sgrep / home
SEMANTIC CODE SEARCH · JEV SYSTEM ONE

Search code
by meaning.

sgrep slices your repo into chunks and asks Jev one typed question per chunk — “does this match?” — then ranks by calibrated confidence. No keywords. No vector index.

~150 TOKENS/CALL· ~100MS/CALL· FREE OUTPUT· RUNS IN CI
JEV · TYPED DECISIONOUTPUT
$ sgrep scan ""
autobot/auth.py:1490.97
def verify_clerk_jwt(token):
server/middleware.py:130.94
class AuthMiddleware(Base):
server/api_keys.py:410.88
def check_api_key(request):
exec-worker/main.py:870.79
def require_worker_auth():
4 HITS · 175 CHUNKS JUDGED · 2.6S
02 — THE PROBLEM

Search "authentication". Now find verify_jwt().

The code that matters rarely spells out the concept. Here's how three approaches handle one query.

grep

Literal keyword match.

  • ✗ Misses verify_jwt() — the word isn't there
  • ✗ Fires on comments that mention the term
  • ~ Fast, but you read every false hit
vector index

Prebuilt embedding DB.

  • ~ Must build & keep an index in sync
  • ~ Approximate nearest-neighbour recall
  • ✗ Goes stale as code changes
sgrep meaning

Jev decides, one chunk at a time.

  • ✓ Finds verify_jwt() by what it does
  • ✓ No index — every chunk judged live
  • ✓ Ranked by calibrated confidence
01

Discover

Prune vendor dirs, skip minified.

02

Chunk

ast & tree-sitter units.

03

Pre-filter

Model2Vec + BM25 → top-k.

04

Jev decides

One typed question / chunk.

05

Rank

By calibrated confidence.

05 — BENCHMARKS

Fewer tokens for the same answer.

Claude agents answered the same questions about a distributed app (~450 files, 4 services), comparing grep-and-read, plain sgrep, and sgrep + its graphify call graph. Same model, verified same-quality answers.

−41%
total tokens
−68%
code read into context
=
answer quality (verified)
3
domains · 4 services

Describe-a-flow question · tokens

lower is better
Manual sgrep
Authentication−49%
manual
76,679
sgrep
39,020
Script-execution−45%
manual
81,498
sgrep
44,797
Trigger-node config−25%
manual
62,730
sgrep
47,038

The win scales with scatter: auth spans 3 services + client (−49%); trigger config lives in one tidy app (−25%).

Show the numbers
Domain Manual sgrep Lines Δ
Authentication 76,679 39,020 2,990→672 −49%
Script-execution 81,498 44,797 4,361→918 −45%
Trigger-node config 62,730 47,038 1,856→1,343 −25%
Total 220,907 130,855 9,207→2,933 −41%

Connection question · blast radius

3-way · lower is better
Manual raw sgrep sgrep + graphify
tokens−64%
manual
75,460
raw sgrep
55,954
+ graphify
27,061
wall-clock−36%
manual
146s
raw sgrep
247s
+ graphify
94s

"What breaks if we change the worker dispatch?" — sgrep + graphify used −64% tokens, read 94% fewer lines, and finished fastest (94s vs 146s / 247s). Plain semantic search can't traverse callers — that arm fell back to grep. Use trace/impact for connection questions; plain scan for find/describe.

Latency ladder

3-query batch · lower is better

Batch multi-query + a warm daemon flipped the wall-clock sign from slower to faster.

cold, in-process
7.87s
warm daemon
5.31s
warm + cache
1.11s

Warm daemon −33% vs cold · cached re-scan −86%. n = 1 per cell — directional. Full report in BENCHMARK.md ↗

06 — INSTALL

Up and running in a minute.

Python 3.10+. The first run pulls a tiny (~7 MB) local embedding model for the pre-filter.

# global, isolated command (recommended)
$ pipx install "git+https://github.com/Lagnajit09/sgrep@v0.3.0"

# or into the current environment
$ pip install -e .

# set your Jev key — macOS / Linux (add to ~/.zshrc to persist)
$ export TYPESAFE_API_KEY="sk-..."
# …or Windows PowerShell (persists for new sessions)
> setx TYPESAFE_API_KEY "sk-..."
# …or set once, used from any dir: ~/.config/sgrep/.env  (Windows: %APPDATA%\sgrep\.env)
$ echo 'TYPESAFE_API_KEY=sk-...' >> ~/.config/sgrep/.env

# optional backup provider — Vercel AI Gateway (auto falls back to it)
$ export VERCEL_AI_GATEWAY_API_KEY="vck-..."

# ask your codebase anything
$ sgrep scan "where are JWT tokens verified" ./src

# batch several questions in one run
$ sgrep scan "how are requests authenticated" ./src -q "service-to-service auth" --json

# follow the call graph: trace a flow, or a change's blast radius
$ sgrep trace  "how is a script dispatched to the worker" ./src
$ sgrep impact --symbol build_worker_payload ./src
  • →No API key? Run with --mock for an offline stand-in for Jev.
  • →Providers. TypeSafe direct (default) or the Vercel AI Gateway — the key resolves from an OS env var, a local .env, then a global ~/.config/sgrep/.env.
  • →Going faster. sgrep serve keeps the model warm; add --daemon to any scan.
  • →Follow the call graph. sgrep trace and sgrep impact map callers & callees via graphify — 2–3× cheaper on connection questions.
  • →Ignore rules. A .sgrepignore plus automatic skipping of build/vendor & minified files.
07 — CLAUDE CODE & CODEX

Add it to your coding agent.

sgrep ships as an agent skill, so Claude Code and Codex reach for scan / trace / impact on their own. One SKILL.md, published straight from the repo as a plugin marketplace — the agent runs the CLI you installed, the skill just teaches it when.

Claude Code
# add the marketplace, then install the skill
› /plugin marketplace add Lagnajit09/sgrep
› /plugin install sgrep@sagex-tools

# Claude now uses sgrep on its own — or call it directly
› /sgrep:sgrep
Codex
# add the Agent Plugins marketplace, then the plugin
$ codex plugin marketplace add Lagnajit09/sgrep
$ codex plugin add sgrep@sagex-tools

# invoke the skill with $sgrep
  • →One skill, both agents. The same SKILL.md serves Claude Code and Codex through the open Agent Plugins standard.
  • →Auto-invoked. The agent reaches for sgrep on “where/how does X work?” and “what breaks if I change Y?” — or you call it explicitly.
  • →Wraps the CLI. Install sgrep and set your key first; the skill runs scan/trace/impact for you.
  • →No registry. Your GitHub repo is the marketplace — bump the version to ship an update.
Semantic grep Compare Benchmarks Install Agents POWERED BY JEV · TYPESAFE SYSTEM ONE