tokensave — security grade SAFE, quality 62/100

Security audit verdict: SAFE · quality 62/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by aovestdipaperino · MCP Server · ★ 628

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is tokensave safe to install? View the security audit →

About tokensave

Semantic Code Intelligence for AI Coding Agents Fewer tokens • Fewer tool calls • 100% local Why tokensave? AI coding agents waste tokens exploring codebases. Every grep, glob, and file read costs money. On complex tasks, agents spawn multiple Explore sub-agents that scan hundreds of files just to build context. tokensave gives agents a pre-indexed semantic knowledge graph. Instead of scanning files, the agent queries the graph and gets instant, structured answers -- the right symbols, their relationships, and source

Quick Facts

Stars628
Forks65
LanguageRust
CategoryMCP Server
LicenseMIT
Quality Score61.9735389320676/100
Open Issues4
Last Updated2026-09-14
Created2026-02-26
Platformsmcp, rust
Est. Tokens~34k

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Rust Agent Tools

Frequently Asked Questions

What is tokensave?

tokensave is The most comprehensive code intelligence MCP server for AI coding agents. 40+ tools, 30+ languages, 9 agent integrations. Pre-indexed semantic knowledge graphs for instant code understanding — fewer t. It is categorized as a MCP Server with 628 GitHub stars.

What programming language is tokensave written in?

tokensave is primarily written in Rust.

How do I install or use tokensave?

You can find installation instructions and usage details in the tokensave GitHub repository at github.com/aovestdipaperino/tokensave. The project has 628 stars and 65 forks, indicating an active community.

What license does tokensave use?

tokensave is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools