Osnova

io.github.getdomovoiv0.11.0Updated Oct 1, 2026

Deterministic code map for AI coding agents: a tree-sitter call graph with exact file:line over MCP.

Installation

In SourceWeft

  1. Open Osnova in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

[osnova. A deterministic code map for AI coding agents. Ten tools over MCP and CLI.]

Osnova

[npm version] [license Apache-2.0] [ci] [node >=22.13] [M8ven Verified]

A deterministic code map for AI coding agents. Osnova indexes a repository into a symbol and call graph with tree-sitter, then serves it to any MCP client or from the command line. Same input, same output, byte for byte. No embeddings, no telemetry, and no network connection unless you type osnova update-check. Twenty languages, seven of them (TypeScript, JavaScript, Python, Go, Rust, Java, C#) with deep adapters.

Osnova is the Slavic word for base or foundation. That is the job: give an agent solid ground to stand on before it edits code.

[A coding agent asks osnova a question and gets back exact file and line, the resolution basis and an omission count; osnova reads a local cache that is built and refreshed from the repository by tree-sitter parsing.]

Quick start

Node.js 22.13 or newer. Serve a repository to any MCP client:

sh
npx -y @getdomovoi/osnova mcp --workspace /path/to/repo

After npm install -g @getdomovoi/osnova, one command per kind of agent: claude wires Claude Code (MCP entry, session, prompt and stop hooks, and the skill); agents wires every installed harness that reads AGENTS.md (Codex, OpenCode, Kilo, Pi, Cursor), each with its hooks, plugin or extension, plus one shared skill in ~/.agents/skills/. Each previews its changes; --apply writes them, backing up every file it changes.

sh
osnova setup claude --applyosnova setup agents --apply

Or add the MCP entry by hand; replace osnova with npx -y @getdomovoi/osnova when there is no global install.

json
{ "mcpServers": { "osnova": { "command": "osnova", "args": ["mcp"] } } }
[One agent turn in five steps: prompt, footing, edit, settle, review; footing and settle are answered by osnova from the index, the rest are the agent or the developer acting.]

What you get back

[A terminal recording: osnova warp lists the five resolved callers of click Context.invoke, each with its receiver hint; grep finds twelve .invoke( lines; osnova plumb checks those twelve and reports five confirmed, six name-only matches on other invoke methods and one line inside a docstring.]

osnova warp src/api.ts#refreshWorkspace on this repository, cut to twelve lines (test/docs-readme-warp.test.ts fails when the first two no longer reproduce):

text
function src/api.ts#refreshWorkspace: 83 indexed edgesreach: d1 callers 83 in 14 files (3 dirs); d2 +16 in 2 files; unresolved same-name 10; tests 18d1 calls src/cli/cli.ts#ensureIndex:78 [import-binding]d1 calls src/cli/hook.ts#runHook:191,203,225,240 [import-binding]d1 calls src/mcp/server.ts#createOsnovaMcpServer.refresh:297 [import-binding]d1 calls test/verification-fastpath.test.ts#<module>:37,47,48,51,53,57,58,64,68,74,78,85,110,114,132,145,154,166,171,197 [re-export-binding]  via src/index.ts:65 refreshWorkspace -> src/api.ts (export refreshWorkspace)This does not prove absence of callers or that deletion is safe.unresolved evidence (10); not confirmed relationshipscandidates for refreshWorkspace (2, unverified): src/api.ts#refreshWorkspace, test/mcp-watch.test.ts#refreshWorkspaced1 calls refreshWorkspace test/artifact-format9.test.ts:78,85,104,120,140 [binding-blocked]d1 calls refreshWorkspace scripts/perf.mjs:485,486,491 [import-target-unresolved]

Each confirmed line names the caller, its lines and the evidence that tied the call to this definition: an import binding, a same-file definition, a re-export chain with its hop, or an identified receiver. Calls the index could not tie to a definition are listed apart as unresolved evidence, with the same-name candidates it found and the reason it stopped, so a name match is never mistaken for a caller. The reach line gives exact counts, not scores, and when the list outgrows its budget a capped: line and an omitted: footer count what was left out.

How much of the graph is exact

A call site counts as resolved when the index ties it to one definition through evidence it can name; everything else stays unresolved with a reason. These are the shares on the pinned checkouts under benchmarks/corpora/, recorded in benchmarks/results/resolution-coverage-2026-09-21b.json; the last column leaves out calls through packages outside the repository and calls to builtins, which can never resolve locally, and the reference defines every column.

