shows the complete codebase map.
The map also shows relationships that are not visible in one file. These relationships include duplicated logic, dead code, hotspots, and tangled domains.
<div align="center"> <a href="https://ghostlygawd.github.io/codeweb/research.html"><img src="assets/brand/proof-strip.svg" alt="Measured codeweb results: agents found 74% of real callers with codeweb and 44% with grep at the same context spend; impact analysis used 126 times fewer tokens; more than 490,000 deterministic comparisons had zero disagreements" width="100%"></a> <br><sub>Measured against fixed tasks and independent oracles. Select the proof strip for the methodology and receipts.</sub> </div>
Try it on your repo
cd your-project
npx -y @ghostlygawd/codeweb .
For a repository with 3,000 symbols, the first map takes approximately 3 seconds. Open
.codeweb/report.html to inspect the map.
<div align="center"> <img src="assets/screens/zod-terminal-run.svg" alt="Condensed real terminal run of codeweb 0.12.0 on Zod commit 912f0f5: 1,388 symbols and 1,616 edges from 409 files, followed by 66 actionable findings" width="840"> <br><sub>Real run against <a href="https://github.com/colinhacks/zod/tree/912f0f51b0ced654d0069741e7160834dca742ee">Zod at commit <code>912f0f5</code></a>, captured 2026-07-29. The replay shortens the absolute local path to <code>.codeweb</code>; the displayed values are unchanged.</sub> </div>
See it in action
Each screenshot below shows a generated report for axios (274 symbols and 8 domains). The screenshots are not mockups.
codeweb found 3 real duplications in axios and rejected 12 false positives. Read the case study, or inspect the live map.
Know what an edit breaks — before you write
Select a function in the live map. The map highlights the function's blast radius and shows the symbols that the change can affect.
Your agents can get the same answer from the codeweb_impact MCP tool before they edit the code.
<div align="center"> <img src="assets/screens/axios-blast-radius.png" alt="codeweb blast radius: AxiosError selected in the axios graph — the selected block wears the accent with a viewfinder frame, blast edges lit across three domains, 27 callers listed in the inspector" width="760"> <br><sub>Selecting <code>AxiosError</code> in axios lights up its <b>27 callers across the domains that depend on it</b> — try it yourself in the <a href="https://ghostlygawd.github.io/codeweb/">living map</a>.</sub> </div>
Navigate the whole system
The force-directed map shows every symbol. You can collapse symbols into domains. Search, drag, zoom, or select a node to trace its callers and dependencies.
<img src="assets/screens/axios-graph.png" alt="codeweb Graph tab on axios: eight domain blocks (helpers, core, adapters, cancel, defaults, platform) sized by symbol count and linked by stippled call edges" width="100%">
Findings — stop guessing what to refactor
The Findings tab ranks duplication, highly connected hotspots, and likely dead code. Select a row to inspect the symbol's callers and dependencies.
<img src="assets/screens/axios-findings.png" alt="codeweb Findings tab on axios: ranked duplication, hotspots, and likely-dead code, with a clickable detail panel" width="100%">
See duplication density, and where domains tangle
<table> <tr> <td width="50%" valign="top"> <img src="assets/screens/axios-treemap.png" alt="codeweb Treemap on axios: every file sized by lines of code, duplication density carried by a dark-to-lime lightness ramp"> <br><b>Treemap</b> — The size of each block shows the file's lines of code. A brighter block contains more duplicated code. Use the bright blocks to identify possible consolidation targets. </td> <td width="50%" valign="top"> <img src="assets/screens/axios-matrix.png" alt="codeweb Matrix on axios: a heatmap of call coupling between domains"> <br><b>Matrix</b> — The matrix shows coupling between domains. A large off-diagonal cell shows strong coupling. You can merge the domains or add a clear interface between them. </td> </tr> </table>
<div align="center"> <img src="assets/brand/demo.svg" alt="The codeweb pipeline: extract → cluster → overlap → render, looping" width="840"> <br><sub>The deterministic pipeline, looping: extract → cluster → overlap → render.</sub> </div>
codeweb works at symbol resolution. It maps functions, classes, methods, and the call and import edges between them. A file-level scanner can show that two modules are similar. codeweb can show that two functions do the same work, identify their callers, and calculate the effect of a merge.
Benchmarks
- Find callers before an edit: Agents found 74% of a function's real callers with codeweb and 44% with grep at the same context spend. A missed caller can cause an edit to break working code.
