2026-10-11 16:38 UTC

heuristicolab claims its released ctxfw MCP server's in-memory Tree-Sitter AST pruning replaces peripheral dependency implementations with interface stubs (reported 59.5-72.4% token reduction on its own codebase, zero telemetry egress) without degrading edit quality β€” adoption or independent measurement in Cursor/Claude workflows would establish AST-level dependency pruning as a practical token-control layer for coding agents.

state: seedheat: lowuncertainty: highconvergesscott: mediumagent-harnesses context-management token-efficiency mcpheuristicolab

What is this?

heuristicolab (an org with no other identifiable presence in the supplied material) has released ctxfw, an open-source MCP server positioned as an 'AST context firewall' for coding agents: it parses the workspace in-memory with Tree-Sitter and rewrites peripheral (distance-1/2+) dependency implementations into typed interface stubs, claiming 59.5–72.4% token reduction measured on its own codebase (49,096 tokens down to ~2x,xxx per the README snippet) with zero telemetry egress. It launched on Show HN roughly a day before this case was opened and has minimal traction (6 points). The snippets confirm the artifact and the self-reported numbers but provide no independent measurement, no edit-quality validation, and no info on who is behind it; meanwhile the surrounding space is crowded with adjacent Tree-Sitter+MCP token-reduction tools (CodeTree, tree-sitter-analyzer, aidex's SQLite code index, a Codebase-Memory arXiv system), though ctxfw's specific stub-pruning mechanism differs from those index/lookup approaches.

Why it matters to Scott

ctxfw independently lands where Scott already argues and builds β€” deterministic AST reduction of code so agents consume typed interface stubs instead of full implementations β€” and its dependency-distance stubbing is a direct design-space rival to his own deterministic-code-skeleton and adaptive-source-context-compilation (same Tree-sitter substrate, different selection policy: distance-1/2 retention vs ranked signatures), so independent measurement or adoption would bear on how he compiles code context in his own harnesses. It stays medium rather than high because the 59.5–72.4% figure is seller-class by his own evidence ladder β€” self-benchmarked on ctxfw's codebase, no edit-quality validation, 6-point Show HN launch from an unknown org β€” and it joins a crowded sibling set of radar AST/token-pruning watch cases, making it a mechanism to track, not a dated receipt.
dev:concept.deterministic-code-skeletondev:concept.adaptive-source-context-compilationdev:technology.tree-sitterip:concept.working-set-principleip:concept.read-ladderradar:concept.context-managementradar:concept.token-efficiencyradar:concept.mcpradar:concept.agent-harnessesradar:driftwatch-ast-token-pruningradar:benzi-deterministic-source-harnessradar:novgraph-persistent-codebase-memory
queries asked of Scott's wikis
  • context window token budget management in my agent harnesses
  • MCP servers I have built or evaluated for coding agents
  • tree-sitter parsing or code indexing in my dev projects
  • repo-map vs compaction vs shunting context strategies
  • agents reading interfaces/signatures instead of full implementations
  • self-reported benchmark claims and how I vet them

Measured heat

now 0 pts/hpeak 2 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 386h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

09-25 16:41 (minted)⭐ origin echo-reconstructedREADME claims '72.4% Bloat Eliminated' by compacting distance-1/2+ dependencies to typed stubs via in-memory Tree-Sitter, reporting 49,096β†’2
heuristicolab on github (echo) Β· attributed from hn.story.49845110 Β· published time unknown
β€”
09-25 14:23first on hacker news Β· published Β· lag ?Show HN: Ctxfw – In-memory AST pruner and token firewall for Cursor and Claude
mikemo88
β€”
09-25 14:23amplified on hacker newshn.story.49845110
mikemo88
peak 3 Β· 0 comments Β· 38% of case engagement
09-29 14:23amplified on hacker news πŸ‘‘hn.story.49893845
mikemo88
peak 5 Β· 0 comments Β· 62% of case engagement
09-25 15:21our radar first saw it Β· lag ?discovery anchor: hn.story.49845110β€”
pace: p36 vs 1032 stories at the 336h mark (now 386h old) β€” ahead of agentgate-signed-agent-receipts (1.3x), behind agent-memory-add-search-evaluation (0.8x)

