search — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited search (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Find symbols without reading any files. Returns a compact index listing.
# Exact
jq '[.symbols[] | select(.name == "validateToken")]' .claude/codemunch/index.json
# Case-insensitive
jq '[.symbols[] | select(.name | ascii_downcase | contains("validate"))]' .claude/codemunch/index.json
# Fuzzy: split query into chars and find symbols containing all of them in order
# e.g. "vt" matches "validateToken", "visitTree"# Find all classes
jq '[.symbols[] | select(.kind == "class")]' .claude/codemunch/index.json
# Find all exported functions
jq '[.symbols[] | select(.kind == "function")]' .claude/codemunch/index.json
# Kinds vary by language:
# TypeScript: function, class, method, property, interface, type, enum, constant, variable
# Python: function, class, method, variable
# Go: function, struct, interface, method, constant, variable, type
# Rust: function, struct, enum, trait, impl, method, constant, type
# Ruby: method, class, module, constant
# Java/Kotlin: class, interface, method, field, enum, constructor
# C/C++: function, class, struct, enum, method, field, typedefjq --arg f "auth" '[.symbols[] | select(.file | contains($f))]' .claude/codemunch/index.jsonjq --arg c "AuthService" '[.symbols[] | select(.container == $c)]' .claude/codemunch/index.json# All methods in a specific class
jq --arg c "Invoice" --arg k "method" \
'[.symbols[] | select(.container == $c and .kind == $k)]' \
.claude/codemunch/index.jsonAlways return a compact list — never the full source. Source is fetched separately with the fetch skill:
Found 6 symbols matching "validate":
1. validateToken function src/auth/tokens.ts:142 AuthService
2. validateInvoice function src/lib/validation.ts:89 —
3. validateAmount function src/lib/validation.ts:112 —
4. validateEmail method src/models/user.ts:34 UserModel
5. validateExpense function convex/expenses.ts:67 —
6. validateDateRange function src/utils/dates.ts:23 —
Use /codemunch:fetch <name> to read the source of any symbol.
Tokens used: 12 (vs reading 6 files: ~18,000 tokens)If LSP is configured, additionally offer:
Workspace symbol search — searches across the entire project including symbols not yet in the index:
Use Claude Code's /lsp tool:
workspace/symbol
query: "[search term]"This is the most powerful mode — LSP returns every symbol in the project matching the query, with full type information, even in files not yet indexed.
When searching an unfamiliar codebase, these compound searches help:
"Show me the shape of this file"
jq --arg f "$FILENAME" '[.symbols[] | select(.file == $f) | {name, kind, start_line, container}]' \
.claude/codemunch/index.json | jq 'sort_by(.start_line)'"What are the entry points?"
# Find exported/public top-level functions
jq '[.symbols[] | select(.kind == "function" and (.container == null or .container == ""))]' \
.claude/codemunch/index.json"Show me the class hierarchy"
jq '[.symbols[] | select(.kind == "class" or .kind == "interface" or .kind == "struct")] |
group_by(.file) |
map({file: .[0].file, types: map(.name)})' \
.claude/codemunch/index.json~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.