- Calculate the effect of a change: One codeweb call returned one small answer. Agents that used grep needed approximately 5 search rounds and 126 times the tokens. They still had to guess.
- Detect duplicate code: codeweb found every planted duplicate with zero false alarms, including renamed copies. Text search found 0% of the renamed copies.
- Check deterministic results: Tests compared codeweb with the TypeScript compiler and other independent implementations more than 490,000 times, with zero disagreements.
- Map and query quickly: The first map takes approximately 3 seconds for a repository with 3,000 symbols. Queries take approximately 0.1 seconds. A repository with twice as many symbols takes approximately 1.3 times as long to map.
- Understand the limits: A new map after a very large edit can take more time. Agents also completed simple tasks successfully without codeweb.
Methodology, raw data, and per-claim receipts:
the evidence ledger. Benchmark your own
repo: npm run bench -- <path>/.codeweb/graph.json. CI re-runs the performance budgets on
every PR; breaking a published number fails the build.
codeweb also keeps a local activity tally. Run npm run stats to see it:
codeweb this month: 41 pre-edit card(s) · 5 card-named caller(s) followed · 2 regression(s) flagged · 120 queries served
To evaluate a dependency, point codeweb at a repository that you do not own:
/codeweb https://github.com/owner/repo. codeweb makes a read-only clone, maps the clone, and
adds an adoption review. codeweb does not execute the target code.
Install
Free & MIT-licensed. Runs entirely on your machine — no account, no server, no telemetry. Reads your code; never executes it.
- codeweb requires Node.js ≥ 22.
- codeweb has zero required dependencies. CI verifies operation with an empty
node_modulesdirectory. - The optional
web-tree-sitterwasm grammar improves extraction. codeweb does not require it. - CI publishes releases with npm provenance. Run
npm audit signaturesto verify a release.
Using Claude Code? Install the plugin to add the /codeweb command, automatic pre-edit
impact cards, and all 27 tools:
/plugin marketplace add GhostlyGawd/codeweb
/plugin install codeweb
Restart Claude Code to register the /codeweb command, agents, and skill.
Cursor, Windsurf, or another MCP agent: Register the zero-dependency stdio server. The example uses Claude Code syntax. Use the equivalent server-registration command for your client:
claude mcp add codeweb -- npx -y -p @ghostlygawd/codeweb codeweb-mcp
Map a repository without an AI agent: Run one command from your project directory:
cd your-project
npx -y @ghostlygawd/codeweb . # ~3 s for 3,000 symbols — then open .codeweb/report.html
For a temporary evaluation, use the npx command. It creates the map without a permanent
installation.
Run the engine from a clone:
git clone https://github.com/GhostlyGawd/codeweb.git
node codeweb/scripts/run.mjs /path/to/your/project
docs/cli.md lists each executable, flag, and exit code.
VS Code: editor/vscode-codeweb shows an
N callers · blast M lens above each mapped symbol. Select the lens to open the report.
What you can do
Each link lands on full docs, flags, and examples in the reference.
- Know before you edit: Find callers, calculate the effect of a change, and check for an existing implementation. → Query the graph · context & pre-flight
- Gate every edit: Get a structural regression result for an edit, pull request, or
architecture rule.
→ The
diffverdict · the PR gate · the capability suite - Clean up, ranked: Rank consolidation and dead-code work by evidence.
→
optimize·hotspots·campaign·trend
Use
/codeweb # map the current project
/codeweb src/payments --depth symbol # deep-dive one subsystem
/codeweb https://github.com/owner/repo # external review before adopting
/codeweb owner/repo --open # clone, map, and open the report
Available flags include --depth module|symbol|auto, --engine hybrid|read|tools,
--focus <glob>, --mode internal|external, and --open. See commands/codeweb.md for details.
codeweb writes all outputs to <target>/.codeweb/. Agents and other tools can read graph.json.
You can open report.html. codeweb also creates Markdown versions.
See the description of each output file.
Use it as an MCP tool
scripts/mcp-server.mjs is a zero-dependency Model Context Protocol (MCP) stdio server. It gives
each MCP client access to all 27 tools. The tools help the client orient, read the structure,
check before writing, gate an edit, and plan cleanup.
The plugin registers the server automatically. To register the standalone server, run:
claude mcp add codeweb -- npx -y -p @ghostlygawd/codeweb codeweb-mcp
The server includes these agent-specific features:
- Optional
graphargument: The server finds the nearest map when you omitgraph. If no map exists, the error directs the agent tocodeweb_map. - Budgeted responses: Responses include the highest-ranked items and the true totals. A context response that was approximately 300 KB is now approximately 10 KB.