CorpusLanguagesCall sitesResolvedShareExcluding externals
clickall6593290344.0%62.4%
cobraall4374198045.3%88.9%
gsonall23382847336.2%56.7%
humanizerall30517779825.6%51.3%
pyrightall585783007051.3%74.5%
ripgrepall13387612145.7%71.6%
zodall534172163040.5%73.2%

Per-language rows are in the reference. osnova coverage reports the same numbers for your own repository, per language and per reason.

Resolved is not the same as right, so the call edges are also scored against a type checker. Every call site in two pinned checkouts was sent to the language's own checker for the callee's declarations, and each osnova edge was marked true when the symbol it names contains that declaration and false when it does not. Measured at 0.8.0: on click (160 files, pyright 1.1.414) 2883 edges were decided and 0 are false, and osnova covers 90.4% of the call sites the checker resolves inside the repository. On zod (702 files, TypeScript 5.9.3) 21276 edges were decided and 4 are false, a false-edge rate of 0.02%, with 76.9% of in-repo sites covered. The four false edges are listed by site in benchmarks/results/type-checker-oracle-2026-09-21.json with the method and its limits. The scripts that produce these numbers are in benchmarks/oracle/, and they reproduce every count at 0.10.0.

Grep versus the graph

The reason to keep a call graph instead of running a text search is not speed. It is that the first regex a person types is wrong more often than it looks, and nobody notices. Nine call-site sets in five languages were verified line by line; each cell shows sites found (precision / recall), and the method lists what each side got wrong.

CorpusTargetVerified sitesText searchResolved graph
clickContext.invoke depth 21312 (0.92 / 0.85)12 (1.00 / 0.92)
pyrightgetChildNodes depth 2285 (0.80 / 0.14)28 (1.00 / 1.00)
cobraCommand.Root depth 13030 (1.00 / 1.00)30 (1.00 / 1.00)
cobraCommand.PersistentFlags depth 11213 (0.92 / 1.00)12 (1.00 / 1.00)
humanizerConfigurator.GetFormatter depth 11819 (0.74 / 0.78)18 (1.00 / 1.00)
ripgrepSearcher.line_terminator depth 11232 (0.38 / 1.00)12 (1.00 / 1.00)
ripgrepLineTerminator.as_byte depth 12626 (1.00 / 1.00)26 (1.00 / 1.00)
gsonJsonReader.beginObject depth 11029 (0.34 / 1.00)10 (1.00 / 1.00)
gsonTypeToken.getRawType depth 12743 (0.63 / 1.00)27 (1.00 / 1.00)

The graph never returned a site that was not a call of the target. The record is benchmarks/results/grep-vs-graph-2026-09-21.json.

The ten tools

The names play on the foundation image. The CLI uses the same names without the prefix: osnova ground and osnova_ground are the same query.

ToolMeaningDoes
osnova_groundthe ground you stand onKeyword search: ranked definitions with exact file:line
osnova_threadthe thread you follow through the clothText search: regex or literal matches grouped by symbol
osnova_outlinethe outline of one partSignatures and line spans for one file
osnova_warpthe threads that hold the weaveCall graph: callers and callees, direct or transitive
osnova_groundworkthe groundwork under everythingRepository map: directory clusters, hubs and hotspots
osnova_footingthe footing you build onTask context: definitions, relationships and candidate tests around a question
osnova_settlehow the ground settles after a changeChange impact: the symbols a diff touches and their indexed dependents
osnova_plumbthe plumb line dropped straight throughCheck claims: which listed call sites the index confirms, and which dependents were left out
osnova_teststhe cloth pulled to see what holdsTests: the test files that reference a symbol, or the symbols one test file reaches
osnova_unreferencedthreads left loose at the edgeDefinitions with no indexed caller, each with its leads; candidates, never proof

Every MCP response opens with its index generation, says when the index is partial, and counts what its budget left out; the budgets, and which CLI subcommands carry the generation, are in the reference.

Hooks and clients

One global install serves every repository and every client: one entry in each client's global config, nothing per project, nothing written inside your repository. osnova setup claude and osnova setup agents show the diff and write nothing until --apply; agents skips a harness whose config folder is missing, --only codex,pi narrows it, and a skill or plugin file you edited is kept and reported. --uninstall reverses either family the same way, previewing first. The table lists the per-client form, for one piece at a time. What each hook prints, when it stays quiet, and what the trials measured are in the reference.

