Skip to main content

Topos

the agent harness for structural code quality

Topos measures complexity, coupling, and risky data flows, then gives your agent a concrete target—from SLOP to GOLD.

Install Topos MCP in VS Code PyPI License Topos MCP server ClawHub

Install · What it checks · Under the hood · Docs · Issues


Why Topos

Coding agents produce working code quickly. The harder question is whether the result is still easy to understand, safe to change, and well-fitted to the rest of the repository. Quality is the new currency.

Topos computes that signal from program structure—not from an LLM review or a style opinion—and returns concrete failure locations and next actions. It is fast enough to sit inside the agent loop: measure, edit, verify, repeat.

Tests check behavior. Topos checks whether the implementation is built to keep changing.

Grounded in category theory, powered by a native-Rust engine.

Install and Quick Start

One binary. Every supported agent harness. A clean way back out.

1. Install the CLI

Use the verified release installer:

curl -fsSL https://docs.krv.ai/topos/install.sh | bash

Or install with Homebrew:

brew install krv-labs/tap/topos

[!TIP] Prefer an editor-managed install? In VS Code or Cursor, search @mcp topos in the Extensions view or choose Install MCP server. This is an alternative to topos install: your editor installs and manages the Topos MCP server for you.

2. Connect your coding agents

topos install detects every supported MCP harness and lets you configure any—or all—of them from one interactive checklist:

topos install
┌  Which agent integrations do you want to configure?
│
│  ↑↓ move · space toggle · a all · enter confirm · esc cancel
│
│ ❯ ○ Claude Code          (detected)
│   ○ Claude Desktop       (detected)
│   ● Codex CLI            (✓ active)
│   ● Gemini CLI           (✓ active)
│   ○ GitHub Copilot CLI   (detected)
│   ○ Cursor               (detected)
│   ○ VS Code              (detected)
│   ○ Google Antigravity   (detected)
└

Restart the agents you configured, then ask:

"Use Topos to find this repository's worst structural problem, make one focused improvement, and verify the result."

[!IMPORTANT] Too many tools spray MCP servers across agent JSON files, scatter symlinks around your machine, then leave you to burn half a Claude session untangling the mess—or pull your own hair out doing it. Topos does not play that game. We follow a leave-no-trace policy: topos status shows every registration, while topos uninstall opens the same selector, previews exactly what will change, and removes everything Topos installed. If Topos makes it easy to do, it should be just as easy to undo.

topos status
topos uninstall

See the agent setup guide for permissions, manual configuration, and troubleshooting.

3. Evaluate from the terminal

topos evaluate . -r

Topos discovers Python, Rust, JavaScript, TypeScript, C++, and Go automatically. Pass --language only when you want to narrow the run.

See Installation for platform support and alternative install paths.

Under the hood

Topos is a self-contained Rust CLI and MCP server. Analysis runs locally; your source code is not sent to an external model or hosted analysis service.

Component Role
tree-sitter Parses six languages and powers the native AST, CFG, CPG, PDG, and UAST representations.
GitNexus Supplies the repository dependency graph scored by COMPOSABLE (topos depgraph generate). Requires npm install -g gitnexus@1.6.8.
Sighthound Embedded in the MCP server for supplementary security findings; native CPG probes remain the SECURE scoring source.
Graphify Optional advisory orphan and fragile-edge detection via topos graphify / topos_refactor(target="graphify"); does not affect the medal. Requires pip install graphifyy.

The result is one agent-facing contract over several structural lenses: one score to optimize, explicit evidence for each failure, and a verification loop that can tell a real improvement from cosmetic churn.

More ways to use Topos

What Topos checks

Every file gets three independent verdicts:

  • SIMPLE — avoids unnecessary complexity using AST entropy and control-flow complexity.
  • COMPOSABLE — stays decoupled from the repository using module-dependency structure and Martin instability.
  • SECURE — avoids dangerous API reachability and taint paths in the code property graph.

Those verdicts roll up into one memorable quality medal without hiding which pillar failed:

Medal Criteria
🥇 GOLD Passes all 3
🥈 SILVER Passes 2 of 3
🥉 BRONZE Passes 1 of 3
SLOP Passes 0, or fails to parse

Topos also returns ranked refactor guidance: failing metric locations, control-flow cycles, load-bearing dependency edges, process bottlenecks, and optional Graphify knowledge-graph findings. Advisory findings never silently change the scored medal.

How the medal system is derived

The three pillars are pairwise incomparable and form an eight-element evaluation lattice; GOLD is their intersection.

