ast-grep-find — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ast-grep-find (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Structural code search that understands syntax. Find patterns like function calls, imports, class definitions - not just text.
uv run python -m runtime.harness scripts/ast_grep_find.py \
--pattern "import asyncio" --language pythonuv run python -m runtime.harness scripts/ast_grep_find.py \
--pattern "async def \$FUNC(\$\$\$)" --language python --path "./src"uv run python -m runtime.harness scripts/ast_grep_find.py \
--pattern "console.log(\$MSG)" --replace "logger.info(\$MSG)" \
--language javascriptuv run python -m runtime.harness scripts/ast_grep_find.py \
--pattern "print(\$X)" --replace "logger.info(\$X)" \
--language python --dry-run| Parameter | Description |
|---|---|
--pattern | AST pattern to search (required) |
--language | Language: python, javascript, typescript, go, etc. |
--path | Directory to search (default: .) |
--glob | File glob pattern (e.g., **/*.py) |
--replace | Replacement pattern for refactoring |
--dry-run | Preview changes without applying |
--context | Lines of context (default: 2) |
| Syntax | Meaning |
|---|---|
$NAME | Match single node (variable, expression) |
$$$ | Match multiple nodes (arguments, statements) |
$_ | Match any single node (wildcard) |
# Find all function definitions
uv run python -m runtime.harness scripts/ast_grep_find.py \
--pattern "def \$FUNC(\$\$\$):" --language python
# Find console.log calls
uv run python -m runtime.harness scripts/ast_grep_find.py \
--pattern "console.log(\$\$\$)" --language javascript
# Replace print with logging
uv run python -m runtime.harness scripts/ast_grep_find.py \
--pattern "print(\$X)" --replace "logging.info(\$X)" \
--language python --dry-run| Tool | Best For |
|---|---|
| ast-grep | Structural patterns (understands code syntax) |
| warpgrep | Fast text/regex search (20x faster grep) |
Use ast-grep when you need syntax-aware matching. Use warpgrep for raw speed.
Requires ast-grep server in mcp_config.json.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.