code-search

code-search is a skill for Claude Code, Codex from zhaoxingxing06/kimi-tree-lens. It costs 16 tokens per session (1,118 once invoked), scanned A, original, MIT.

A code-navigation tool for finding definitions, references, callers, and related structures across many programming languages. It reads code by its structure, not just by matching text.

In plain words
What is it for?
Use it to locate a function or class, inspect one method, find where a name is used, trace callers and callees, search code patterns, or review function complexity.
Why use it?
It reduces the time spent searching through large codebases and helps avoid misleading text matches. It can also highlight complex functions that may need review.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: mentions subagents.

Good fit Use it to locate a function or class, inspect one method, find where a name is used, trace callers and callees, search code patterns, or review function complexity.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/zhaoxingxing06/kimi-tree-lens/code-search
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add zhaoxingxing06/kimi-tree-lens --skill code-search
Clone the repo
git clone --depth 1 https://github.com/zhaoxingxing06/kimi-tree-lens

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for code-search

README.md
[![agentmods](https://agentmods.dev/badge/skills/zhaoxingxing06/kimi-tree-lens/code-search/github.svg)](https://agentmods.dev/skills/zhaoxingxing06/kimi-tree-lens/code-search)
Your own site
<a href="https://agentmods.dev/skills/zhaoxingxing06/kimi-tree-lens/code-search"><img src="https://agentmods.dev/badge/skills/zhaoxingxing06/kimi-tree-lens/code-search/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for code-search

Your own site · 80×15
<a href="https://agentmods.dev/skills/zhaoxingxing06/kimi-tree-lens/code-search"><img src="https://agentmods.dev/badge/skills/zhaoxingxing06/kimi-tree-lens/code-search.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 16 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,118 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00016 $0.01118
Opus 5 $0.00008 $0.00559
Sonnet 5 $0.00003 $0.00224
Haiku 4.5 $0.00002 $0.00112

Measured 9d ago against content hash ad4da7ad123c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

code-search scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/code-search/SKILL.md · 35 lines

How it starts

The opening of the file, as written. The whole thing — 35 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Detailed reference companion to the plugin's always-on system prompt (which carries the core rules): this file adds pagination, index semantics, path confinement, and extension points. Load it on demand — sub-agents can invoke it themselves.

For source code files (java, python, typescript, tsx, go):

  • Outline a file or find where a definition lives -> list_definitions(file)
  • Read one method/class/function body -> read_definition(file, name). Prefer this over Read on large files.
  • AST-shaped search (e.g. all call sites of a function, all assignments to a field) -> ast_search(file, pattern). Grep is for strings, comments and config files only.
  • Workspace-wide: run index_workspace(root) once, then find_references(name) (syntactic, name-based), go_to_definition(name, file?), callers(name) / callees(name) (heuristic call graph).
  • Audit & quality: list_presets({language?}) + preset_search(file, name); analyze_complexity(file) ranks functions by cyclomatic complexity.
  • get_node_types({language}) returns grammar node types and fields — use it to write correct ast_search patterns without trial and error.
  • Extend it: extra definition queries in ~/.kimi-code/tree-sitter-queries/<lang>/*.scm; audit presets in ~/.kimi-code/tree-sitter-queries/presets/<lang>/*.scm (first ;; line = description). Use the official upstream tags.scm format: @definition.<kind> optionally paired with @name and @doc (#strip! supported); legacy @<kind>.def still decodes. callers/callees are query-driven from official @reference.call tags where available (java/go/python; ts/tsx use built-in call extraction).
  • Paths are confined automatically: the plugin walks up from each file to the nearest project marker (.git, package.json, pom.xml, ...), or uses host-provided roots / TREE_SITTER_MCP_ROOTS. Markerless paths are rejected unless TREE_SITTER_MCP_ALLOW_UNCONFINED=1.
  • The workspace index auto-refreshes on file changes: the watcher re-parses ONLY the changed files (an index_version bump means an incremental update, not a full rebuild), and the index survives restarts via a disk cache whose reuse is verified by content hash — reused counts are safe to trust. index_status reports freshness.
  • Hidden directories (dot-prefixed) and build/dependency dirs (node_modules, target, dist, build, out, coverage, __pycache__, .venv, venv, vendor, gradle, .gradle) are excluded from both the initial walk and watcher updates. Throwaway probe/scratch files must live OUTSIDE any indexed root — files created inside one will never appear in the index.
  • list_definitions returning an empty list means the language is query-only.
  • file must be an absolute path unless workspace roots are available; relative paths then resolve against the first root.
  • On any tool error or timeout, fall back to Read/Grep directly. Do not retry the same call.

