An AI agent's safe read-only scout to orient in an unknown repository before touching it.
Voyager's repo-penetration organ — the eyes an AI agent sends ahead before it touches an unknown repository.
Voyager penetrates the web (@dir-ai/voyager),
the repo (this), and — next — networks. Repotector is the repo's guardian
that receives and controls; Voyager Repo is the agent's counterpart that reaches
outward and reports back, safely.
npx @dir-ai/voyager-repo scout . # orient in the repo you're standing in
npx @dir-ai/voyager-repo scout . --check-deps 10 # + vet 10 deps via Voyager
Like how Claude or Codex orient themselves in a new codebase — but as a safe,
repeatable tool. scout produces an orientation brief:
--check-deps N)npm install), committed secrets, missing
lockfile, large opaque binariesA careful newcomer, not a bulldozer:
.repotector/) — read
its active zones/leases and respect them before editing.--allow-install / --allow-exec / --allow-clone) — and execution,
when allowed, belongs in a sandbox.scout reads files and git;
it never runs the repo's code. (Execution, when consented, runs in Voyager's
hardened container.)0 oriented · 1 oriented + HIGH-risk finding(s) · 2 tool error.voyager-repo mcp
Tool: scout_repo — same orientation, safe-by-default (invasive flags off).
import { scout } from '@dir-ai/voyager-repo'
const brief = await scout('/path/to/repo', { checkDeps: 10 })
if (brief.risks.some((r) => r.level === 'high')) { /* caution */ }
0.x — Phase 1 (repo orientation) of the Voyager "senses" line. Roadmap:
capability analysis of a package's tarball, PyPI/cargo/go dependency vetting,
and the net organ (cloud/infra introspection).
MIT
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @dir-ai/voyager-repoMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-dir-ai-voyager-repo": {
"command": "npx",
"args": [
"-y",
"@dir-ai/voyager-repo"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup reference@dir-ai/voyager-reponpmio.github.dir-ai/voyager-repo works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.