{"_id":"@agent-tool-platform/ast-summarizer","_rev":"2-9d062b29d25a8066a79cb09e8749bb82","name":"@agent-tool-platform/ast-summarizer","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@agent-tool-platform/ast-summarizer","version":"0.1.0","license":"MIT","_id":"@agent-tool-platform/ast-summarizer@0.1.0","maintainers":[{"name":"ashergarland","email":"asher.garland@gmail.com"}],"homepage":"https://github.com/ashergarland/agent-tool-server-ast-summarizer#readme","bugs":{"url":"https://github.com/ashergarland/agent-tool-server-ast-summarizer/issues"},"bin":{"agent-tool-ast-summarizer":"dist/mcp/stdio.js"},"dist":{"shasum":"5618270f6445d80277607312538e2e7d37349b79","tarball":"https://registry.npmjs.org/@agent-tool-platform/ast-summarizer/-/ast-summarizer-0.1.0.tgz","fileCount":60,"integrity":"sha512-6iJlSi09xU/SLkUOdvbj53/dvWxkEIwXdinf8WBN8rN5tmB4Aeu6y1i0i3w+a6LSYxT8znKIL8XmwjBlPHazfA==","signatures":[{"sig":"MEQCICZsCKf5kCPFrL6kuh//5GSlXHQmw9uoXnuJsZztWbItAiB1Y9y8trt+O5Dh/eIUbFB9rqT/niTQWBPTXo8g3kfhww==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":245660},"main":"./dist/public.js","type":"module","_from":"file:C:/Users/AsherGarland/.copilot/session-state/164f10df-10e2-4392-a22f-d95da149598b/files/ast-summarizer-bootstrap-0.1.0-ad7bc46d/agent-tool-platform-ast-summarizer-0.1.0.tgz","types":"./dist/public.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/public.d.ts","import":"./dist/public.js"}},"gitHead":"ad7bc46d4696f4d22de20fce828d03dc2ef3d4cf","scripts":{"dev":"tsx watch src/index.ts","lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","start":"node dist/index.js","format":"prettier --write .","lint:fix":"eslint . --fix","prebuild":"npm run clean","mcp:stdio":"node dist/mcp/stdio.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","format:check":"prettier --check .","openapi:emit":"tsx scripts/emit-openapi.ts openapi.json","package:smoke":"tsx scripts/package-smoke.ts","test:coverage":"vitest run --coverage","metadata:validate":"agent-tool-validate-metadata --server server.json --package package.json --registry examples/central-registry-entry.json"},"_npmUser":{"name":"ashergarland","email":"asher.garland@gmail.com"},"_resolved":"C:\\Users\\AsherGarland\\.copilot\\session-state\\164f10df-10e2-4392-a22f-d95da149598b\\files\\ast-summarizer-bootstrap-0.1.0-ad7bc46d\\agent-tool-platform-ast-summarizer-0.1.0.tgz","_integrity":"sha512-6iJlSi09xU/SLkUOdvbj53/dvWxkEIwXdinf8WBN8rN5tmB4Aeu6y1i0i3w+a6LSYxT8znKIL8XmwjBlPHazfA==","repository":{"url":"git+https://github.com/ashergarland/agent-tool-server-ast-summarizer.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP and HTTP tools for local AST skeletons and dependency graphs.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","typescript":"5.9.3","@agent-tool-platform/runtime":"0.1.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"4.23.11","eslint":"9.39.5","vitest":"4.1.10","prettier":"3.9.6","@types/node":"22.20.1","typescript-eslint":"8.66.0","@vitest/coverage-v8":"4.1.10","eslint-config-prettier":"10.1.8","@agent-tool-platform/testkit":"0.1.2"},"_npmOperationalInternal":{"tmp":"tmp/ast-summarizer_0.1.0_1787550204853_0.3631431786519783","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agent-tool-platform/ast-summarizer","version":"0.1.1","description":"MCP and HTTP tools for local AST skeletons and dependency graphs.","license":"MIT","type":"module","engines":{"node":">=22.0.0"},"main":"./dist/public.js","types":"./dist/public.d.ts","exports":{".":{"types":"./dist/public.d.ts","import":"./dist/public.js"}},"bin":{"agent-tool-ast-summarizer":"dist/mcp/stdio.js"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"scripts":{"clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","prebuild":"npm run clean","build":"tsc -p tsconfig.build.json","start":"node dist/index.js","dev":"tsx watch