PluginBench
MCP Server
Stale
MIT

RLM Tools MCP Server

io.github.stefanoshea/rlm-tools

Persistent Python sandbox for token-efficient codebase exploration—reduce context usage by 25-35% with server-side code analysis.

What is the RLM Tools MCP server?

RLM Tools is an MCP server that provides a persistent Python sandbox for exploring codebases without dumping raw data into your AI agent's context window. Instead of sending full grep results and file contents to the model, it keeps data server-side and returns only summaries, reducing token usage by 25-35% on typical tasks. It exposes three core tools (rlm_start, rlm_execute, rlm_end) plus built-in helpers for reading files, searching, and analyzing code.

RLM Tools solves a critical inefficiency in AI-assisted coding: agents waste 25-35% of their token budget just reading raw code output instead of reasoning about it. By running exploration (grep, file reads, glob patterns) in a server-side sandbox and returning only summaries, it lets your agent explore roughly 40-50% more code before hitting context limits. Perfect for large codebases where every token counts.

How to install RLM Tools

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "rlm-tools": {
      "command": "uvx",
      "args": [
        "rlm-tools"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • rlm_start — Open a session on a directory to begin exploration
  • rlm_execute — Run Python code in the sandbox with access to built-in helpers (read_file, grep, glob_files, tree, llm_query)
  • rlm_end — Close a session and free resources
  • read_file / read_files — Read files into variables with caching across calls
  • grep / grep_summary / grep_read — Search for patterns with optional summarization and file reading
  • glob_files — Find files by glob pattern
  • tree — Display directory structure with configurable depth
  • llm_query — Optional sub-LLM semantic analysis within the sandbox (requires Anthropic API key)

Use cases

  • Explore large codebases without filling your context window with raw grep/file-read output
  • Summarize import patterns, module dependencies, or code usage across hundreds of files
  • Incrementally build understanding of unfamiliar code by running multi-step analysis in the sandbox
  • Reduce token costs on coding tasks by 25-35% through server-side data aggregation
  • Analyze code structure and patterns using optional Claude-powered semantic queries within the sandbox

RLM Tools MCP server FAQ

What is RLM Tools?

RLM Tools is an MCP server that runs code exploration (grep, file reads, glob) in a persistent Python sandbox. Data stays server-side; only summaries enter your AI agent's context, reducing token usage by 25-35% on typical tasks.

Is it free?

Yes. Core features (read, grep, glob, tree) require no API key. The optional llm_query() helper requires an Anthropic API key for semantic analysis.

How do I install it in Claude Code or Cursor?

For Claude Code: run `claude mcp add rlm-tools -- uvx rlm-tools`. For Cursor/Windsurf, add to your MCP config: `{"rlm-tools": {"command": "uvx", "args": ["rlm-tools"]}}`. Install via PyPI: `pip install rlm-tools` or use `uvx rlm-tools`.

Does it require authentication?

No authentication required for core features. Only the optional llm_query() helper (for Claude-powered semantic analysis) requires an ANTHROPIC_API_KEY in your .env file.

Is the sandbox secure?

Yes. The sandbox is read-only, restricted to stdlib imports, blocks dangerous builtins (exec, eval, __import__), and scopes file access to the session directory with path-traversal protection.

How much context can I save?

Typical workflows save 25-35% context. Heavy exploration tasks (reading many files, broad searches) save 72-99%: a 500-line grep result becomes 5 lines of summary.

README (reference)

Source of truth, from the repository.

RLM Tools

Your AI coding agent spends most of its token budget just reading your code — not reasoning about it. Every grep, file read, and glob result gets dumped into the conversation. On a large codebase, that's 25-35% of your context (and cost) burned on raw data the model never needed to see.

RLM Tools gives your agent a persistent sandbox to explore code in. Data stays server-side. Only the conclusions come back.

# Install in one line (Claude Code)
claude mcp add rlm-tools -- uvx rlm-tools

# Or Codex
codex mcp add rlm-tools -- uvx rlm-tools

That's it. Your agent automatically uses the sandbox for exploration. No config, no prompting changes.

What Changes

Without RLM Tools — agent greps for import UIKit, gets 500 matches dumped into context. Reads 10 files, burns all their content as tokens. Context window fills up. Agent forgets what it was doing.

