DEV Community

VANSH ARORA
VANSH ARORA

Posted on

How We Built Blast Radius Impact Analysis for AI Agents Using Tree-Sitter

When a human refactors a function, they look at who calls it. When an AI agent refactors a function, it often looks only at the single open file and hallucinates that nobody else depends on the old signature.

To give agents real spatial awareness of code, we built symbol-level impact analysis into TokenCap using tree-sitter WASM grammars.

Methodology: From AST to Call Graph

  1. Parsing: Every JS, TS, Python, Go, Rust, and Java file is parsed into an abstract syntax tree.
  2. Symbol Extraction: Functions, methods, classes, and exported constants are cataloged with line-range coordinates.
  3. Call Resolution: Call expressions are matched against defined symbols using precision-aware resolution (disambiguating direct calls vs method invocations).
  4. Louvain Clustering: The dependency graph is clustered into functional domains to detect boundary crossings.

CLI Inspection in Action

You can query the blast radius directly from the command line:

tokencap ask impact src/auth/jwt.js:verifyToken
Enter fullscreen mode Exit fullscreen mode

Output:

Target: src/auth/jwt.js:verifyToken (function)
Direct Callers (4):
  - src/middleware/authMiddleware.js:14: authenticate
  - src/api/routes/user.js:45: handleProfile
  - src/api/routes/billing.js:28: handleInvoice
  - src/bridge/server.js:89: validateLoopbackSession
Transitive Reach: 18 files across 3 clusters
Boundary Crossings: Auth -> Billing, Auth -> API Gateway
Risk Assessment: HIGH (Core security primitive with multi-module reach)
Enter fullscreen mode Exit fullscreen mode

By exposing this data via the TokenCap MCP server, agents running in Claude Code, Cursor, or VS Code can check the impact of their planned edits before making them.

Explore the architecture at tokencap.vansharora.app

Top comments (0)