.vscode — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited .vscode (MCP Server) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
A bulleted imperative like {match} tells the agent to never reveal, disclose, or mention something to the user. Used adversarially it can instruct the agent to hide its tool calls or lie about what it did — stripping the transparency a user relies on to trust the agent.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- SPDX-FileCopyrightText: 2025 Knitli Inc. SPDX-FileContributor: Adam Poulemanos <[email protected]>
SPDX-License-Identifier: MIT OR Apache-2.0 -->
[!WARNING]
>
## CodeWeaver is no longer maintained
>
We're really proud of CodeWeaver and think it's pretty awesome, but we can't maintain it anymore.
>
We're focused on something else.
>
CodeWeaver is (was?) a sophisticated, smart, code search tool with wide provider support. and it's still licensed under your choice of MIT or Apache-2.0.
>
So please, fork it and build something great!
<div align="center">
<picture> <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/knitli/codeweaver/refs/heads/main/docs-site/src/assets/codeweaver-reverse.svg"> <source media="(prefers-color-scheme: light)" srcset="https://raw.githubusercontent.com/knitli/codeweaver/refs/heads/main/docs-site/src/assets/codeweaver-primary.svg"> <img alt="CodeWeaver logo" src="https://raw.githubusercontent.com/knitli/codeweaver/refs/heads/main/docs-site/src/assets/codeweaver-primary.svg" height="150px" width="150px"> </picture>
[![Python Version][badge_python]][link_python] [![License][badge_license]][link_license] [![Release][badge_release]][link_release] [![MCP Compatible][badge_mcp]][link_mcp]
[Documentation][nav_docs] • [Installation][nav_install] • [Features][nav_features] • [Comparison][nav_comparison]
</div>
CodeWeaver gives Claude and other AI agents precise context from your codebase. Not keyword grep. Not whole-file dumps. Actual structural understanding through hybrid semantic search.
CodeWeaver is Professional Context Infrastructure. With 100% Dependency Injection (DI) and a Pydantic-driven configuration system, it provides the reliability and extensibility required for industrial-grade AI deployments.
Example:
Without CodeWeaver:
Claude: "Let me search for 'auth'... here are 50 files mentioning authentication"
Result: Generic code, wrong context, wasted tokens
With CodeWeaver:
You: "Where do we validate OAuth tokens?"
Claude gets: The exact 3 functions across 2 files, with surrounding context
Result: Precise answers, focused context, 60-80% token reductionCodeWeaver is no longer in alpha!
>
Early Release (0.x): CodeWeaver is in active development. APIs may change between minor versions. It's very well-tested but still in 'it works on my machine' territory. [Use it, break it, help shape it][issues].
| Feature | CodeWeaver | Legacy Search Tools |
|---|---|---|
| Search Type | Hybrid (Semantic + AST + Keyword) | Keyword Only |
| Context Quality | Exquisite / High-Precision | Noisy / Irrelevant |
| Extensibility | DI-Driven (Zero-Code Provider Swap) | Hardcoded |
| Reliability | Resilient (Automatic Local Fallback) | Fails on API Timeout |
| Token Usage | Optimized (60–80% Reduction) | Wasted on Noise |
Using the CLI with [uv][uv_tool]:
# Add CodeWeaver to your project
uv add code-weaver
# Initialize with a profile (recommended uses Voyage AI)
cw init --profile recommended
# Verify setup
cw doctor
# Start the background daemon
cw start📝 Note:cw initsupports different Profiles: -recommended: High-precision search (Voyage AI + Qdrant) -quickstart: 100% local, private, and free (FastEmbed + Local Qdrant)
>
Want full offline? See the [Local-Only Guide][local_only_guide].
🐳 Prefer Docker? [See Docker setup guide →][docker_guide]
<table> <tr> <td width="50%">
</td> <td width="50%">
</td> </tr> <tr> <td>
</td> <td>
cw doctor)cw / codeweaver)</td> </tr> </table>
AI agents face too much irrelevant context, causing token waste, missed patterns, and hallucinations. CodeWeaver addresses this with one focused capability: structural + semantic code understanding that you control.
