ast-grep

ast-grep is a skill for Claude Code, Codex from OutlineDriven/outline-driven-development. It costs 57 tokens per session (1,227 once invoked), scanned A, original, Apache-2.0.

A code search and rewrite tool that understands the structure of programs, such as calls, functions, classes, and imports.

In plain words
What is it for?
Use it for structural searches, linting, or safe source-code replacements when text matching is too fragile.
Why use it?
It avoids the false matches and accidental edits that can happen when regular expressions are used on source code. Changes are checked and previewed before they are applied.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/outlinedriven/outline-driven-development/ast-grep
Any agent
npx skills add OutlineDriven/outline-driven-development --skill ast-grep
Clone the repo
git clone --depth 1 https://github.com/OutlineDriven/outline-driven-development

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ast-grep

README.md
[![agentmods](https://agentmods.dev/badge/skills/outlinedriven/outline-driven-development/ast-grep.svg)](https://agentmods.dev/skills/outlinedriven/outline-driven-development/ast-grep)
Your own site
<a href="https://agentmods.dev/skills/outlinedriven/outline-driven-development/ast-grep"><img src="https://agentmods.dev/badge/skills/outlinedriven/outline-driven-development/ast-grep.svg" alt="Measured on agentmods" height="20"></a>
Per session 57 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,227 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00057 $0.01227
Opus 5 $0.00028 $0.00613
Sonnet 5 $0.00011 $0.00245
Haiku 4.5 $0.00006 $0.00123

Measured yesterday against content hash ff045ffe3959, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

ast-grep scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

The scan reads SKILL.md. This mod also ships 2 executable files (scripts/ast_grep_helper.py, tests/smoke.sh), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.devin/skills/ast-grep/SKILL.md · 51 lines

How it starts

The opening of the file, as written. The whole thing — 51 lines — stays where its author put it; the contents beside it link to each section on GitHub.

ast-grep

Contract

Field Bound contract
Trigger AST-based modification, structural search, lint, or replacement too fragile for regex.
Authority Reversible local writes to VCS-tracked source files only. Search is read-only; rewrites apply only through the helper after dry-run review. Roll back via version control.
Side effect Local file writes through the helper two-pass validate/dry-run/apply flow; no remote, credential, or published mutation.
Done Pattern validated, blast radius reviewed, and rewrite landed at the correct scope.

Inputs

  • An ast-grep pattern, single-quoted in the shell so $VAR reaches ast-grep unexpanded.
  • A language (--lang) or a single target path whose extension auto-detects it; required for stdin patterns.
  • For rewrites: a rewrite template and one or more target paths (defaults to the current directory).
  • Optional: include/exclude globs (repeatable, prefix ! to exclude), context lines, JSON output mode.

Procedure

  1. Confirm the task is structural (call, function, class, or import shaped like a pattern), not text/regex/filename matching (use grep) or semantic type/reference lookup (use LSP or the compiler). ast-grep matches syntax, not bytes. Done when: the task is confirmed structural.
  2. Validate the pattern before searching: python3 scripts/ast_grep_helper.py validate '<pattern>' --lang <L>. Exit 0 means ast-grep parses it cleanly; exit 2 means malformed (the helper prints the parsed pattern tree showing the ERROR node). Fix and re-validate. Done when: validate exits 0.
  3. For a rewrite, run the dry-run: python3 scripts/ast_grep_helper.py replace '<pattern>' '<rewrite>' --lang <L> <paths>. Read the diff and the N matches across M files count. If the blast radius is wrong, stop and refine the pattern (tighten meta-variables, add --lang, add context); re-run the dry-run. Done when: the dry-run diff and match count are correct.
  4. Apply only after the dry-run diff is correct: python3 scripts/ast_grep_helper.py replace '<pattern>' '<rewrite>' --lang <L> <paths> --apply. The helper writes via a separate --update-all pass. Done when: files are updated via --update-all.
  5. Invoke ast-grep, never sg: sg collides with the setgroups binary on many systems. Done when: ast-grep is invoked, not sg.

Read the full file on GitHub · 51 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 51 lines · 57 tokens per session scan A ff045ffe3959

Subscribe to this mod's changes

ast-grep is a skill published in the GitHub repository OutlineDriven/outline-driven-development (52 stars, last pushed yesterday), licensed Apache-2.0. It adds 57 tokens to every session and 1,227 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

fin-brief-generator

根据用户输入或已有研究输出(文献综述/想法报告/新颖性报告),自动生成或更新FINBRIEF.md,减少用户填写负担。.

csmar432/finai-research · 42 tokens

doc-review

Use when the user asks to review or critique a prose planning document — a plan, spec, PRD, requirements doc, or design doc.

OutlineDriven/odin-claude-plugin · 32 tokens

autolearn

Compound a solved problem into a durable in-repo learning doc. Use when a verified non-trivial fix lands, the user says "compound this", "document this fix", or "remember this". This is the automatic-capture entry point; for an explicitly requested one-off write-up, use compound.

OutlineDriven/odin-claude-plugin · 65 tokens

deps-upgrade

Use when dependency upgrades need tiered batches for CVEs, a major release, forced compatibility, scheduled hygiene, a pre-release lockfile audit, or a cadence-driven or vulnerability-triggered sweep. Classifies each update on a risk ladder, verifies it, or defers it with a reason. Not for PR queue triage; use…

OutlineDriven/odin-claude-plugin · 78 tokens

askme

Explore intent with Verbalized Sampling before planning. Use when the task is ambiguous, you need maximum clarifying questions, or you want collaborative or adversarial mode via /askme.

OutlineDriven/odin-claude-plugin · 40 tokens

strict-validation-setup

Use when a user invokes a strict-mode validation or verifiable-goals loop setup. Bootstraps strict-mode tooling and per-task GOALS.md scaffolding so an agentic loop can self-verify. Don't use for remote, credential, publish, deploy, or irreversible changes.

OutlineDriven/odin-claude-plugin · 61 tokens