Evidence (3) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Ctxfw – In-memory AST pruner and token firewall for Cursor and Claude
Retrieved article excerpt

Open article Β· Retrieved 2026-09-25T16:30:17.212958+00:00

# CTXFW // CONTEXT FIREWALL

### High-Assurance Axiomatic Gatekeeper & In-Memory AST Pruning for Coding Agents

[PyPI - Version](https://pypi.org/project/ctxfw/)
[Axiomatic Completeness Index](https://ctxfw.heuristicolab.com)
[Tests](https://pypi.org/project/ctxfw/)
[License](https://github.com/heuristicolab/ctxfw/blob/main/LICENSE)
[Glama](https://glama.ai/mcp/servers/heuristicolab/ctxfw)

**The deterministic boundary between probabilistic LLM hallucination and production infrastructure.**

[Installation](https://github.com/heuristicolab/ctxfw#installation) β€’ [Benchmarks](https://github.com/heuristicolab/ctxfw#ast-pruning-benchmarks) β€’ [Diagnostic](https://github.com/heuristicolab/ctxfw#system-diagnostics) β€’ [Architecture](https://github.com/heuristicolab/ctxfw#architecture) β€’ [Enterprise Governance](https://github.com/heuristicolab/ctxfw#enterprise-governance)

---

## Executive Abstract

Autonomous coding agents (Claude, Gemini, Cursor, Antigravity) consume massive context windows with bloated peripheral dependencies, triggering token exhaustion, context drift, and security degradation.

**CTXFW** is an open-core context firewall and Model Context Protocol (MCP) gatekeeper. It combines an **in-memory polyglot AST pruner** with a **deterministic axiomatic intake sieve**:

1. **Compacts Peripheral Code (72.4% token reduction)**: Replaces distance-1 and distance-2+ module implementations with clean interface signatures, type definitions, and functional stubs.
2. **Enforces Axiomatic Integrity (ACI $\ge$ 0.9000)**: Rejects ungrounded or deficient architecture briefs missing negative invariants ($N \ge 5$), bounded variable domains, deterministic state machines, or formal error taxonomies.
3. **Zero Telemetry Egress**: Guaranteed local execution with zero network telemetry leakage on standard operating mode.

---

## AST Pruning Benchmarks

CTXFW operates directly at the syntax tree layer using native polyglot grammars:

| Benchmark Dimension | Raw Context Ingestion | CTXFW Topological Compactor | Performance Gain / Impact |
| --- | --- | --- | --- |
| **Token Consumption** | 100% (Raw Files) | 27.6% (Interface Stubs) | **72.4% Bloat Eliminated** |
| **Engine Compaction Overhead** | β€” | Native in-memory parser | **< 5.0 ms** |
| **Warm Cache Hit Overhead** | β€” | SQLite WAL semantic cache | **< 0.8 ms** |
| **Stdio Telemetry Egress** | Unsanitized stdout | Pure isolated JSON-RPC | **Zero Egress (100% Isolated)** |
| **Axiom Verification Latency** | β€” | Sieve evaluation | **< 12.0 ms** |
| **CI/CD Pre-Commit Latency** | β€” | Headless git sentry | **< 85.0 ms** |