src/index.ts","mcp:stdio":"node dist/mcp/stdio.js","openapi:emit":"tsx scripts/emit-openapi.ts openapi.json","metadata:validate":"agent-tool-validate-metadata --server server.json --package package.json --registry examples/central-registry-entry.json","package:smoke":"tsx scripts/package-smoke.ts","typecheck":"tsc -p tsconfig.json --noEmit","lint":"eslint .","lint:fix":"eslint . --fix","format":"prettier --write .","format:check":"prettier --check .","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage"},"repository":{"type":"git","url":"git+https://github.com/ashergarland/agent-tool-server-ast-summarizer.git"},"dependencies":{"@agent-tool-platform/runtime":"0.1.2","typescript":"5.9.3","zod":"4.4.3"},"devDependencies":{"@agent-tool-platform/testkit":"0.1.2","@types/node":"22.20.1","@vitest/coverage-v8":"4.1.10","eslint":"9.39.5","eslint-config-prettier":"10.1.8","prettier":"3.9.6","tsx":"4.23.11","typescript-eslint":"8.66.0","vitest":"4.1.10"},"gitHead":"93bffa78d3fbbb4d835a8da55f33af68e48ec8cd","_id":"@agent-tool-platform/ast-summarizer@0.1.1","bugs":{"url":"https://github.com/ashergarland/agent-tool-server-ast-summarizer/issues"},"homepage":"https://github.com/ashergarland/agent-tool-server-ast-summarizer#readme","_integrity":"sha512-KLP86c/Ylp+oqCTVHuZdHwql2GX4Xfai59UEXUjWrFpzq/l1vMlMPWz44jFgXNaavAmiVl07y73oplVwnKXRxw==","_resolved":"/home/runner/work/_temp/agent-tool-platform-ast-summarizer-0.1.1.tgz","_from":"file:/home/runner/work/_temp/agent-tool-platform-ast-summarizer-0.1.1.tgz","_nodeVersion":"24.19.0","_npmVersion":"11.19.0","dist":{"integrity":"sha512-KLP86c/Ylp+oqCTVHuZdHwql2GX4Xfai59UEXUjWrFpzq/l1vMlMPWz44jFgXNaavAmiVl07y73oplVwnKXRxw==","shasum":"2d8b89aec963a2fb8fa0a4de18a16e7b730794a7","tarball":"https://registry.npmjs.org/@agent-tool-platform/ast-summarizer/-/ast-summarizer-0.1.1.tgz","fileCount":60,"unpackedSize":245731,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-tool-platform%2fast-summarizer@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDJC5tvR5aXd1eyvy5K1saQhP1mm5PjZ0PCex+IQA+7eAiAJfoLR0R/YX8sXXimkm7r41vpjvW5VSq24OFO5SiFW+Q=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c61f1050-62b0-41b4-9c9b-e2f197b9ed59"}},"directories":{},"maintainers":[{"name":"ashergarland","email":"asher.garland@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ast-summarizer_0.1.1_1787679367563_0.6087282494839408"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-24T05:43:24.727Z","modified":"2026-08-25T17:36:08.045Z","0.1.0":"2026-08-24T05:43:24.992Z","0.1.1":"2026-08-25T17:36:07.715Z"},"bugs":{"url":"https://github.com/ashergarland/agent-tool-server-ast-summarizer/issues"},"license":"MIT","homepage":"https://github.com/ashergarland/agent-tool-server-ast-summarizer#readme","repository":{"type":"git","url":"git+https://github.com/ashergarland/agent-tool-server-ast-summarizer.git"},"description":"MCP and HTTP tools for local AST skeletons and dependency graphs.","maintainers":[{"name":"ashergarland","email":"asher.garland@gmail.com"}],"readme":"# Agent Tool Server AST Summarizer\n\nRead-only TypeScript and JavaScript structure analysis for one local workspace, exposed over stdio\nMCP (primary), stateless Streamable HTTP MCP, and HTTP/OpenAPI. It lets an agent learn what a file\ndeclares and what it depends on without reading implementations.\n\nThis repository is a **capability**: it owns AST behaviour and nothing else. Transports, the tool\nregistry, authentication, rate limiting, OpenAPI generation, lifecycle, readiness aggregation, and\nthe filesystem root boundary come from [`@agent-tool-platform/runtime`](https://www.npmjs.com/package/@agent-tool-platform/runtime).\n\nThe publication-ready package identity is `@agent-tool-platform/ast-summarizer`. The initial npm\npublication is intentionally deferred to M2.5, so the installation commands below describe\npost-publication usage rather than current registry availability.