zero-review-graph
v0.1.0
Published
Graph-first code review for Go/Rust/ZeroLang workspaces — trace impact, read less. OpenCode plugin + MCP server (zrg / zrg-mcp).
Maintainers
Readme
ZeroReview Graph (ZRG) — OpenCode Library Kit
Trace impact. Read less. — Review the graph, not the guess.
A Go/Rust graph-first code-review toolkit for OpenCode, inspired by the minimal-context review model of code-review-graph and Zerolang’s semantic-graph and checked-edit model.
The goal is simple: make the agent ask the graph what deserves context before it reads the repository broadly.
This starter kit includes:
- a Go workspace indexer and CLI (
zrg), - a Go MCP server (
zrg-mcp), - an optional Rust reverse-impact accelerator (
zrg-core), - an optional Zerolang compiler-facts adapter,
- a thin OpenCode TypeScript plugin shim,
- a pointable OpenCode skill,
- and a provenance-aware OpenCode master ledger derived from the supplied Dynamic Agent Master Ledger.
Status: working prototype. ZRG is not feature-equivalent to either inspiration source. The current indexer intentionally favors a small, auditable surface over claiming call-graph knowledge it does not yet have.
Core idea
User / OpenCode task
│
▼
OpenCode skill + thin plugin shim
│
▼
Go MCP tools
graph_build
graph_search
impact_analyze
context_pack
zero_read
zero_patch_preview
│
├──────────────► Go graph/index + workspace_id
│ │
│ └── optional Rust reverse-impact core
│
└──────────────► optional Zerolang zero.graph / compiler facts
│
└── graph hash + checked-edit preview
All findings / status / provenance
│
▼
ZeroReview Graph OpenCode Master LedgerWhat “powered by Zerolang” means here
Zerolang is treated as an optional semantic-truth provider, not as a magic parser for arbitrary Go/Rust repositories. When zero.graph is present, ZRG can:
- run an allowlisted set of
zero query,zero inspect,zero check,zero test,zero verify-projection, andzero skillsoperations; - return the current
zero.graphSHA-256 alongside the result; - produce a
zero patchcommand preview without executing it.
That preserves Zerolang’s useful graph-hash and checked-edit model without granting this starter kit silent mutation authority.
Graph-first review sequence
The OpenCode skill teaches agents to use:
graph_build
↓
graph_search
↓
impact_analyze
↓
context_pack
↓
read the bounded source evidence
↓
zero_read (when zero.graph exists)
↓
report findings + limits + workspace_idworkspace_id is a first-class agent-use primitive: it identifies the exact indexed workspace snapshot derived from normalized indexed paths and SHA-256 content hashes. If the ID changes, prior graph conclusions may be stale.
Repository layout
.
├── cmd/
│ ├── zrg/ # local Go CLI
│ └── zrg-mcp/ # MCP stdio server
├── internal/
│ ├── graph/ # reverse impact + context pack + Rust fallback
│ ├── index/ # Go AST + bounded Rust lexical index
│ ├── model/ # snapshot/node/edge contracts
│ └── zero/ # allowlisted Zerolang adapter
├── rust/zrg-core/ # optional stdlib-only Rust impact engine
├── .opencode/
│ ├── plugins/zero-review-graph.ts
│ └── skills/zero-review-graph/
├── ledger/
│ ├── zero_review_graph_opencode_master_ledger.html
│ ├── MASTER_INDEX.yaml
│ ├── runtime.toml
│ ├── state.json
│ └── provenance/dynamic_agent_master_ledger.original.html
├── docs/
│ ├── brand/ # lockup, mark, board, topology (see docs/brand/README.md)
│ └── ...
├── scripts/
├── opencode.jsonc
└── BUILD_LEDGER.mdRequirements
Core CLI
Most core Go packages use only the standard library and were initially exercised during prototype development with Go 1.23. The repository-level supported build floor is Go 1.25+, because this project pins github.com/modelcontextprotocol/go-sdk v1.7.0, which requires Go 1.25 or later. Treat Go 1.25+ as the canonical requirement for building the complete project.
MCP server
- Go 1.25+
- network access on first dependency resolution, or a populated Go module cache
github.com/modelcontextprotocol/go-sdk v1.7.0
Optional Rust accelerator
- a current Rust toolchain (
cargo,rustc) - otherwise the Go impact engine is used automatically
Optional Zerolang
zeroonPATH- a Zerolang package/workspace if compiler facts are desired
Build
make bootstrap
make test
make buildOr manually:
go mod download
go test ./...
