mrkeyoor.com_
Wed 07 Oct 07:31 UTC
Dev Toolsevaluationupdated 07 Oct 2026

sys1grep review

The project formerly called jev-semgrep is now sys1grep, a command-line search tool that finds text by meaning instead of exact words. It asks a System One decision model whether each line, sentence, record, or function satisfies a plain-language condition, then prints results in a grep-like format.

Verdict

Our sys1grep run installed 0 packages in 7 seconds, then the 228-second test step exited 1 on spinner: the count of requests: cat@slow. Use it for proposition-shaped searches over text you are allowed to send to the configured endpoint, especially when language differs between the query and the files. Keep ripgrep for exact local search, and wait for a stable post-rename release if scripts depend on the interface.

We ran it

Lab card: what happened when we ran sys1grepScreenshot of sys1grep (uehaj.github.io/sys1grep)
Install✓ · 7s0 packages · 3 MB
Buildn/ano build script
Tests✗ · 228sran, no count parsed
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo98 files~6,420 lines of source · 1.8 MB · 2 CI workflows · tests dir

Answers from our run

Does sys1grep build from source?

Dependencies installed in 7 seconds (0 packages), and the project has no separate build step. We cloned commit 6a19b88 into a clean Debian container with 3 CPUs and no project-specific setup.

Do sys1grep's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does sys1grep have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use sys1grep?

Teams handling text they cannot send to an outside service: the default endpoint receives every searched line.

What are the alternatives to sys1grep?

ripgrep, ast-grep, Semgrep. Our sys1grep run installed 0 packages in 7 seconds, then the 228-second test step exited 1 on spinner: the count of requests: cat@slow.

Setup4/57-second install with 0 packages, followed by API setup
Docs4/5Detailed on privacy, thresholds, costs, grammar, and migration
Community3/5148 stars and an October 6 push, with 23 open issues
Maturity2/50.5.0 is pre-release and our full test step failed

Who it’s for

Developers searching mixed-language logs, tickets, Git history, or source by intent.
Investigators whose question is a proposition, such as whether a line answers a question or records a failed retry.
Teams willing to inspect probabilities and tune a threshold around borderline matches.
Claude Code users who want a skill that narrows large text inputs before the main model reads them.

Who it’s NOT for

Teams handling text they cannot send to an outside service: the default endpoint receives every searched line.
Audits that require identical results on every run: the README says probabilities drift by about 0.05, and issue #193 records changed matches on the same input.
Repeated searches over a large, fixed corpus: sys1grep builds no index, so each new query sends and pays for the corpus again.
Scripts that need a frozen command and environment interface today: main is 0.5.0-next.2, the project was renamed, and old SEMGREP names are due to disappear in 1.0.0.
Release gates that require a passing full suite: our 228-second test step exited 1 on the spinner request-count check.

Setup reality

Our fresh Debian sandbox installed commit 6a19b88 in 7 seconds. npm added 0 packages and the installed project used 3 MB. There was no build script or target, so that step was skipped. The tests ran for 228 seconds and exited 1. npm audit reported 0 known vulnerabilities.

The CLI requires Node.js 20.16 or later plus a TypeSafe API key, or a compatible /v1/systemone endpoint. A local compatible server can run without a key. The README recommends keeping credentials in ~/.config/sys1grep/settings.json with mode 0600.

Every searched line goes to the configured endpoint unless a local regex or file filter removes it first. The 1.8 MB checkout had 98 files, about 6,420 source lines, 2 CI workflows, a tests directory, and no Dockerfile. Main also carries the 0.5.0 rename while the latest stable release is v0.4.0.

sys1grep asks whether a proposition holds

Version 0.5.0-next.2 turns each plain-language meaning into a yes-or-no question for every search unit. A unit may be a line, sentence, NUL-separated record, or function. The model returns a probability, sys1grep applies a threshold, and the terminal output looks familiar to anyone who uses grep. AND, OR, and NOT expressions can combine several meanings.

That design handles questions a regex cannot state cleanly. A search can distinguish a customer asking for a refund from a line about refund policy, or find an answer written in a different language from the query. The default positive threshold is 0.5. Add -p to inspect scores when a result sits close to the cutoff.

Zero dependencies still requires a System One endpoint

The package declares 0 dependencies and requires Node.js 20.16 or later. Global npm installation is one command, and npx can run the package without a permanent install. The current package name is @uehaj/sys1grep. It installs both sys1grep and git-sys1grep, so tracked files and revisions can be searched through a Git subcommand.