\n\n## Tools\n\n| Tool                   | Purpose                                                                       |\n| ---------------------- | ----------------------------------------------------------------------------- |\n| `get_file_skeleton`    | Declaration-only view of one source file: signatures, types, bounded doc text |\n| `get_dependency_graph` | Bounded local source relationships from one entry file                        |\n\nBoth tools are read-only (`kind: read`, `routing.changesState: false`). The server never executes,\nwrites, installs, clones, or generates source, and it never sends source to an external service.\nEach tool publishes routing metadata — `useWhen`, `doNotUseWhen`, `nextSteps`, and `scope` — so an\nagent can choose between them without trial and error.\n\n**The server reads source from its own filesystem; a caller only ever sends a path string.** That\nsingle rule decides which deployment shapes work. Read [`docs/use-cases.md`](docs/use-cases.md)\nbefore planning a deployment — in particular, pointing VS Code at a remote instance is not\nsupported, because a remote server cannot see your local files.\n\n## Package consumption (after initial publication)\n\nAST Summarizer is local-first because it must read the workspace being analysed. The normal MCP\ndeployment is therefore a local stdio process launched with the workspace as its root, not a remote\nservice.\n\n### Local MCP host\n\nAn MCP host may let `npx` resolve and launch the package's sole executable:\n\n```json\n{\n  \"servers\": {\n    \"ast-summarizer\": {\n      \"type\": \"stdio\",\n      \"command\": \"npx\",\n      \"args\": [\"--yes\", \"@agent-tool-platform/ast-summarizer\"],\n      \"env\": { \"AST_WORKSPACE_ROOT\": \"${workspaceFolder}\" }\n    }\n  }\n}\n```\n\nFor a pinned installation, install the package in the host project and launch the\n`agent-tool-ast-summarizer` bin. `AST_WORKSPACE_ROOT` takes precedence; when it is unset or blank,\nthe executable uses its launch directory.\n\n### Programmatic composition\n\nNode/TypeScript assemblies import the side-effect-free capability definition from the package root:\n\n```ts\nimport {\n  astSummarizerCapability,\n  astManifest,\n  type GetFileSkeletonInput,\n  type GetFileSkeletonOutput,\n} from '@agent-tool-platform/ast-summarizer';\n```\n\nThe public surface is intentionally narrow: the capability definition, its manifest, AST\nconfiguration types, and typed inputs and outputs for both tools. Internal services, projectors,\nworkspace adapters, and transport bootstraps are not public deep imports.\n\n## Repository development in VS Code\n\n### Analysing this repository\n\nAlready configured. Install dependencies, reload the window, and the `ast-summarizer` server from\n[`.vscode/mcp.json`](.vscode/mcp.json) is available to the agent:\n\n```bash\nnpm ci\n```\n\nIt runs from TypeScript source through `tsx`, so there is no build step to forget and no risk of\nanalysing a stale `dist/`.\n\n### Analysing a different repository\n\nBuild once here, then register the built entry point in the repository you want to analyse:\n\n```bash\nnpm ci\nnpm run build\n```\n\n`.vscode/mcp.json` in that repository:\n\n```json\n{\n  \"servers\": {\n    \"ast-summarizer\": {\n      \"type\": \"stdio\",\n      \"command\": \"node\",\n      \"args\": [\"/absolute/path/to/agent-tool-server-ast-summarizer/dist/mcp/stdio.js\"],\n      \"env\": { \"AST_WORKSPACE_ROOT\": \"${workspaceFolder}\" }\n    }\n  }\n}\n```\n\n`${workspaceFolder}` scopes the server to that repository, so it reads those files and no others.\n\nstdio is a local, non-networked transport, so it runs with authentication disabled and writes\nnothing but protocol traffic to stdout. One process serves exactly one root; run one scoped\ninstance per folder of a multi-root workspace.