npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

zero-review-graph

v0.1.0

Published

Graph-first code review for Go/Rust/ZeroLang workspaces — trace impact, read less. OpenCode plugin + MCP server (zrg / zrg-mcp).

Readme

ZeroReview Graph (ZRG) — OpenCode Library Kit

ZERO REVIEW GRAPH lockup

Trace impact. Read less. — Review the graph, not the guess.

A Go/Rust graph-first code-review toolkit for OpenCode, inspired by the minimal-context review model of code-review-graph and Zerolang’s semantic-graph and checked-edit model.

The goal is simple: make the agent ask the graph what deserves context before it reads the repository broadly.

This starter kit includes:

  • a Go workspace indexer and CLI (zrg),
  • a Go MCP server (zrg-mcp),
  • an optional Rust reverse-impact accelerator (zrg-core),
  • an optional Zerolang compiler-facts adapter,
  • a thin OpenCode TypeScript plugin shim,
  • a pointable OpenCode skill,
  • and a provenance-aware OpenCode master ledger derived from the supplied Dynamic Agent Master Ledger.

Status: working prototype. ZRG is not feature-equivalent to either inspiration source. The current indexer intentionally favors a small, auditable surface over claiming call-graph knowledge it does not yet have.

Core idea

User / OpenCode task
        │
        ▼
OpenCode skill + thin plugin shim
        │
        ▼
Go MCP tools
  graph_build
  graph_search
  impact_analyze
  context_pack
  zero_read
  zero_patch_preview
        │
        ├──────────────► Go graph/index + workspace_id
        │                         │
        │                         └── optional Rust reverse-impact core
        │
        └──────────────► optional Zerolang zero.graph / compiler facts
                                  │
                                  └── graph hash + checked-edit preview

All findings / status / provenance
        │
        ▼
ZeroReview Graph OpenCode Master Ledger

What “powered by Zerolang” means here

Zerolang is treated as an optional semantic-truth provider, not as a magic parser for arbitrary Go/Rust repositories. When zero.graph is present, ZRG can:

  • run an allowlisted set of zero query, zero inspect, zero check, zero test, zero verify-projection, and zero skills operations;
  • return the current zero.graph SHA-256 alongside the result;
  • produce a zero patch command preview without executing it.

That preserves Zerolang’s useful graph-hash and checked-edit model without granting this starter kit silent mutation authority.

Graph-first review sequence

The OpenCode skill teaches agents to use:

graph_build
   ↓
graph_search
   ↓
impact_analyze
   ↓
context_pack
   ↓
read the bounded source evidence
   ↓
zero_read (when zero.graph exists)
   ↓
report findings + limits + workspace_id

workspace_id is a first-class agent-use primitive: it identifies the exact indexed workspace snapshot derived from normalized indexed paths and SHA-256 content hashes. If the ID changes, prior graph conclusions may be stale.

Repository layout

.
├── cmd/
│   ├── zrg/                      # local Go CLI
│   └── zrg-mcp/                  # MCP stdio server
├── internal/
│   ├── graph/                    # reverse impact + context pack + Rust fallback
│   ├── index/                    # Go AST + bounded Rust lexical index
│   ├── model/                    # snapshot/node/edge contracts
│   └── zero/                     # allowlisted Zerolang adapter
├── rust/zrg-core/                # optional stdlib-only Rust impact engine
├── .opencode/
│   ├── plugins/zero-review-graph.ts
│   └── skills/zero-review-graph/
├── ledger/
│   ├── zero_review_graph_opencode_master_ledger.html
│   ├── MASTER_INDEX.yaml
│   ├── runtime.toml
│   ├── state.json
│   └── provenance/dynamic_agent_master_ledger.original.html
├── docs/
│   ├── brand/                  # lockup, mark, board, topology (see docs/brand/README.md)
│   └── ...
├── scripts/
├── opencode.jsonc
└── BUILD_LEDGER.md

Requirements

Core CLI

Most core Go packages use only the standard library and were initially exercised during prototype development with Go 1.23. The repository-level supported build floor is Go 1.25+, because this project pins github.com/modelcontextprotocol/go-sdk v1.7.0, which requires Go 1.25 or later. Treat Go 1.25+ as the canonical requirement for building the complete project.

MCP server

  • Go 1.25+
  • network access on first dependency resolution, or a populated Go module cache
  • github.com/modelcontextprotocol/go-sdk v1.7.0

Optional Rust accelerator

  • a current Rust toolchain (cargo, rustc)
  • otherwise the Go impact engine is used automatically

Optional Zerolang

  • zero on PATH
  • a Zerolang package/workspace if compiler facts are desired

Build

make bootstrap
make test
make build

Or manually:

go mod download
go test ./...
go build -o bin/zrg ./cmd/zrg
go build -o bin/zrg-mcp ./cmd/zrg-mcp
cargo build --release --manifest-path rust/zrg-core/Cargo.toml

To prefer the Rust accelerator:

export ZRG_RUST_CORE="$PWD/rust/zrg-core/target/release/zrg-core"

Local CLI

Build an index:

zrg build -root .