go build -o bin/zrg ./cmd/zrg
go build -o bin/zrg-mcp ./cmd/zrg-mcp
cargo build --release --manifest-path rust/zrg-core/Cargo.tomlTo prefer the Rust accelerator:
export ZRG_RUST_CORE="$PWD/rust/zrg-core/target/release/zrg-core"Local CLI
Build an index:
zrg build -root .Search graph nodes:
zrg search -graph .zrg/graph.json "main"Impact analysis accepts a graph node ID or an absolute indexed file path:
zrg impact -graph .zrg/graph.json -depth 3 /absolute/path/to/file.goCreate a byte-bounded review list:
zrg context -graph .zrg/graph.json -depth 3 -bytes 120000 /absolute/path/to/file.goZerolang facts:
zrg zero -root . query
zrg zero -root . inspect
zrg zero -root . checkPreview a checked patch without running it:
zrg patch-preview -root . --op 'addMain' --op 'addCheckWrite fn="main" text="hello\n"'OpenCode
opencode.jsonc configures the repository-local MCP integration. The project skill and plugin do not need to be manually “wired” through that file: OpenCode discovers project skills from .opencode/skills/ and local JavaScript/TypeScript plugins from .opencode/plugins/.
The plugin is intentionally a thin TypeScript shim because OpenCode loads local plugins as JavaScript/TypeScript modules; the substantive indexing, graph, MCP, and runtime behavior stays in Go/Rust.
The reusable skill lives at:
.opencode/skills/zero-review-graph/SKILL.mdThe plugin lives at:
.opencode/plugins/zero-review-graph.tsFor a global installation, prefer pointing OpenCode’s global skill/plugin locations at these repository-owned files rather than maintaining copied variants. Keep the repository as the canonical source.
MCP tool surface
| Tool | Purpose | Mutates source? |
|---|---|---:|
| graph_build | index the workspace and write .zrg/graph.json | No source mutation |
| graph_search | locate graph nodes before broad reads | No |
| impact_analyze | reverse-dependency blast radius | No |
| context_pack | return bounded file list, not file contents | No |
| zero_read | allowlisted Zerolang query/check operations | No source mutation intended |
| zero_patch_preview | return proposed zero patch command + hash | No execution |
See docs/MCP_TOOLS.md for request/response contracts.
What is implemented now
- deterministic
workspace_idfrom indexed path/content hashes; - Go file/function/type extraction with the Go parser;
- local Go module import edges;
- bounded Rust function/type/module/use extraction;
- Rust module-dependency approximation;
zero.graphsnapshot anchoring when present;- reverse-dependency BFS blast radius;
- byte-bounded context packs;
- optional Rust impact traversal with automatic Go fallback;
- Go MCP tool façade;
- OpenCode plugin + skill integration;
- derived self-contained HTML ledger with original ledger preserved intact.
What is intentionally not claimed yet
This is not yet equivalent to code-review-graph’s mature parser/analysis surface. The starter does not currently claim:
- Tree-sitter coverage across many languages;
- complete call-site or dynamic-dispatch resolution;
- inheritance/interface resolution;
- community detection;
- embedding/vector retrieval;
- incremental database updates;
- test-coverage edges;
- CI risk scoring;
- perfect Rust macro/module resolution;
- direct arbitrary source mutation through MCP.
Those are roadmap candidates, not hidden features.
Master ledger
Open:
ledger/zero_review_graph_opencode_master_ledger.htmlIt preserves the original 145-node uploaded ledger and appends 12 ZRG-specific source, runtime, OpenCode, and governance nodes. The original upload is retained byte-for-byte under ledger/provenance/ with its SHA-256 recorded in the derived ledger.
The ledger follows the supplied rule that resource discovery is separate from dependency adoption, preserves stable IDs and provenance, and treats cross-reference scores as retrieval hints rather than proof of compatibility.
Brand
ZeroReview Graph's visual system is a review instrument, not a mascot. The core mark — “The Review Lens” — is a broken zero ring (incomplete inspection by design) with three graph nodes and a diagonal review cut.
- Display name:
ZERO REVIEW GRAPH· Repo:zero-review-graph· Short:ZRG - Tagline: Trace impact. Read less. · Secondary: Review the graph, not the guess.
- Palette: Obsidian
#0A0E12, Graph Cyan#31E6D6, Graph Violet#7A5CFF, Review Amber#FFC857, Risk Coral#FF6B6B - Assets:
docs/brand/contains the canonical brand kit — lockup, mark, brand board, and supporting topology (seedocs/brand/README.md).
The supporting topology illustration contains one intentionally tiny easter egg (0xED + found it.); the core mark and lockup do not depend on it.
Brand identity:
docs/brand/zero-review-graph-brand-id.md· Board:docs/brand/board/zero-review-graph-brand-board.svg· Mark:docs/brand/logo/zero-review-graph-mark.svg· Topology:docs/brand/supporting/zero-review-graph-topology.svg
Source lineage and licensing
This project is independently implemented and inspired by, not presented as a fork or drop-in replacement for:
es-3581100/code-review-graph— MIT licensed; conceptual inspiration for minimal-context graph review, blast radius, and MCP ergonomics.es-3581100/zerolang— Apache-2.0 licensed; conceptual/runtime inspiration for semantic graph handles, graph hashes, query-before-edit, checked patch behavior, and projections.
See NOTICE and docs/SOURCE_LINEAGE.md.
The kit itself is licensed under Apache-2.0.