\n\nTry it by asking the agent: _\"Use the skeleton tool on `src/ast/projector.ts` and tell me what it\nexports.\"_\n\n## Workspace boundary\n\n- The readable root is canonicalized once with `realpath`.\n- Every input is resolved with `realpath` and must land strictly beneath that root.\n- Absolute paths, drive-relative paths, UNC paths, NUL bytes, traversal, links that escape the root,\n  directories, unsupported extensions, and `node_modules` are refused with stable errors.\n- Only root-relative POSIX paths are returned. Absolute paths never appear in results, errors, or\n  logs.\n- HTTP deployments must set `AST_WORKSPACE_ROOT`. Without it the process starts, stays live, and\n  reports **not ready**; every tool call returns `not_ready`.\n\nSupported extensions: `.ts`, `.tsx`, `.mts`, `.cts`, `.js`, `.jsx`, `.mjs`, `.cjs`.\n\n## What a skeleton contains\n\nThe skeleton is a **projection, not compilable source**. Declarations are re-rendered from an\nexplicit whitelist of structural pieces, so no original expression can survive into the output.\n\nRetained: exported declarations and overloads, interfaces, type aliases, enum member names, callable\nshapes for exported arrow and function expressions, class members with modifiers, re-exports,\ndefaults, namespaces and ambient modules, referenced import provenance, and bounded JSDoc.\n\nRemoved and reported under `omissions`: function, method, accessor, and constructor bodies; variable,\nproperty, enum-member, parameter, and destructuring initializers; export-default and export-equals\nexpressions; decorator arguments; non-literal computed property names; runtime heritage expressions;\nstatic blocks; and top-level executable statements. Omissions are counted, never restated as text\nthat resembles a value.\n\nVisibility: public and protected members are included. `private` and `#private` members require\n`AST_INCLUDE_PRIVATE_MEMBERS=true` or `includePrivateMembers: true` on the call.\n\nTypes: an annotation is rendered when it is free of runtime expressions. Otherwise the type is\ninferred **only** from the single file already loaded — never by loading a project — and a type that\ncannot be resolved safely is reported as `unknown` with a warning rather than guessed. Inferred\ntypes that would restate a literal value are discarded.\n\nJavaScript: `module.exports = { ... }`, `module.exports = fn`, and `exports.name = ...` are described\nby shape. Anything that cannot be described without evaluating it is reported as unsupported.\n\nMalformed input: syntax diagnostics are returned, `complete` is `false`, and the result is presented\nas a recovery view rather than a full one.\n\n## Resolution\n\nRelative imports, re-exports, `require`, dynamic `import()`, and `import x = require()` are followed.\nA `tsconfig.json` or `jsconfig.json` at or above the entry file is used, but only its\nresolution-relevant options; the include/exclude file set is never expanded and `extends` chains are\nfollowed only while they stay inside the root. Otherwise NodeNext-style resolution applies.\n\nEvery reference is classified: resolved in-root (`dependencies`, with `traversed`), package\n(`external`), or `unresolved` with a reason of `missing`, `unsupported`, `out_of_root`, or\n`limit_stopped`.\n\n`maxDepth` is the number of edges followed from the entry: `0` analyses the entry only.\n\n## Limits\n\nEvery analysis is bounded by deployment ceilings for per-file and cumulative bytes, graph depth,\nfiles and edges, declarations, members, JSDoc characters, result characters, request deadline, and\nconcurrent and queued jobs. See `.env.example` for names and defaults, which are sized for a\ndeveloper machine and a 0.25 vCPU / 0.5 GiB container.\n\nA call may lower a limit but never raise it; an over-large request is clamped with a `limit_clamped`\nwarning. Results are truncated only at declaration or member boundaries, never by slicing JSON, and\nthey always carry `complete`, `truncated`, `limitsReached`, counts, and bounded `warnings`.\nAnalysis admission is bounded by a semaphore and queue; surplus demand is rejected as a retryable\n`busy` error, and shutdown drains in-flight work.\n\n## HTTP contract\n\n| Method            | Path                | Authentication | Purpose                                       |\n| ----------------- | ------------------- | -------------- | --------------------------------------------- |\n| `GET`             | `/health`           | Public         | Liveness only                                 |\n| `GET`             | `/ready`            | Public         | Configuration, workspace, and capacity checks |\n| `GET`             | `/version`          | Public         | Build and capability metadata                 |\n| `GET`             | `/openapi.json`     | Public         | OpenAPI 3.1 generated from the registry       |\n| `GET`             | `/tools`            | Required       | Tool catalogue and input/output schemas       |\n| `POST`            | `/tools/{toolName}` | Required       | Invoke one registered tool                    |\n| `GET/POST/DELETE` | `/mcp`              | Required       | Stateless Streamable HTTP MCP                 |\n\n```bash\nAPI_KEY=\"$(openssl rand -hex 32)\"\nAUTH_MODE=api-key API_KEYS=\"$API_KEY\" AST_WORKSPACE_ROOT=\"$PWD\" npm run dev\ncurl -H \"x-api-key: $API_KEY\" http://localhost:8080/tools\n```\n\n`src/tools/definitions.ts` is the single source of truth. Zod schemas drive runtime validation, MCP\nregistration, JSON Schema, and OpenAPI through the platform registry, so the registry, HTTP endpoint,\nOpenAPI operation, and MCP tool counts are the same number by construction. Do not define\ntransport-specific tool lists.\n\n## Architecture\n\n```text\nstdio MCP / Streamable HTTP MCP / HTTP + OpenAPI     <- @agent-tool-platform/runtime\n                     |\n                ToolRegistry                          <- @agent-tool-platform/runtime\n                     |\n              astSummarizerCapability                 <- src/capability.ts\n                     |\n                 AstService  --- budgets, deadline, semaphore\n                     |\n   projector (declarations)   graph (resolution)\n                     |\n          TypeScript Compiler API (parse only)\n```\n\n| Owner                                 | Responsibility                                                                                                                                                                                                                                |\n| ------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `@agent-tool-platform/runtime`        | HTTP server, MCP (stdio and Streamable HTTP), tool registry and routing grammar, OpenAPI, authentication, rate limiting, lifecycle, readiness aggregation, error contract, logging, cancellation, concurrency, `RootBoundary`, telemetry seam |\n| `@agent-tool-platform/ast-summarizer` | Declaration projection, dependency resolution, diagnostics, type rendering, AST limits and budgets, AST workspace policy, AST configuration, readiness contributors, context-savings estimates                                                |\n\nThe whole HTTP entry point is:\n\n```ts\nimport { startAgentToolApplication } from '@agent-tool-platform/runtime';\nimport { astSummarizerCapability } from './capability.js';\n\nawait startAgentToolApplication(astSummarizerCapability);\n```\n\n`src/mcp/stdio.ts` is the same capability started through the platform's\n`startStdioAgentToolApplication`, which owns the silent logger, local execution semantics, the MCP\nserver, the transport, signal handling, and ordered shutdown. The only thing the file decides is AST\npolicy: the workspace defaults to `process.cwd()`, and a blank `AST_WORKSPACE_ROOT` is treated as\nunset. No listener is bound and nothing but protocol traffic reaches stdout.