Search graph nodes:

zrg search -graph .zrg/graph.json "main"

Impact analysis accepts a graph node ID or an absolute indexed file path:

zrg impact -graph .zrg/graph.json -depth 3 /absolute/path/to/file.go

Create a byte-bounded review list:

zrg context -graph .zrg/graph.json -depth 3 -bytes 120000 /absolute/path/to/file.go

Zerolang facts:

zrg zero -root . query
zrg zero -root . inspect
zrg zero -root . check

Preview a checked patch without running it:

zrg patch-preview -root . --op 'addMain' --op 'addCheckWrite fn="main" text="hello\n"'

OpenCode

opencode.jsonc configures the repository-local MCP integration. The project skill and plugin do not need to be manually “wired” through that file: OpenCode discovers project skills from .opencode/skills/ and local JavaScript/TypeScript plugins from .opencode/plugins/.

The plugin is intentionally a thin TypeScript shim because OpenCode loads local plugins as JavaScript/TypeScript modules; the substantive indexing, graph, MCP, and runtime behavior stays in Go/Rust.

The reusable skill lives at:

.opencode/skills/zero-review-graph/SKILL.md

The plugin lives at:

.opencode/plugins/zero-review-graph.ts

For a global installation, prefer pointing OpenCode’s global skill/plugin locations at these repository-owned files rather than maintaining copied variants. Keep the repository as the canonical source.

MCP tool surface

| Tool | Purpose | Mutates source? | |---|---|---:| | graph_build | index the workspace and write .zrg/graph.json | No source mutation | | graph_search | locate graph nodes before broad reads | No | | impact_analyze | reverse-dependency blast radius | No | | context_pack | return bounded file list, not file contents | No | | zero_read | allowlisted Zerolang query/check operations | No source mutation intended | | zero_patch_preview | return proposed zero patch command + hash | No execution |

See docs/MCP_TOOLS.md for request/response contracts.

What is implemented now

  • deterministic workspace_id from indexed path/content hashes;
  • Go file/function/type extraction with the Go parser;
  • local Go module import edges;
  • bounded Rust function/type/module/use extraction;
  • Rust module-dependency approximation;
  • zero.graph snapshot anchoring when present;
  • reverse-dependency BFS blast radius;
  • byte-bounded context packs;
  • optional Rust impact traversal with automatic Go fallback;
  • Go MCP tool façade;
  • OpenCode plugin + skill integration;
  • derived self-contained HTML ledger with original ledger preserved intact.

What is intentionally not claimed yet

This is not yet equivalent to code-review-graph’s mature parser/analysis surface. The starter does not currently claim:

  • Tree-sitter coverage across many languages;
  • complete call-site or dynamic-dispatch resolution;
  • inheritance/interface resolution;
  • community detection;
  • embedding/vector retrieval;
  • incremental database updates;
  • test-coverage edges;
  • CI risk scoring;
  • perfect Rust macro/module resolution;
  • direct arbitrary source mutation through MCP.

Those are roadmap candidates, not hidden features.

Master ledger

Open:

ledger/zero_review_graph_opencode_master_ledger.html

It preserves the original 145-node uploaded ledger and appends 12 ZRG-specific source, runtime, OpenCode, and governance nodes. The original upload is retained byte-for-byte under ledger/provenance/ with its SHA-256 recorded in the derived ledger.

The ledger follows the supplied rule that resource discovery is separate from dependency adoption, preserves stable IDs and provenance, and treats cross-reference scores as retrieval hints rather than proof of compatibility.

Brand

ZeroReview Graph's visual system is a review instrument, not a mascot. The core mark — “The Review Lens” — is a broken zero ring (incomplete inspection by design) with three graph nodes and a diagonal review cut.

  • Display name: ZERO REVIEW GRAPH · Repo: zero-review-graph · Short: ZRG
  • Tagline: Trace impact. Read less. · Secondary: Review the graph, not the guess.
  • Palette: Obsidian #0A0E12, Graph Cyan #31E6D6, Graph Violet #7A5CFF, Review Amber #FFC857, Risk Coral #FF6B6B
  • Assets: docs/brand/ contains the canonical brand kit — lockup, mark, brand board, and supporting topology (see docs/brand/README.md).

The supporting topology illustration contains one intentionally tiny easter egg (0xED + found it.); the core mark and lockup do not depend on it.

Brand identity: docs/brand/zero-review-graph-brand-id.md · Board: docs/brand/board/zero-review-graph-brand-board.svg · Mark: docs/brand/logo/zero-review-graph-mark.svg · Topology: docs/brand/supporting/zero-review-graph-topology.svg

Source lineage and licensing

This project is independently implemented and inspired by, not presented as a fork or drop-in replacement for:

  • es-3581100/code-review-graph — MIT licensed; conceptual inspiration for minimal-context graph review, blast radius, and MCP ergonomics.
  • es-3581100/zerolang — Apache-2.0 licensed; conceptual/runtime inspiration for semantic graph handles, graph hashes, query-before-edit, checked patch behavior, and projections.

See NOTICE and docs/SOURCE_LINEAGE.md.

The kit itself is licensed under Apache-2.0.