### Empirical Case Study: `ctxfw/cli.py` Core Dependency Graph

Empirical context reduction metrics generated via `ctxfw.resolve_context_bundle` running against 16 internal dependencies:

| Dimension | Raw Context Ingestion | CTXFW Topological Sieve | Performance Delta |
| --- | --- | --- | --- |
| **Total Context Size** | 49,096 tokens | 20,014 tokens | **-59.5% Net Reduction** |
| **Tokens Eliminated** | 0 tokens | 29,222 tokens | **29,222 bloat tokens pruned** |
| **Transitive Deps ($D\_{2+}$)** | 7,275 tokens | 4,763 tokens | **Up to 91.9% reduction** |
| **FinOps Cost Impact** | Base Cost | Reduced by $0.0877 USD / prompt | **~$87.70 USD saved per 1K calls** |
| **AST Compaction Latency** | β€” | 1,407.96 ms | In-memory Tree-Sitter parsing |
| **Attestation Integrity** | None | SHA-256 sealed | Strict interface preservation |

**Topological Hierarchy Breakdown:**

- **$D\_0$ Target (`ctxfw/cli.py`)**: 100% Full Implementation preserved.
- **$D\_1$ Direct Deps (e.g. `gatekeeper.py`, `mcp.py`)**: Implementation truncated to typed stubs (`...`). Token savings: **73% – 86%**.
- **$D\_{2+}$ Transitive Deps (e.g. `polyglot.py`)**: Nominal symbols only. Token savings: **91.9%**.

---

## Installation

### 1. PyPI (Official Package)

Install via `pip` or isolated environment manager:

```
pip install ctxfw
```

Or for global CLI availability using `pipx`:

```
pipx install ctxfw
```

### 2. Native MCP Stdio Configuration

Register the stdio server directly in your IDE or client configuration (`claude_desktop_config.json`, Cursor, Windsurf, or Antigravity):

```
{
  "mcpServers": {
    "ctxfw": {
      "command": "ctxfw",
      "args": ["mcp"]
    }
  }
}
```

### 3. Verified MCP Registry (Glama)

CTXFW is indexed and verified with Grade A compliance on the official Glama MCP registry:

[Glama](https://glama.ai/mcp/servers/heuristicolab/ctxfw)

Direct access to tool inspection, schemas, and live diagnostic telemetry on [Glama](https://glama.ai/mcp/servers/heuristicolab/ctxfw).

---

## System Diagnostics

Validate local environment readiness, stdio isolation purity, SQLite WAL concurrency, and Tree-Sitter grammars with a single command:

```
ctxfw doctor
```

```
========================================================================
  CTXFW DOCTOR // HIGH-ASSURANCE HEALTH & ISOLATION DIAGNOSTIC
========================================================================
[PASS]   Python Package & sys.path        ctxfw v3.5.0 loaded cleanly.
[PASS]   MCP stdio Stream Isolation       100% pure JSON-RPC on stdout. Diagnostic logs isolated to stderr.
[PASS]   Global CLI Executable (PATH)     Binary 'ctxfw' found in PATH.
[PASS]   Axiomatic Sieve Engine           Evaluation verified (ACI: 1.0000, Invariants: 5).
[PASS]   SQLite WAL Cache & Concurrency   Journal mode: WAL, Busy timeout: 5000ms.
[PASS]   Polyglot Tree-Sitter Grammars    Initialized language parsers (typescript, go, java).
------------------------------------------------------------------------
Overall Verdict:            [HEALTHY] [ATTESTED] Perimeter defense operational.
========================================================================
CTXFW // 72.4% AST Bloat Eliminated. Zero Telemetry Egress.
Need team-wide budget circuit breakers or multi-node proxy governance?
Control Plane & Enterprise Licensing: https://ctxfw.heuristicolab.com
========================================================================
```