---
config:
  layout: dagre
  theme: neutral
---
graph BT
    SLOP["❌ SLOP<br/>No Medal"]
    SIMPLE["🥉 BRONZE<br/>Simple"]
    COMPOSABLE["🥉 BRONZE<br/>Composable"]
    SECURE["🥉 BRONZE<br/>Secure"]
    SC["🥈 SILVER<br/>S ∧ C"]
    SSc["🥈 SILVER<br/>S ∧ Sc"]
    CSc["🥈 SILVER<br/>C ∧ Sc"]
    IDEAL["🥇 GOLD<br/>Quality Code"]

    SLOP --> SIMPLE
    SLOP --> COMPOSABLE
    SLOP --> SECURE
    SIMPLE --> SC
    SIMPLE --> SSc
    COMPOSABLE --> SC
    COMPOSABLE --> CSc
    SECURE --> SSc
    SECURE --> CSc
    SC --> IDEAL
    SSc --> IDEAL
    CSc --> IDEAL

    style SLOP       fill:#f8d7da,stroke:#842029,color:#000
    style SIMPLE     fill:#cd7f32,stroke:#5c3a1e,color:#fff
    style COMPOSABLE fill:#cd7f32,stroke:#5c3a1e,color:#fff
    style SECURE     fill:#cd7f32,stroke:#5c3a1e,color:#fff
    style SC         fill:#c0c0c0,stroke:#4a4a4a,color:#000
    style SSc        fill:#c0c0c0,stroke:#4a4a4a,color:#000
    style CSc        fill:#c0c0c0,stroke:#4a4a4a,color:#000
    style IDEAL      fill:#ffd700,stroke:#856404,color:#000

Measures · Category-theory foundations

Distribution

Topos ships four ways:

  • GitHub Releases — the topos CLI binary (macOS/Linux), via install.sh or a direct release download.
  • PyPItopos-mcp, a thin bin-wheel bundling the MCP server binary (pip install topos-mcp / uvx topos-mcp), zero Python runtime.
  • VS Code Marketplace — the Topos extension, bundling platform binaries.
  • Docker — a container image for Glama and other MCP-registry hosting.

Crate layout and adapter details: docs.krv.ai/topos/architecture.

Contributing

Topos is used internally at Krv Labs to manage AI-agent code output. We welcome bugs, ideas, and contributions.


Full documentation · Measures and metrics · Engineering notes

Made by Krv Labs

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

topos_mcp-0.4.4-py3-none-manylinux_2_34_x86_64.whl (13.6 MB view details)

Uploaded Python 3manylinux: glibc 2.34+ x86-64

topos_mcp-0.4.4-py3-none-manylinux_2_34_aarch64.whl (13.2 MB view details)

Uploaded Python 3manylinux: glibc 2.34+ ARM64

topos_mcp-0.4.4-py3-none-macosx_13_0_arm64.whl (9.9 MB view details)

Uploaded Python 3macOS 13.0+ ARM64

File details

Details for the file topos_mcp-0.4.4-py3-none-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for topos_mcp-0.4.4-py3-none-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 464bdc44a7d4b1012087f2c948480f71e6f5666c63e3f5488b4ee5c894d1bc8e
MD5 8943005458664c624291a642a68384c7
BLAKE2b-256 c4b94f762b41950f0d174114e660297c3dcc4689b0500f4d8c299db56408d671

See more details on using hashes here.

Provenance

The following attestation bundles were made for topos_mcp-0.4.4-py3-none-manylinux_2_34_x86_64.whl:

Publisher: release.yml on Krv-Labs/topos

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file topos_mcp-0.4.4-py3-none-manylinux_2_34_aarch64.whl.

File metadata

File hashes

Hashes for topos_mcp-0.4.4-py3-none-manylinux_2_34_aarch64.whl
Algorithm Hash digest
SHA256 c01c1ad8cf94806eb240330534fdd702b5fa659185b85ce8726777446cf6ec4d
MD5 bf93806270a82d4fd9f75783b9d54ef4
BLAKE2b-256 8cfb84a928c684c20acb17b9e9f8be72fead45491c69e4a175258e68fd09b742

See more details on using hashes here.

Provenance

The following attestation bundles were made for topos_mcp-0.4.4-py3-none-manylinux_2_34_aarch64.whl:

Publisher: release.yml on Krv-Labs/topos

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file topos_mcp-0.4.4-py3-none-macosx_13_0_arm64.whl.

File metadata

File hashes

Hashes for topos_mcp-0.4.4-py3-none-macosx_13_0_arm64.whl
Algorithm Hash digest
SHA256 85269dcf2bde1a3c6fab1fb0ade906d4ef37eca708dfb7ef92ba1cadfa60fc59
MD5 925291205b563fc266b69ba102cc9e46
BLAKE2b-256 a4e2abfaf19fc7b40d61978b86543155c0168a51c4a78504434a5950d03856e5

See more details on using hashes here.

Provenance

The following attestation bundles were made for topos_mcp-0.4.4-py3-none-macosx_13_0_arm64.whl:

Publisher: release.yml on Krv-Labs/topos

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page