Are you the author? Sign in to claim
Local MCP daemon that compresses your codebase before sending it to Claude 41-89% token reduction
AI coding assistants often fail because they retrieve the wrong context. On a large codebase, blindly dumping raw files into the prompt leads to hallucinations, slow responses, and high API costs.
Foldwork fixes this. It is a deterministic repository understanding engine that pre-indexes your entire codebase into a local SQLite catalog. It acts as the Context Layer for your IDE, serving exactly the functions the AI needs—no more, no less—maximizing the first-try success rate and reducing token usage by 41-89%.
By combining AST body folding (which strips out function bodies while preserving signatures) with canonical determinism (which guarantees byte-identical outputs to maximize Anthropic's KV cache hits), Foldwork transforms massive enterprise monorepos into lightweight, cache-friendly payloads. This drastically reduces token consumption, cuts API costs by up to 90%, and eliminates context window overflow.
No cloud. No telemetry. Runs entirely on your machine.--
Estimate the impact of AST code compression on large open-source repositories (calculated at $2.00 / million input tokens for Claude Sonnet 5):
| Repository | Total Files | Raw Context Tokens | Compressed Context Tokens | Token Reduction | Cost Saved / Run |
|---|---|---|---|---|---|
| Django | 2,359 | 5,554,607 | 596,752 | 89.3% | $10.99 |
| Tokio | 789 | 1,597,813 | 444,164 | 72.2% | $3.11 |
| Gin | 99 | 197,300 | 47,718 | 75.8% | $0.39 |
Numbers are reproducible. Run the open-source benchmark tool on any public repository:
mcp-benchmark repository
Run mcp-benchmark on your own project to see your exact savings before installing anything:
mcp-benchmark ./your-project
════════════════════════════════════════════════════════════════════════════════
mcp-injector Benchmark — context
Tier 3 compression | $2.00/1M tokens | 2026-07-15T12:00:00Z
════════════════════════════════════════════════════════════════════════════════
FILE RAW TOKENS COMPRESSED SAVED COST SAVED*
──────────────────────────────────────────────────────────────────────────────────────────
cmd/license-gen/main.go 3,633 214 94% $0.0072
main.go 17,555 1,917 89% $0.0347
website/api/webhook.go 2,682 295 89% $0.0053
main_test.go 1,576 353 78% $0.0031
──────────────────────────────────────────────────────────────────────────────────────────
TOTAL (4 files) 25,446 2,779 89.1% $0.0503
* Based on $2.00 / 1M input tokens
💡 Running this codebase through Claude 10×/day costs $0.51/day raw.
With mcp-injector: $0.01/day. You save $0.50/day ($15/month).
get_project_mapReturns a compressed structural overview of the workspace. Function bodies are folded and replaced with placeholders to reduce token usage.
tier (integer, optional): Compression tier to apply (default: 2).unfolded_files (array of strings, optional): Workspace-relative paths or glob patterns for files to serve at full resolution (uncompressed).path_prefixes (array of strings, optional): Scope the project map to specific microservices or packages, drastically reducing payload bloat.git_context: always includes current branch, changed files, and recent commits in the response.secrets_redacted: count of credentials automatically redacted before sending to Claude.Example call:
{
"tool": "get_project_map",
"arguments": {
"tier": 3,
"unfolded_files": ["src/auth/handler.go", "**/*_test.go"],
"path_prefixes": ["src/auth/"]
}
}
injector_retrieveRetrieves the full uncompressed source of a file from the local cache.
path (string, required): The workspace-relative path of the file to retrieve.retrievalKey (string, optional): The SHA-256 retrieval key returned in a prior compressed payload.start_line (integer, optional): 1-indexed start line for range retrieval.end_line (integer, optional): 1-indexed end line for range retrieval.expand_graph (boolean, optional): Resolves and appends cross-file dependencies (limited to 50 1st-degree dependencies).injector_searchBM25-ranked full-text symbol search over the local SQLite catalog. Supports FTS5 boolean logic (e.g., user AND (auth OR login)).
query (string, required): FTS5 query string (bare terms, "phrase", prefix*).limit (integer, optional): Maximum results (default: 20).search_paths (array of strings, optional): Scope search to specific isolated directories.injector_diagramGenerates a Mermaid sequence diagram for a given symbol by traversing its outbound dependencies (halts after 500 nodes).