📖 [Read the detailed rationale →][why_codeweaver]
<div align="center">
Official Documentation: [docs.knitli.com/codeweaver/](https://docs.knitli.com/codeweaver/)
Built with ❤️ by [Knitli][knitli_site]
[⬆ Back to top][nav_top]
</div>
<!-- Badges -->
[badge_license]: <https://img.shields.io/badge/license-MIT%20OR%20Apache--2.0-green.svg> "License Badge" [badge_mcp]: <https://img.shields.io/badge/MCP-compatible-purple.svg> "MCP Compatible Badge" [badge_python]: <https://img.shields.io/badge/python-3.12%2B-blue.svg> "Python Version Badge" [badge_release]: <https://img.shields.io/pypi/v/code-weaver.svg> "PyPI Version"
<!-- Other links -->
[api_find_code]: <src/codeweaver/agent_api/find_code/README.md> "find_code API Documentation" [arch_find_code]: <src/codeweaver/agent_api/find_code/ARCHITECTURE.md> "find_code Architecture" [bashandbone]: <https://github.com/bashandbone> "Adam Poulemanos' GitHub Profile" [codecov]: <https://codecov.io/gh/knitli/codeweaver/graph/badge.svg?token=EO3DQVHVVH> "Code Coverage" [changelog]: <https://github.com/knitli/codeweaver/blob/main/CHANGELOG.md> "Changelog" [cla]: <CONTRIBUTORS_LICENSE_AGREEMENT.md> "Contributor License Agreement" [cli_guide]: <docs/CLI.md> "Command Line Reference" [config_schema]: <schema/codeweaver.schema.json> "The CodeWeaver Config Schema" [docker_guide]: <https://docs.knitli.com/codeweaver/guides/docker/> "Docker Setup Guide" [docker_notes]: <docs/docker/DOCKER_BUILD_NOTES.md> "Docker Build Notes" [enhancement_label]: <https://github.com/knitli/codeweaver/labels/enhancement> "Enhancement Issues" [issues]: <https://github.com/knitli/codeweaver/issues> "Report an Issue" [knitli_blog]: <https://blog.knitli.com> "Knitli Blog" [knitli_github]: <https://github.com/knitli> "Knitli GitHub Organization" [knitli_linkedin]: <https://linkedin.com/company/knitli> "Knitli LinkedIn" [knitli_site]: <https://knitli.com> "Knitli Website" [knitli_x]: <https://x.com/knitli_inc> "Knitli X/Twitter" [link_license]: <LICENSE> "License File" [link_mcp]: <https://modelcontextprotocol.io> "Model Context Protocol Website" [link_python]: <https://www.python.org/downloads/> "Python Downloads" [link_release]: <https://github.com/knitli/codeweaver/releases> "CodeWeaver Releases" [mcp]: <https://modelcontextprotocol.io> "Learn About the Model Context Protocol" [local_only_guide]: <https://docs.knitli.com/codeweaver/guides/local-only/> "Local-Only Operation Guide" [nav_contributing]: <#-contributing> "Contributing Section" [nav_docs]: <https://docs.knitli.com/codeweaver/> "CodeWeaver Documentation" [nav_comparison]: <#-quick_reference_matrix> "How CodeWeaver Compares" [nav_features]: <#-features> "Features Section" [nav_how_it_works]: <#-how-it-works> "How It Works Section" [nav_install]: <#-getting-started> "Installation Section" [nav_top]: <#codeweaver> "Back to Top" [privacy_policy]: <PRIVACY_POLICY.md> "Privacy Policy" [providers_list]: <overrides/partials/providers.md> "Full Provider List" [qdrant]: <https://qdrant.tech> "Qdrant Website" [repo]: <https://github.com/knitli/codeweaver> "CodeWeaver Repository" [reuse_spec]: <https://reuse.software> "REUSE Specification" [sbom]: <sbom.spdx> "Software Bill of Materials" [sponsor]: <https://github.com/sponsors/knitli> "Sponsor Knitli" [telemetry_impl]: <src/codeweaver/common/telemetry/> "Telemetry Implementation" [telemetry_readme]: <src/codeweaver/common/telemetry/README.md> "Telemetry README" [uv_tool]: <https://astral.sh/uv> "uv Package Manager" [voyage_ai]: <http://voyage.ai> "Voyage AI Website" [why_codeweaver]: <https://docs.knitli.com/codeweaver/why/> "Why CodeWeaver" [wiki_ast]: <https://en.wikipedia.org/wiki/Abstract_syntax_tree> "About Abstract Syntax Trees"
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.