---

## Architecture

CTXFW enforces a strict deterministic perimeter dividing probabilistic agent code from the core codebase:

```
PROBABILISTIC DOMAIN                      DETERMINISTIC PERIMETER
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”                  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  Autonomous AI Agent  β”‚                  β”‚             CTXFW ENGINE               β”‚
β”‚  (Claude / Gemini /   β”‚                  β”‚                                        β”‚
β”‚   Cursor / Antigravityβ”‚                  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                  β”‚  β”‚   Polyglot AST Topological Engineβ”‚  β”‚
            β”‚                              β”‚  β”‚  - Python (ast)                  β”‚  β”‚
            β”‚  Target Context / Brief      β”‚  β”‚  - TypeScript / Go / Java (CST)  β”‚  β”‚
            β–Ό                              β”‚  β”‚  - Multi-Depth Interface Stubs   β”‚  β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”                  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β”‚ MCP Stdio Interceptor β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Ίβ”‚                   β”‚                    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
                                           β”‚  β”‚  SQLite WAL High-Concurrency     β”‚  β”‚
                                           β”‚  β”‚  Semantic Cache (<5ms warm hit)  β”‚  β”‚
                                           β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
                                           β”‚                   β–Ό                    β”‚
                                           β”‚         [ ACI >= 0.9000? ]             β”‚
                                           β”‚          /              \              β”‚
                                           β”‚       YES                NO            β”‚
                                           β”‚        β”‚                  β”‚            β”‚
                                           β”‚        β–Ό                  β–Ό            β”‚
                                           β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
                                           β”‚ β”‚ VERIFIED     β”‚   β”‚ QUARANTINED     β”‚ β”‚
                                           β”‚ β”‚ SHA-256 Seal β”‚   β”‚ Execution Halt  β”‚ β”‚
                                           β”‚ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
                                           β””β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                                    β”‚                    β”‚
                                                    β–Ό                    β–Ό
                                           [ Code Generation ]   [ Forensic Report ]
                                           [ & Git Permitted ]   [ Pre-Commit Abort]
```

### Key Subsystems:

1. **Polyglot Tree-Sitter Pruner**:
   - Compiles topological dependency trees. Distance 0 (target file) is preserved in full; Distance 1 dependencies retain signatures and docstrings while pruning implementation logic; Distance 2+ dependencies are reduced to compact type stubs.
   - Built-in support for **Python**, **TypeScript/JavaScript**, **Go**, and **Java**.
2. **SQLite WAL High-Concurrency Semantic Cache**:
   - Atomic multi-process caching configured with Write-Ahead Logging (`PRAGMA journal_mode=WAL`) and `busy_timeout=5000ms`, delivering sub-millisecond warm cache hits.
3. **Axiomatic Sieve Engine**:
   - Formal specification gatekeeper evaluating requirements against 5 negative invariants (`shall never`), explicit mathematical bounds, deterministic state machines, and a 4-class error taxonomy.

---

## Zero-Touch Provisioning

Inject perimeter rules, MCP server declarations, and pre-commit sentinels into your workspace:

### Global IDE Integration

```
ctxfw init --global
```

Automatically configures Google Antigravity, Cursor, and Claude Desktop.

### Repository Pre-Commit Sentry

```
ctxfw init --repo .
```

Deploys `.git/hooks/pre-commit` to prevent uncertified code commits lacking an attested specification brief.

---

## Enterprise Governance

For distributed engineering teams requiring centralized policy controls:

- **Team-wide LLM budget circuit breakers**: Hard token and dollar thresholds with automatic killswitches.
- **Multi-node reverse proxy governance**: Centralized firewall gateways supporting OpenAI and Anthropic streaming SSE endpoints.
- **FinOps Telemetry Ledger**: Aggregate tokens saved, cost elusion analytics, and tamper-evident audit trails.

**Control Plane & Enterprise Licensing:** <https://ctxfw.heuristicolab.com>

---

ENGINEERED BY HEURISTICO LAB // SKUNK WORKS DIVISION  
HIGH-ASSURANCE DEFENSE SYSTEMS GROUP
mikemo8830
🟧 echo.github ⭐README claims '72.4% Bloat Eliminated' by compacting distance-1/2+ dependencies to typed stubs via in-memory Tree-Sitter, reporting 49,096β†’2heuristicolabβ€”β€”
🟧 hnShow HN: Ctxfw – AST context firewall that cuts agent prompt tokens by 67%mikemo8850

Interpretation history

Decision trace