With RLM Tools — agent runs the same exploration in a server-side Python sandbox. Data stays in sandbox memory. Only the print() output enters context:

matches = grep("import UIKit")
by_module = {}
for m in matches:
    module = m["file"].split("/")[0]
    by_module.setdefault(module, []).append(m)
for module, ms in sorted(by_module.items(), key=lambda x: -len(x[1]))[:5]:
    print(f"{module}: {len(ms)} files")

500 lines of grep results become 5 lines of summary. The agent sees what it needs, nothing more.

Real-World Impact

In typical coding workflows: 25-35% context reduction. That means your agent can explore roughly 40-50% more code before hitting context limits.

In heavy exploration tasks (reading many files, broad searches), savings go much further:

ScenarioStandard ToolsRLM ToolsSaved
Grep across full app40,045 chars1,644 chars95.9%
Read 10 large files1,493,720 chars13,588 chars99.1%
Multi-step exploration136,102 chars5,285 chars96.1%
Grep then read matches340,408 chars6,022 chars98.2%
Find all usages of a pattern13,478 chars3,691 chars72.6%
Understand a module94,745 chars16,925 chars82.1%

Full benchmark methodology and reproduction steps: docs/benchmarks.md

How It Works

Three MCP tools. That's the entire API:

ToolPurpose
rlm_start(path, query)Open a session on a directory
rlm_execute(session_id, code)Run Python in the sandbox
rlm_end(session_id)Close session, free resources

The sandbox provides built-in helpers:

  • read_file(path) / read_files(paths) — Read files into variables (cached across calls)
  • grep(pattern) / grep_summary(pattern) / grep_read(pattern) — Search
  • glob_files(pattern) — Find files by pattern
  • tree(path, max_depth) — Directory structure
  • llm_query(prompt, context) — Sub-LLM analysis (optional, requires API key)

Variables persist across rlm_execute calls within a session. The agent can build up understanding incrementally — search, filter, read, analyze — without any intermediate data touching the context window.

Works With

RLM Tools is a standard MCP server. It works with any MCP-compatible client: Claude Code, Codex, Cursor, and others.

<details> <summary><strong>Other installation methods</strong></summary>

JSON MCP config (Cursor, Windsurf, etc.)

{
  "mcpServers": {
    "rlm-tools": {
      "command": "uvx",
      "args": ["rlm-tools"]
    }
  }
}

Direct run

uvx rlm-tools

From source

git clone https://github.com/stefanoshea/rlm-tools.git
cd rlm-tools
uv sync
uv run rlm-tools

Then point your MCP client to command: uv, args: ["--directory", "/path/to/rlm-tools", "run", "rlm-tools"].

</details>

Configuration

Copy .env.example to .env to customize. All settings are optional — RLM Tools works out of the box with zero config.

The core exploration features (read, grep, glob, tree) require no API key. The optional llm_query() helper calls the Anthropic API for semantic analysis within the sandbox — this is the only feature that requires a key.

VariableDefaultDescription
ANTHROPIC_API_KEY—Required for llm_query() only. Uses Anthropic's API (Claude).
RLM_SUB_MODELclaude-haiku-4-5-20251001Claude model used for llm_query()
RLM_MAX_SESSIONS5Max concurrent sessions
RLM_SESSION_TIMEOUT10Session timeout in minutes

Security

The sandbox is read-only and restricted:

  • Imports: Safe stdlib only (re, json, collections, math, etc.)
  • Builtins: Blocks exec, eval, compile, __import__, breakpoint
  • File access: Read-only, scoped to session directory, path traversal blocked
  • Execution: Configurable per-call timeout (default 30s)
  • Rate limits: Configurable max calls per session

Background

RLM Tools implements an RLM-style exploration loop: keep raw data in tool-side memory, send only compact outputs to the model. Built on the Model Context Protocol.

Development

git clone https://github.com/stefanoshea/rlm-tools.git
cd rlm-tools
uv sync --dev
pytest tests

Run comparative benchmarks (requires a local project checkout):

RLM_EVAL_PROJECT_PATH=/path/to/project pytest evals -q -s

License

MIT

Related MCP servers

Discover and explore Azure Verified Modules from the Bicep Public Registry

Check messages, npm packages and crypto addresses before acting. Read-only scanner tools.

0
JavaScript
AGPL-3.0
View repository →

Dutch-learning market map: schools, Verified Pro tutors, exams, paths and courses near any capital.

Local MCP server for requesting signatures from Agent-Q Firmware.

0
C++
View repository →

Local-first Sui DeFi evidence and review for AI clients before wallet signing.

0
TypeScript
MIT
View repository →

Phone camera bridge for Claude Code — photos, live video, voice, and generative UI

1
TypeScript
MIT
View repository →