Skip to content
Back to skills

Miru

ASecurity

Use Miru Code Search when the user asks where code lives, how behavior is wired, or what related code paths exist in a repo. Prefer this for conceptual code exploration over grep, glob, or broad file reads.

  • 11 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 25, 2026
ai-agents

Works with

  • mcp

Security analysis

A100/100

Scanned October 2, 2026

npx -y skills add takara-ai/miru-code --skill miru --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Miru?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Miru
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/takara-ai-miru/badge)](https://www.skillsdirectory.com/skills/takara-ai-miru)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: miru
description: Use Miru Code Search when the user asks where code lives, how behavior is wired, or what related code paths exist in a repo. Prefer this for conceptual code exploration over grep, glob, or broad file reads.
---

# Miru Code Search

Use Miru MCP as the default code-exploration path when it is available.

## When to use it

Exact token (identifier, quoted string, env var, error code) → `locate`. Otherwise → `search` —
e.g. "where is auth wired?", "what handles this behavior?", "find related code for this file/line".

## Workflow

1. Literal in the request? `locate(literal="<token>")` — prefer `mode="locations"`/`"count"`.
2. Otherwise `search(query="<question>")` once.
3. `truncated: true`? `expand` with `file_path`/`anchor_line` — only if the snippet doesn't already answer.
4. `find_related` for similar code elsewhere, not more context in the same file.
5. Read files directly only after Miru has already located the path.

`repo` is optional, set it for another repo. Reuse it on follow-up calls.

## If Miru tools report credential errors

Only call `auth` in direct response to a tool error saying credentials are missing, expired,
rejected, invalid, or unauthorized — never speculatively, since it starts a real sign-in prompt.
`auth` with no arguments starts a login and returns a URL and a short code — show both to the
user. Once they confirm, call `auth` again with `{"action": "check"}`. If still pending, wait
for the user to confirm again before re-checking — don't poll in a tight loop.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…