symbol (string, required): The exact symbol name.max_depth (integer, optional): Maximum traversal depth (default: 3).include_primitives (boolean, optional): Include basic types (String, boolean) and framework boundaries.injector_regex_searchFallback for exact literal or regex searches against file contents. Bypasses FTS5 tokenization.
query (string, required): The string or regex pattern to search for.is_regex (boolean, optional): Treats query as extended regex (-E).injector_write_fileWrite a full file to disk. CRITICAL: Prevents data loss by intercepting and rejecting payloads containing compressed fold markers.
injector_blast_radiusAnalyzes the architectural impact of changing a symbol by traversing the dependency graph. Supports inbound and outbound directional traversal.
injector_git_contextIntegrates with local Git history to surface commit context, authorship, and code evolution directly into the LLM context.
injector_inspect_tableEnables direct database introspection capabilities. Currently supports PostgreSQL and MySQL.
CRITICAL: You must start the daemon with the FOLDWORK_DB_DSN environment variable set to your database connection string (e.g. postgres://user:pass@localhost:5432/dbname) to activate this tool.
injector_clear_cacheWipes the SQLite index cache and triggers a clean cold-start full re-index.
injector_statsReturns index status, current compression ratio, total files indexed, and cache hit rate.
injector_sync (Deprecated)Read tools automatically wait for pending indexing implicitly. You never need to manually call this tool.
Install the daemon locally and configure your IDEs:
curl -fsSL https://foldwork.dev/install | sh
Automatically configures Claude Desktop, Cursor IDE, VS Code, Devin Desktop, and Antigravity.
Run the benchmark CLI on your project to see your token savings and line count:
mcp-benchmark ./your-project
If your project is under 50,000 lines, mcp-injector is completely free. The benchmark output shows your exact line count.
curl -fsSL https://foldwork.dev/install | sh
The installer auto-detects Claude Desktop, Cursor, VS Code, Devin Desktop, and Antigravity and writes the MCP config automatically. You should see output like:
* mcp-injector v0.2.0 installed to /usr/local/bin/mcp-injector
* Claude Desktop configured
* Cursor configured
Restart your IDE and mcp-injector will be active.
The MCP server starts automatically when your IDE launches. No separate daemon process to manage.
In Claude Code or Cursor, ask Claude:
"Use get_project_map to show me the structure of this project"
Claude will call the mcp-injector tool and return a compressed map of your entire codebase. If you see module names, entry points, and dependency information - it is working.
When Claude needs to see the complete implementation of a compressed function, it automatically calls injector_retrieve. You can also trigger this explicitly:
"Show me the full implementation of UserService.java"
Claude will fetch the uncompressed source from the local cache.
Editing Code: You MUST use the injector_write_file tool to edit code. If Claude tries to write back folded placeholders into your source code, the daemon will hard-reject the payload to protect you from data loss.
injector_stats
Or ask Claude directly: "Call injector_stats and tell me my current token savings."
Now that your AI has deterministic tools to search, traverse, and retrieve code, you can ask it high-level architectural questions that usually fail on raw codebases:
injector_retrieve with expand_graph=true to traverse through middleware, validation, and database layers.injector_blast_radius (inbound traversal) to identify unused functions and isolated structs.injector_diagram to instantly draw the entire outbound execution sequence.injector_blast_radius to see exactly what services or packages rely on a specific core module.injector_search (BM25 full-text indexing) to find exact function definitions across millions of lines of code.injector_blast_radius to see every caller that will be impacted.injector_git_context to understand recent commits and author intent alongside the code.get_project_map gives the AI a compressed, birds-eye view of your entire architecture, allowing it to drill down into specific microservices using path_prefixes.Sometimes you need Claude to see the exact implementation of a file while keeping the rest compressed. Use the unfolded_files parameter:
In your MCP call or by asking Claude:
"Get the project map but show me src/auth/handler.go at full resolution"
This passes "unfolded_files": ["src/auth/handler.go"] to get_project_map. That file is served raw; everything else stays compressed.
