sys1grep asks whether a proposition holds
Version 0.5.0-next.2 turns each plain-language meaning into a yes-or-no question for every search unit. A unit may be a line, sentence, NUL-separated record, or function. The model returns a probability, sys1grep applies a threshold, and the terminal output looks familiar to anyone who uses grep. AND, OR, and NOT expressions can combine several meanings.
That design handles questions a regex cannot state cleanly. A search can distinguish a customer asking for a refund from a line about refund policy, or find an answer written in a different language from the query. The default positive threshold is 0.5. Add -p to inspect scores when a result sits close to the cutoff.
Zero dependencies still requires a System One endpoint
The package declares 0 dependencies and requires Node.js 20.16 or later. Global npm installation is one command, and npx can run the package without a permanent install. The current package name is @uehaj/sys1grep. It installs both sys1grep and git-sys1grep, so tracked files and revisions can be searched through a Git subcommand.
Useful searches still need a decision model. The default route uses TypeSafe's Jev service and a credential. A compatible local /v1/systemone server can avoid both the external call and the API key. For hosted use, the README recommends a settings file with mode 0600. Passing a credential as a command option exposes it to process listings and shell history.
What happened when we ran it
Our sandbox installed commit 6a19b88 in 7 seconds with 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges. npm added 0 packages, and installation occupied 3 MB. The checkout itself held 98 files, about 6,420 source lines, and used 1.8 MB. There was no build script or target, so our harness skipped that step. npm audit reported 0 known vulnerabilities across all severities.
The test step ran for 228 seconds and exited 1. Its tail repeated a warning that the settings file held a key readable by other users, printed two write EPIPE messages, and showed two searches where no line reached the 0.5 threshold. The named failure was spinner: the count of requests: cat@slow. The summary repeated that failure. The log does not establish whether timing, the environment, or product code caused it.
Every searched line leaves the machine by default
The README states that every searched line goes to the TypeSafe endpoint by default. Recursive mode skips common credential files, ignored paths, generated output, binary files, and several key formats. Those filters reduce accidental exposure, but an explicitly named file is searched even if it matches the skip list. A private repository should be treated as upload material unless the team points sys1grep at a local compatible server.
There are practical controls before the first paid request. Regex terms run locally and can narrow the lines sent to a meaning. --dry-run reports files, requests, token estimates, and projected cost without sending the search. An interactive guard asks before estimated input exceeds 1 USD by default. These controls help only when the estimate and filters match the real workload.
Borderline results can change between runs
The documentation says probabilities can drift by about 0.05 between runs. That is enough to move a borderline line across the default threshold. You can print every probability, adjust strictness, and word the meaning more precisely. English is documented as the most accurate query language, while Japanese works with more noise near the cutoff. This is exploratory search behavior, not a stable rule engine.
Open issue #193 adds a second caution. In the maintainer's recorded case, --dry-run with deduplication estimated about 16,000 tokens before the real operation used about 255,000. The same issue reports two runs over one input returning 574 and 578 matches. Those are the issue author's measurements, not ours, but they show why cost guards and exact result counts need verification on your own corpus.
The 0.5.0 rename is still pre-release
The repository now redirects from uehaj/jev-semgrep to uehaj/sys1grep, and package.json reports 0.5.0-next.2. The rename avoids a collision with the separate Semgrep static-analysis project. Old SEMGREP_* variables and the previous config path remain as temporary aliases for one minor release, while issue #96 says 1.0.0 will remove that fallback and declare the interface stable.
GitHub showed 148 stars and 25 open issues and pull requests on October 7, 2026. The API list split that total into 23 issues and 2 pull requests. The last push was October 6, one day before our review. The latest stable release was v0.4.0 from September 25, so current main includes active work that stable-package users do not yet receive.
Use it when grep cannot express the question
The 3 closest alternatives answer different searches. Ripgrep is the right default for exact text and regex on local files. ast-grep understands syntax trees, making it better for code-shape searches and rewrites. Semgrep targets repeatable static-analysis rules. sys1grep belongs beside them when the condition depends on who did what, negation, intent, or cross-language meaning.
Our run confirms that the package is tiny: 0 dependencies, 3 MB installed, and a 7-second setup. The 228-second failing test step prevents an unconditional recommendation, while remote text handling rules out sensitive corpora on the default route. Start with a nonsecret sample, use --dry-run, inspect -p scores around the threshold, and keep the command only if the hits are worth the repeated model calls.

