All skills
oaustegard avatar

/searching-codebases

@04bfd5b

Binding-resolved Python symbol queries via pyright — every true caller (--refs), the real definition (--def), or an inferred signature (--hover) of a .py symbol, excluding the same-named false positives text search cannot tell apart. Use when a task needs ALL callers or users of a named Python symbol and grep would over-match. Python only, and only for the caller/definition question: measured 2026-07-04 on real issue-localization tasks, plain ripgrep tied or beat the semantic and indexed-regex tiers at 4-60x less wall-clock, so those tiers survive below without being a default.

Use this Skill: https://skilld.dev/gh/oaustegard/claude-skills/searching-codebases

This session only. Nothing lands on disk.

README.md

≈490 tokens on demand. Your agent reads this file only when SKILL.md points to it.

searching-codebases

Find code in any codebase by regex pattern or natural language concept. Auto-routes between n-gram indexed regex search (2-20x faster than ripgrep) and TF-IDF semantic search. Expands results to full functions via tree-sitting AST data. For Python sources, a binding-resolved reference/definition tier (pyright, via python-lsp) finds real callers and definitions without same-name false positives.

Features

  • Dual search modes — regex (pattern/identifier) and semantic (natural language concepts), auto-routed per query
  • N-gram indexed regex — sparse inverted index narrows candidate files by 90-99% before ripgrep verification
  • TF-IDF semantic search — cosine similarity ranking over code chunks (functions, classes)
  • Binding-resolved Python tier — --refs/--def/--hover via pyright: true find-all-callers and go-to-definition that exclude same-named, unrelated symbols and follow imports. Engaged lazily; degrades to the regex text path when pyright/node is unavailable
  • AST context expansion — --expand returns complete function/class bodies instead of line fragments
  • Flexible sources — accepts GitHub URLs, local directories, uploaded files/archives, or project knowledge
  • Mixed queries — multiple queries with different modes in a single invocation; indexes built once per mode

Dependencies

  • ripgrep — required for regex verification
  • tree-sitting — auto-installs the bare tree-sitter package when needed: for --expand context and for the symbol→position resolution that seeds the binding-resolved tier (grammars ship bundled). Regex and semantic search work without it
  • scikit-learn — required for semantic mode (auto-installs)
  • python-lsp — provides the binding-resolved tier (--refs/--def/--hover); self-bootstraps pyright on first use and needs system node (v18+). Without it those flags degrade to the regex text path

Source: SKILL.md on GitHub

3 warnings9d3 checks · Risk MEDIUM
  • Gen Agent Trust Hub9d

    This skill provides advanced code search capabilities but contains a security vulnerability in how it handles archive files (path traversal) and performs automated package installations at runtime.

  • Socket9d

    1 alert: gptSecurity

  • Snyk9d

    Risk: MEDIUM · 1 issue

Signed by skilld at 04bfd5b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "2.5.0"
}

README badge

README badge for oaustegard/claude-skills/searching-codebases