ClientHow to wireWhat it adds
Claude Codeosnova setup --apply --client claude-code --hooksMCP entry plus session, prompt and stop hooks; --skill adds the skill, --nudge the opt-in grep nudge
Claude Code, as a plugin/plugin marketplace add getdomovoi/osnova then /plugin install osnova@osnovaThe same MCP entry, hooks and skill, run through npx -y @getdomovoi/osnova, with no global install; updates follow the marketplace
Codexosnova setup --apply --client codex --hooksMCP entry plus the same three hooks; trust them in /hooks or Codex skips them silently; step by step in Osnova with Codex
Cursorosnova setup --apply --client cursor --hooksMCP entry plus the stop hook as a follow-up message
OpenCodeosnova setup --apply --client opencode --pluginMCP entry plus a plugin that appends starting points to each message; the tool guidance comes from the MCP instructions
Kiloosnova setup --apply --client kilo --pluginMCP entry plus the same plugin
Piosnova setup --apply --client pi --pluginMCP entry through pi-mcp-adapter plus an extension that does the same

In CI

The action runs osnova settle --base-ref against the pull request base and lists every indexed dependent of the symbols the pull request changed; the report is indexed structural evidence only, so a missing dependent is not proof that nothing depends on the change.

yaml
- uses: actions/checkout@v4  with:    fetch-depth: 0- uses: getdomovoi/[email protected]  with:    depth: "2"

Inputs and the local form are in the reference.

What osnova does not do

  • No type inference and no dynamic dispatch. Edges come from syntax: direct calls, imports, name references, declared heritage (a written superclass or interface name) and framework routes (a registration whose receiver binds to a listed framework import, with the verb and the literal path written at the site), with lexical binding and receiver hints for TypeScript, JavaScript and Python. Resolution is heuristic and says so.
  • No route table. A routes edge is one registration site tied to one handler; prefixes from mounts, blueprints and controllers are recorded on their own edges and never composed into a full path, a computed path records no path, and an inline closure or a wrapped handler records the route with no target. Express, NestJS, Flask and FastAPI are read; gin, axum, Django, Spring, ASP.NET, Rails and file-based routers are not.
  • That boundary has a measured price. Scored against a type checker on two pinned corpora, the calls osnova does not resolve are mostly calls whose receiver type is never written down: 2945 of 6359 missed sites on zod and 164 of 307 on click are a plain name carrying no annotation, and another 1478 on zod are a call result or a property chain. Only 349 missed sites on zod and 10 on click have a type written at the receiver's declaration, and 248 of those 349 are a single library idiom. Resolving every one of them would move recall from 76.9% to 78.2% on zod and from 90.4% to 90.7% on click, so the boundary costs roughly one recall point rather than ten. The full census is in benchmarks/results/receiver-boundary-census-2026-09-21.json.
  • No semantic search. osnova_ground is fielded lexical ranking over definitions. It is fast, deterministic and explainable, and it will not match a paraphrase.
  • No proof of safety. An empty caller list means the index found no caller, not that none exists.
  • No cost claims. Agent trials so far show correctness parity with and without the graph on small tasks. A benchmark that separates the two is in progress.

How it stays honest

  • Every query refreshes the index from the working tree first, uncommitted edits included, and reports its generation.
  • Every clipped output says how much was clipped. Every ranked list says how many candidates it dropped. Partial indexes say so on every response.
  • Every hit carries a file:line span, a source hash and an index generation, so you can check what the agent cites.
  • Every benchmark result in benchmarks/results/ is frozen with its corpus fingerprint, and rejected experiments stay on record next to accepted ones.
  • The cache verifies a SHA-256 over the structural core before parsing it and hash-checks each source text on read. Nothing is written outside it.

CLI

Every tool is a subcommand: osnova build <root>, osnova warp <symbol>, osnova settle --base-ref <ref>, plus coverage, check, doctor, setup and mcp. The full list is in the reference.

Library

import { buildIndex, ask, callersDetailed, renderMapCard } from "@getdomovoi/osnova". The structured APIs return complete results with omission counts; the text budgets apply to CLI and MCP presentation only. Every export is in the reference.

Contributing

Bug reports, language adapters, benchmark corpora and agent trials are all welcome. Read CONTRIBUTING.md for the gates a change must pass: lint, typecheck, tests, build, perf budgets and package smoke.

sh
pnpm installpnpm lint && pnpm typecheck && pnpm test && pnpm build && pnpm perf

Determinism is the core invariant. A change that makes incremental refresh differ from a full rebuild by one byte is a bug.

License

Apache-2.0

Privacy: PRIVACY.md. Security policy and reporting: SECURITY.md.

Source: README.md at commit 34e8c85

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.11.0LatestOct 1, 2026