- Staleness information: A stale result identifies its state and directs the agent to
codeweb_refresh.
All 27 tools, grouped and explained →
How it works
For JavaScript, TypeScript, Python, Rust, Go, Java, C#, Ruby, PHP, Kotlin, and Swift, codeweb uses a deterministic Node pipeline by default. One command creates the map. No LLM is in the pipeline, and the same input produces the same bytes.
The map pipeline has the four stages in the following diagram. scripts/run.mjs also creates
optimize.md after overlap analysis and before report rendering.
<div align="center"> <img src="assets/brand/pipeline.svg" alt="codeweb's four deterministic stages: extract, cluster, overlap, render" width="100%"> </div>
- Extract (
extract-symbols.mjs) parses each source file into atomic nodes such as functions, classes, and methods. It also records call and import edges. If a bare call can refer to more than one definition, codeweb omits the edge instead of guessing. Per-file caching makes extraction incremental and byte-identical to a full rebuild. An imported.jsonfile enters the map as a file-level node without being parsed. An unreferenced.jsonfile stays out of the map, which prevents lock-file noise. - Cluster (
cluster3.mjs) removes genuine utility hubs and groups the remaining nodes into directory-anchored semantic domains. - Overlap (
overlap.mjs) detects duplicated logic and parallel implementations. It compares each candidate with the actual function bodies by using token-shingle similarity. This check prevents name coincidences from becoming findings. A structural pass over identifier-normalized skeletons also finds renamed Type-2 clones (find-similar --structural). - Render (
build-report.mjs) convertsgraph.jsoninto the self-containedreport.htmlandreport.mdfiles.
For a language that the extractor cannot parse, codeweb uses the agent path.
codeweb-dissector agents extract nodes and edges for each subsystem. codeweb-domain-mapper
then assigns domains and overlaps.
Both paths produce the same graph.json schema. In external mode, each path also adds an
adoption verdict.
Curious how the repo is laid out? The component map lives in the reference.
Roadmap
- Support more first-class languages: codeweb currently supports eleven native languages:
JavaScript, TypeScript, Python, Rust, Go, Java, C#, Ruby, PHP, Kotlin,
and Swift. Other languages use the agent fallback. Dynamic-dispatch AST tiers cover JS/TS,
Java, C#, Python, Go, Rust, Ruby, and PHP. Kotlin and Swift dispatch requires a trusted
wasm grammar at the pinned ABI. See
scripts/grammars/PROVENANCE.md.
Recent releases added the agent-intelligence suite (hotspots, campaign, reading-order, Type-2 clone detection, and suppression memory), a live interactive demo, Go and Rust on the fast path, duplication trend data, and the one-command CI regression gate with a GitHub Action. codeweb currently provides 27 tools.
Versioning & releases
codeweb follows Semantic Versioning. It records changes in
CHANGELOG.md, which uses the
Keep a Changelog format. Each capability, benchmark, and fix ships
in a tagged GitHub release.
package.json is the source of truth for the version.
scripts/mcp-server.mjs is the source of truth for the MCP tool count. The release tools derive
and verify the other values:
npm run version-sync # propagate version + tool count -> plugin.json, SKILL.md, README badge
npm run check-consistency # fail if any public-facing surface has drifted
npm run build:site # regenerate the docs/ website (zero-dependency, deterministic)
npm run release -- --minor # roll the changelog, bump, sync, rebuild; prints the git/tag steps
check-consistency runs in CI. It gates version strings on every surface, every prose mention of
the tool and language counts, the CHANGELOG entry for the current version, and every evidence
file the ledger cites.
About
Built by GhostlyGawd. AI agents helped write much of the code.
The commit co-author trailers identify those contributions. Open an issue for questions or
problems. Use SECURITY.md to report a security issue.
Stay current: codeweb does not contact an update service. To receive release notifications, select Watch → Custom → Releases on GitHub.
Support the project
Everything that runs locally is free forever. It does not require an account, telemetry, or a license key.
Sponsoring supports the project. Sponsorship also provides advertising. Top sponsors can put their logo at the top of this README, and each sponsor can join the supporters list. See the support page for details.
Running codeweb at an organization and need help? Send email through the GitHub profile.
Handoffs
You can send codeweb outputs to refactor-cleaner, codebase-onboarding, or code-tour if you
have those tools. codeweb does not require them.
For a useful next step, apply the highest-ranked ready merge from optimize.md. Then run
codeweb again and compare the findings count.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。