Multi-index (one index per root):

  • index_workspace keeps one index per root: indexing a new root adds an index instead of replacing the existing one; re-indexing the same root rebuilds it in place.
  • Index read ops (find_references, go_to_definition, callers, callees, index_status) accept an optional root. With several indexes you MUST pass root; omitting it errors with the available roots. index_status without root reports the most recently built index plus available_roots.
  • Read ops are paginated: limit (default 50, hard 200) / offset; responses carry total/returned/offset/truncated and the index_root/index_version they answered from. Page with offset instead of widening results; index_workspace reports files_truncated when the maxFiles cap clipped the file walk.

Main-agent discipline (sub-agents do NOT see this skill text — relay it yourself):

  • Keep index_workspace exclusive to the main agent. Delegate read-only lookups to a read-only sub-agent whose tool whitelist omits index_workspace (bundled: tree-lens-tracer for chain tracing, tree-lens-impact for pre-change blast radius, tree-lens-verifier for post-change checks).
  • When delegating, spell out in the task prompt: absolute paths, exact tool names, which root to query, and "re-check index_status and compare index_version before concluding". Sub-agents start with zero context and only see tool descriptions.
  • Require compact deliverables: conclusions + file:line references + the index_version used — never raw JSON dumps. Prompt-level rules are advisory; the hard guarantees are the tool whitelist and server-side clamping.

Read the full file on GitHub · 35 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 35 lines · 16 tokens per session scan A ad4da7ad123c

Subscribe to this mod's changes

code-search is a skill published in the GitHub repository zhaoxingxing06/kimi-tree-lens (0 stars, last pushed 9d ago), licensed MIT. It adds 16 tokens to every session and 1,118 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

debug-optimize-lcp

Guides debugging and optimizing Largest Contentful Paint (LCP) using Chrome DevTools MCP tools. Use this skill whenever the user asks about LCP performance, slow page loads, Core Web Vitals optimization, or wants to understand why their page's main content takes too long to appear. Also use when the user mentions…

ChromeDevTools/chrome-devtools-mcp · 99 tokens

systematic-debugging

Use when debugging a failing test, build error, or runtime issue that isn't immediately obvious. Guides a 4-phase root cause analysis instead of random fix attempts.

open-metadata/OpenMetadata · 37 tokens

diagnose

Trace from a reproduced symptom to the source code that causes it. Pin the specific file and approximate line, rate confidence in the cause and clarity of the fix independently, and always propose a concrete fix.

emdash-cms/emdash · 43 tokens

repro-admin

Reproduce an EmDash admin UI bug. Attach a container, start the demo dev server, drive the admin with agent-browser using the dev-bypass session, and capture the reproduction as screenshots plus a replayable transcript.

emdash-cms/emdash · 48 tokens

log-error-digest

Analyze log files to troubleshoot errors, identify peak error periods, and produce error clustering, frequency statistics, and time distribution reports. Supports JSON, syslog, and Nginx formats with automatic detection. Use when a user uploads a .log file and asks to analyze errors, find patterns, debug issues, or…

zebbern/claude-code-guide · 71 tokens

byted-util-volcengine-detect-retry

An orchestration workflow for Volcengine Cloud Detect, a service that checks websites or network endpoints from test locations.

bytedance/agentkit-samples · 101 tokens