AgentmapBLOCK
Stop your coding agent reading the wrong files. Compiler-grade TS/JS repo map — 100% precision on blast radius vs grep's 60%, measured on public repos. CLI + MCP server, fully local, no vector DB.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
= 20">
Your agent burns most of its context just finding code. This gives it the answer in one line.
npx @raymondchins/agentmap --relates lib/db/schema.ts
relates: lib/db/schema.ts (pr 0.073744) dependents (21): lib/types.ts, lib/utils.ts, lib/db/queries.ts, components/chat/message.tsx, app/(chat)/api/chat/route.ts, ...
Every file on that list really imports it. grep gets 40% of them wrong.
💸 What it saves
Token cost of the hidden first step in every agent task — find the relevant code — on a real 154-file Next.js app (vercel/ai-chatbot, sha 2becdb4):
27d033393e28OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add agentmap -- npx -y @raymondchins/[email protected]
Exposed tools (14)
13 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
affected | write | Which test files cover a source file, following import edges transitively — and, just as usefully, whether ANY do. Answers |
any | read | Unified router: resolve a query against the repo map (file → symbol → feature) then fall back to a live git-grep for string/copy/data literals. Best default for |
callers | read | Compiler-accurate call graph: every call site that INVOKES a symbol, resolved by the TypeScript language service (not tree-sitter name-matching) — so a type-position mention, a re-export, or a same-named local in another file is never mis-attributed. Symbol-level blast radius: |
calls | read | Compiler-accurate OUTGOING call graph: every in-project symbol that a given symbol INVOKES, resolved by the TypeScript language service (not tree-sitter name-matching) — callee resolution follows real bindings (imports/re-exports) through to the actual declaration. Answers |
feature | read | List all files belonging to a named feature plus its external dependents. |
features | read | List every detected feature (top-level app/ route segment) with its file count. |
find | read | Find every symbol whose name matches (substring, case-insensitive) — exported symbols plus non-exported top-level declarations. Use to locate a function/class/type before rebuilding it. A match reached through a re-export barrel carries |
hubs | read | List the most important files in the repo by PageRank (the hubs everything imports). Read these first to understand a codebase. |
map | read | Token-budgeted ranked digest of the codebase (PageRank + Aider-style symbol ranking). Optionally focus toward a file and/or set a token budget. |
relates | read | Blast radius for a file: its exports, imports, direct dependents, and the files most related to it by random-walk relevance. Use before editing to see who breaks. |
route | read | Resolve one URL path (e.g. |
routes | read | The Next.js App Router route table: every URL path the repo serves, with the file that serves it. Next.js only — on any other repo this returns an explicit |
search | read | Rank symbols by BM25 lexical relevance for a VAGUE natural-language query (e.g. |
symbols | read | Top N globally ranked symbols (Aider-style importance). Defaults to 30. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (18)
":!*.pem", ":!*.key", ":!*.p12", ":!*.pfx", ":!*.crt", ":!id_rsa*",
":!*.p8", ":!*.jks", ":!*.keystore", ":!id_ed25519*", ":!id_ecdsa*",
":!.npmrc", ":!**/.npmrc", ":!.netrc", ":!**/.netrc",
":!.git-credentials", ":!**/.git-credentials", ":!.pgpass", ":!**/.pgpass",
const SECRET = "SUPER_SECRET_VALUE_ZZQ";
const SECRET = "EXPANDED_SECRET_VALUE_ZZQ";
return createHash("sha1").update(entries.join("\n")).digest("hex");return createHash("sha1").update("HEAD:" + sha + "\n" + toks.join("\n")).digest("hex");console.log(`agentmap token-savings benchmark`);
".git-credentials": `https://user:${SECRET}@github.com\n`,"apps/web/tsconfig.json": '{"extends":"../../packages/shared-config/tsconfig.base.json","compilerOptions":{"allowJs":true},"include":["src/**/*.ts"]}\n',"apps/web/tsconfig.json": '{"extends":"../../packages/shared-config/tsconfig.base.json","compilerOptions":{"allowJs":true},"include":["src/**/*.ts"]}\n',"app/dashboard/page.ts": 'import { run } from "../../src/main";\nexport const page = run();\nexport const MAGIC_TOKEN = "zephyr-42";\n','import { helper } from "../../core/src/index";\nexport const v = helper();\n',`import { FORMAT_VERSION } from "../../lib/format";`,@types/node, typescript
byte-identical to the CLI) so a planted "ignore previous instructions" in an
- **Over MCP, the lines are fenced as data.** The `any` tool appends a second content block marking the result as raw untrusted repository content, so a planted "ignore previous instructions" in an or
Gates applied: no_behavioural_pass.
27d033393e28full audit observations/trust-audit/mcp-server/raymondchins__agentmap-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 27d033393e28 | BLOCK | D | 69 | first audit |
Questions
What is the Agentmap MCP server?
Stop your coding agent reading the wrong files. Compiler-grade TS/JS repo map — 100% precision on blast radius vs grep's 60%, measured on public repos. CLI + MCP server, fully local, no vector DB.
What tools does Agentmap expose?
14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Agentmap safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Agentmap need?
No credential environment variables were found in its source, so it appears to need none.
How does Agentmap run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @raymondchins/agentmap at 0.22.0.
How current is this page?
The grade is for one exact copy of the source (27d033393e28), read on 2026-10-08. The repository is watched and re-audited when it changes.