Useful searches still need a decision model. The default route uses TypeSafe's Jev service and a credential. A compatible local /v1/systemone server can avoid both the external call and the API key. For hosted use, the README recommends a settings file with mode 0600. Passing a credential as a command option exposes it to process listings and shell history.

What happened when we ran it

Our sandbox installed commit 6a19b88 in 7 seconds with 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges. npm added 0 packages, and installation occupied 3 MB. The checkout itself held 98 files, about 6,420 source lines, and used 1.8 MB. There was no build script or target, so our harness skipped that step. npm audit reported 0 known vulnerabilities across all severities.

The test step ran for 228 seconds and exited 1. Its tail repeated a warning that the settings file held a key readable by other users, printed two write EPIPE messages, and showed two searches where no line reached the 0.5 threshold. The named failure was spinner: the count of requests: cat@slow. The summary repeated that failure. The log does not establish whether timing, the environment, or product code caused it.

Every searched line leaves the machine by default

The README states that every searched line goes to the TypeSafe endpoint by default. Recursive mode skips common credential files, ignored paths, generated output, binary files, and several key formats. Those filters reduce accidental exposure, but an explicitly named file is searched even if it matches the skip list. A private repository should be treated as upload material unless the team points sys1grep at a local compatible server.

There are practical controls before the first paid request. Regex terms run locally and can narrow the lines sent to a meaning. --dry-run reports files, requests, token estimates, and projected cost without sending the search. An interactive guard asks before estimated input exceeds 1 USD by default. These controls help only when the estimate and filters match the real workload.

Borderline results can change between runs

The documentation says probabilities can drift by about 0.05 between runs. That is enough to move a borderline line across the default threshold. You can print every probability, adjust strictness, and word the meaning more precisely. English is documented as the most accurate query language, while Japanese works with more noise near the cutoff. This is exploratory search behavior, not a stable rule engine.

Open issue #193 adds a second caution. In the maintainer's recorded case, --dry-run with deduplication estimated about 16,000 tokens before the real operation used about 255,000. The same issue reports two runs over one input returning 574 and 578 matches. Those are the issue author's measurements, not ours, but they show why cost guards and exact result counts need verification on your own corpus.

The 0.5.0 rename is still pre-release

The repository now redirects from uehaj/jev-semgrep to uehaj/sys1grep, and package.json reports 0.5.0-next.2. The rename avoids a collision with the separate Semgrep static-analysis project. Old SEMGREP_* variables and the previous config path remain as temporary aliases for one minor release, while issue #96 says 1.0.0 will remove that fallback and declare the interface stable.

GitHub showed 148 stars and 25 open issues and pull requests on October 7, 2026. The API list split that total into 23 issues and 2 pull requests. The last push was October 6, one day before our review. The latest stable release was v0.4.0 from September 25, so current main includes active work that stable-package users do not yet receive.

Use it when grep cannot express the question

The 3 closest alternatives answer different searches. Ripgrep is the right default for exact text and regex on local files. ast-grep understands syntax trees, making it better for code-shape searches and rewrites. Semgrep targets repeatable static-analysis rules. sys1grep belongs beside them when the condition depends on who did what, negation, intent, or cross-language meaning.

Our run confirms that the package is tiny: 0 dependencies, 3 MB installed, and a 7-second setup. The 228-second failing test step prevents an unconditional recommendation, while remote text handling rules out sensitive corpora on the default route. Start with a nonsecret sample, use --dry-run, inspect -p scores around the threshold, and keep the command only if the hits are worth the repeated model calls.

Alternatives

ProjectWhat it isPick it when
ripgrep gh↗A fast local regex searcher that respects ignore files and never needs a model endpoint.pick this instead when exact text or regex can express the search and the files must stay local.
ast-grep gh↗A structural code search, lint, and rewrite tool based on syntax trees.pick this instead when code shape matters more than the meaning inferred from prose.
SemgrepA multi-language static analysis engine for finding code patterns and bug variants.pick this instead when you need repeatable static-analysis rules rather than probability-scored text search.

What people are saying

  1. [velocity-scout] uehaj/jev-semgrep

Sources

  1. sys1grep README
  2. sys1grep v0.4.0 release
  3. Issue #193 on dedup estimates and result drift
  4. Issue #96 on the 0.5.0 rename and 1.0.0 interface
  5. sys1grep package metadata

More dev tools reviews

skills · niimbot · ZygiskNext · AirCard-iOS · expo-dynamic-notifications · wx-cli-again · the whole board →