\n\n```ts\nimport { startStdioAgentToolApplication } from '@agent-tool-platform/runtime/capability';\nimport { astSummarizerCapability } from '../capability.js';\n\nawait startStdioAgentToolApplication(astSummarizerCapability, {\n  env: {\n    ...process.env,\n    AST_WORKSPACE_ROOT: process.env['AST_WORKSPACE_ROOT']?.trim() || process.cwd(),\n  },\n});\n```\n\n`src/ast/workspace.ts` composes the platform's `RootBoundary` — canonical root resolution,\nrelative-input enforcement, symlink containment, realpath handling, regular-file validation, bounded\nreads, and the per-file byte ceiling — and adds only AST policy: analysable extensions, the\n`node_modules` exclusion, and the AST readiness vocabulary.\n\n## Security defaults\n\n- Production refuses `AUTH_MODE=disabled`; only the local stdio transport disables authentication.\n- API keys must be randomly generated (`openssl rand -hex 32`); the platform refuses short,\n  repetitive, or low-entropy values. They are compared as fixed-width keyed HMAC digests in constant\n  time, and only non-reversible 12-character fingerprints are retained. Raw keys are never logged.\n- Authentication is rate limited before and after credential verification.\n- One bounded error contract across transports: stable code, safe message, retryability, request ID,\n  and limited details. No absolute path, source text, compiler internal, environment value, or stack\n  is ever exposed.\n- Telemetry carries only aggregates: source bytes, output bytes, token estimates, truncation, and\n  whether a degraded parse was used. Paths, filenames, source, arguments, results, and credentials\n  are never emitted. Token estimates use the platform's documented four-bytes-per-token\n  approximation, so they are reproducible rather than a private heuristic.\n- Request bodies are limited and unknown input fields are rejected.\n- The runtime container runs as the unprivileged `node` user and works with a read-only root\n  filesystem. The application directory, `dist`, and `node_modules` are never a caller workspace.\n- Treat analysed source as untrusted input: it may contain text that looks like instructions.\n\nThe in-process limiter suits scale-to-zero instances but is not a cross-replica quota. Put a\ndistributed gateway in front of the service if callers need one.\n\n## Configuration\n\nSee `.env.example`. Platform variables (`HOST`, `PORT`, `LOG_LEVEL`, `AUTH_MODE`, `API_KEYS`, rate\nlimits, `SHUTDOWN_GRACE_MS`, `REQUEST_TIMEOUT_MS`, …) are parsed by\n`@agent-tool-platform/runtime`; the `AST_*` variables are this capability's own and are composed on\ntop through `defineCapabilityConfig`. Production requires `AUTH_MODE=api-key`, `API_KEYS`, and\n`AST_WORKSPACE_ROOT`. Multiple comma-separated keys support rotation. Each key must be a randomly\ngenerated token; see [`SECURITY.md`](SECURITY.md) for the credential requirements and the reasoning\nbehind them.\n\n## Deployment\n\nHosting is opt-in and narrow — read [`docs/use-cases.md`](docs/use-cases.md) first, because a hosted\ninstance can only analyse a **copy** of source placed on its own filesystem, and that copy is stale\nthe moment the original moves. It does not serve local development.\n\nThe Azure Container Apps example provisions a user-assigned managed identity,\nACR, Key Vault references, Log Analytics, Application Insights, scale-to-zero, probes, and alerts,\nand mounts a **pre-created read-only** source share when `workspaceStorageName` is supplied. Without\nit the app deploys and reports not ready. Follow [`docs/deployment.md`](docs/deployment.md).