Glob patterns work too:
"**/*_test.go" - all test files uncompressed"src/auth/*.go" - all files in a directory uncompressedmcp-injector installs a post-checkout git hook when it first runs. Branch switching automatically triggers a full re-index. You will see this in the daemon logs:
[mcp-injector] Branch switched to feature/auth-refactor, re-indexing...
[mcp-injector] Re-index complete in 4.2s (47,293 lines indexed)
Enterprise security teams often block AI coding tools because developers accidentally leak sensitive credentials in their context window.
mcp-injector solves this locally. The daemon includes a built-in Shannon entropy filter that analyzes all AST strings and comments in real-time. If it detects high-entropy strings (like AWS Access Keys, SSH private keys, or database passwords), it dynamically redacts them as [REDACTED: high entropy] before they ever leave your machine. Your API credentials are never sent to Anthropic.
If your codebase has a hardcoded API key or AWS credential, the get_project_map response will include:
"secrets_redacted": 2,
"files_with_redactions": ["config/db.go", "scripts/deploy.sh"]
The actual values are replaced with [REDACTED: high entropy]. Variable names are preserved so Claude still understands the code structure.
If the auto-installer does not detect your IDE, add this to your MCP config manually:
{
"mcpServers": {
"mcp-injector": {
"command": "/usr/local/bin/mcp-injector",
"env": {
"MCP_WORKSPACE": "/absolute/path/to/your/project",
"FOLDWORK_DB_DSN": "postgres://user:pass@localhost:5432/dbname"
}
}
}
}
Note: VS Code supports
"${workspaceFolder}", but Claude Desktop, Cursor, and Devin Desktop require a hardcoded absolute path to your project.
Config file locations:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json~/.config/Claude/claude_desktop_config.json~/.cursor/mcp.json.vscode/mcp.json~/.codeium/windsurf/mcp_config.json~/.gemini/antigravity/mcp_config.jsonSupports: Go, Python, TypeScript, JavaScript, Java, C++, C, C#, Rust.
You can run mcp-injector status in your terminal at any time. This CLI dashboard visually proves your exact token savings and estimated dollars saved by comparing your raw codebase tokens against the AST-compressed tokens in real-time.
mcp-injector automatically redacts secrets and credentials before they reach Claude's context window:
-----BEGIN RSA PRIVATE KEY-----)Redacted content is replaced with [REDACTED BY MCP-INJECTOR]. A count of redactions is included in the get_project_map response so you always know what was protected.
Your code never leaves your machine. Redaction happens locally before compression, and is always-on - it cannot be disabled.
To remove mcp-injector completely:
# Remove binary
sudo rm /usr/local/bin/mcp-injector
# Remove index cache and logs
rm -rf ~/.mcp-injector/
# Remove from IDE MCP config (edit manually):
# Claude Desktop (Linux): ~/.config/Claude/claude_desktop_config.json
# Claude Desktop (macOS): ~/Library/Application Support/Claude/claude_desktop_config.json
# Cursor: ~/.cursor/mcp.json
# VS Code: .vscode/mcp.json
# Devin Desktop: ~/.codeium/windsurf/mcp_config.json
# Antigravity: ~/.gemini/antigravity/mcp_config.json
# (Remove the "mcp-injector" entry from mcpServers)
mcp-injector automatically redacts the following before your code reaches Claude:
| Pattern | Example Match |
|---|---|
| AWS access key IDs | AKIAIOSFODNN7EXAMPLE |
| GitHub PATs (ghp_, ghs_) | ghp_aBcDeFg... |
| Stripe secret keys | sk_live_abc... / sk_test_abc... |
| JWT tokens | eyJ... |
| PEM private key headers | -----BEGIN RSA PRIVATE KEY----- |
| Generic high-entropy strings >20 chars | Detected via Shannon entropy |
| Password / secret / token assignments | password = "abc123" |
Redacted values are replaced with [REDACTED BY MCP-INJECTOR]. File paths and variable names are never redacted - only the values.
Commercial. Free tier available. Source code not public.
Support Contact: foldwork@proton.me
Run Claude Code as an MCP server so any agent can delegate coding tasks to it
Browser automation using accessibility snapshots instead of screenshots
Google's universal MCP server supporting PostgreSQL, MySQL, MongoDB, Redis, and 10+ databases
Official GitHub integration for repos, issues, PRs, and CI/CD workflows