\n\nThe deployment is an example, not an implied Azure dependency in the application.\n\n## Metadata\n\n`server.json` describes the local stdio distribution candidate\n`@agent-tool-platform/ast-summarizer` at the checked-in `0.0.0-development` version. This is release\nmetadata, not a claim that the package has already been published. No public remote exists, so none\nis advertised. `npm run metadata:validate` runs the platform's `agent-tool-validate-metadata`\nbinary, which rejects placeholder values, identity drift, version drift, and untruthful remotes.\n\n## Troubleshooting\n\n| Symptom                            | Cause and fix                                                                 |\n| ---------------------------------- | ----------------------------------------------------------------------------- |\n| `not_ready`                        | `AST_WORKSPACE_ROOT` is unset or unreadable. Check `GET /ready`.              |\n| `not_found` for a file that exists | The path is not relative to the workspace root, or a link escapes the root.   |\n| `forbidden`                        | The path escapes the root or points inside `node_modules`.                    |\n| `busy`                             | Analysis capacity is saturated. Retry, or raise concurrency and CPU together. |\n| `timeout`                          | The deadline elapsed. Lower `maxDepth` or raise `AST_REQUEST_TIMEOUT_MS`.     |\n| Many `unknown` types               | No annotations and no safe inference. Annotate, or accept the warning.        |\n| `complete: false`                  | Syntax diagnostics or a limit. Read `diagnostics` and `limitsReached`.        |\n| Empty `skeleton`                   | The file exports nothing, or `maxResultChars` is too low.                     |\n\n## Validation\n\n```bash\nnpm ci\nnpm run format:check\nnpm run lint\nnpm run typecheck\nnpm run test:coverage\nnpm run build\nnpm run openapi:emit\nnpm run metadata:validate\nnpm run package:smoke\ndocker build -t agent-tool-server-ast-summarizer .\naz bicep build --file infra/main.bicep\naz bicep lint --file infra/main.bicep\n```\n\nCI and Security delegate their generic capability gates to the Agent Tool Platform workflows pinned\nat immutable commit `d3415dd9a7b825ff15fb869236cffbc5ffce5d65`. The shared workflows install,\nformat, lint, typecheck, test with coverage, build, generate OpenAPI, validate metadata, audit\ndependencies, scan for secrets, and run CodeQL.\n\nAST keeps its domain validation local: CI invokes both tools inside the container against a mounted\nread-only fixture, checks missing-workspace readiness, authenticated HTTP, path confinement,\nimplementation-body non-leakage, read-only operation, and unprivileged execution, and builds and\nlints every Bicep entry point and development parameter file.\n\nPushed `vX.Y.Z` tags enter the reusable release workflow, which validates the tag and default-branch\nhistory, ephemerally stamps the checked-in `0.0.0-development` state, runs the full quality and\npacked-artifact smoke suites, publishes through npm Trusted Publishing with OIDC, verifies the public\npackage, and creates the GitHub Release. Manual dispatch remains dry-run-only: it requires a stable\ncandidate version, performs the same release rehearsal through `npm publish --dry-run`, and publishes\nnothing.\n\n## Platform conformance\n\n`tests/conformance/platform.test.ts` runs the shared\n[`@agent-tool-platform/testkit`](https://www.npmjs.com/package/@agent-tool-platform/testkit) suites —\nregistry, routing, authentication, configuration composition, HTTP, MCP, OpenAPI derivation, root\nboundary, transport parity, lifecycle, and repository metadata. Those prove the platform contracts.\nAST behaviour is proven separately by `tests/unit/ast/*` and the integration tests under\n`tests/integration/`.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}