Model or dataset
r14dd/patent avatar
r14dd/patent

Nineteen sources, eight names, one ambiguous exit code

A prior-art search for your code ideas — has this dev tool already been shipped?

532 stars22 forksRustApache-2.0

At a glance

What is it?
patent is a Rust CLI that searches package registries, GitHub and Hacker News for prior art before you build a dev tool. Its ranking happens locally, its verdict comes from a model that can only be pushed toward more crowded, and its exit codes cannot tell a busy market apart from a mistyped flag.
Who is it for?
Use it as a scoping pass, not a clearance. Before wiring it into a gate, decide whether exit 1 means crowded or means broken in your pipeline, because the tool reports both as non-zero, and remember that it can only ever argue against novelty.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 4 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 3, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Nineteen sources, and only eight you can name

The summary claims a search across 19 sources and names eight of them: crates.io, npm, PyPI, Homebrew, Packagist and Hex from the package registries, plus GitHub and Hacker News. The remaining eleven sit behind the phrase "and more", which appears both in that summary and in the source-selection step, where the tool is said to pick the registries relevant to your idea. The count is therefore not a contract you can hold the tool to. It is whatever the picker chose for this run, and the verdict is scoped to exactly that set.

The documentation is unusually clear about the consequence. Every verdict is qualified as found in the sources checked, the list of sources checked is always displayed, and any selected source that failed is surfaced as not reached rather than quietly dropped. A failed source is reported, which is the difference between a short answer and a wrong one. The same passage draws the line on the other side too: a clean Open result means keep looking before you commit, not that the idea is free.

Exit code 1 means Crowded, or it means you mistyped a flag

The exit table is what makes the tool scriptable, and it is also where the design is loosest. Zero is Open, one is Crowded, two is Saturated, and usage errors plus unreachable backends also exit non-zero. A script that gates on 1 cannot distinguish a crowded market from a mistyped flag or from an Ollama daemon that is not running, yet the two demand opposite responses: one means stop building, the other means fix the command and rerun.

The numbering collides with convention too, since exit 1 is what most tooling treats as a generic failure, so any wrapper that maps non-zero to error will report a successful search as a broken run. Nothing in the table reserves a code for usage errors, and no code distinguishes a backend that was unreachable from a backend that answered. Two and three are free, and a CI job that needs to tell those cases apart has to build its own convention on top.

glibc 2.38 gates the binary and the source build alike

The install section puts a libc floor above both delivery routes. Prebuilt binaries and a from-source `cargo install` each require glibc 2.38 or newer, which is mapped to Ubuntu 22.10+, Debian 13+ and Fedora 38+. The stated reason is the bundled ONNX Runtime that powers local semantic search, so this is a runtime dependency of the embedded model code rather than a linker preference you can tune away.

On an older distribution such as Ubuntu 22.04 with glibc 2.35, the suggested route is to build inside a newer toolchain, with a debian:13 or ubuntu:24.04 container named as the place to do it, tracked as issue 37. Linux users also need to install openssl-devel and gcc-c++ on Fedora and RHEL, or libssl-dev and g++ on Ubuntu and Debian, before `cargo install` runs at all. Those build dependencies are listed separately from the libc floor, so a failure on an older box can come from either cause and the two are easy to confuse.

A missing update date and a fresh one look alike on screen

The maintenance signal is built so that missing information never turns into a positive claim. A match is flagged when the source published a date and nothing has touched it for two years or more. Those matches are flagged and never demoted, on the stated reasoning that an abandoned tool is still proof the idea has been built. A match with no date is a separate case: it means no source published one, not that the project is stale.

When two sources return the same URL, one surviving row borrows whichever date was found. None of this is visible in the options table, and the flag gets its own small section next to the TUI keys, where the note is explicit that it is only ever drawn where a date is actually known, so its absence makes no claim about freshness. The practical reading is that the flag is a pointer for where to look, not a quality score to sort by. A row without the flag is not evidence that a project is alive.

The verdict ratchets one way and never under-rates a space

The three levels come from an LLM summary, and the constraint on that summary matters more than its prompt. The verdict is floored against the similarity data so it can never under-rate a populated space: a model may call a thin space crowded, but it cannot call a busy space open. That one-way ratchet explains why an Open result carries its own warning to keep looking.

`--fast` removes the model from the path entirely and derives the verdict from similarity scores alone, with no warmup and no wait. The thresholds that map a score onto Open, Crowded or Saturated are not published, so the cheap mode and the model mode are not guaranteed to agree. By default the model is qwen3.5 served by a local Ollama, and `--api-base` swaps in any OpenAI-compatible endpoint, which must end in /v1. That flag is also the privacy switch: with it, your query text is sent to the remote server to produce the verdict.

Four places a setting can live, resolved in one fixed order

Configuration resolves through a stated chain: CLI flag first, then environment variable, then config file, then built-in default. The config file is a config.toml in the platform config directory, and the path differs per system: `~/.config/patent/config.toml` on Linux, `~/Library/Application Support/patent/config.toml` on macOS, `%APPDATA%\patent\config.toml` on Windows.

The environment layer is narrower than the flag layer. PATENT_MODEL, PATENT_API_BASE and PATENT_API_KEY cover the three model flags, and OPENAI_API_KEY is accepted as a fallback for the key, while `--limit`, `--fast` and `--json` have no documented environment or config counterpart at all. GITHUB_TOKEN is environment-only, and it is the one setting with a stated numeric effect: it raises the GitHub search rate limit from 10 to 30 requests per minute. Limits on the six package registries are not stated anywhere, even though they are queried in the same pass.

One binary, three shapes of stdout, one undocumented sort key

Running the binary with no arguments opens an interactive TUI, while the same binary with a query prints and exits, and `--json` swaps the interface for JSON on stdout so a result can be piped into jq. A third stdout mode exists: `--completions bash` prints a completion script and exits, which makes shell setup a manual redirect into an rc file rather than an installer.

bash
patent --completions bash >> ~/.bashrc    # Bash
patent --completions zsh  >> ~/.zshrc     # Zsh
patent --completions fish > ~/.config/fish/completions/patent.fish

Only bash, zsh and fish are named. Inside the TUI, `s` cycles the sort order through similarity, popularity and name, and popularity is the odd one out: it appears in no options table and in no description of the ranking, while the ranking itself is described only as local embeddings compared by cosine similarity. Filtering with `/`, expanding with `m`, opening and copying URLs with `o` and `y`, a new search on `n` and a help overlay on `?` complete the surface. The sort key with no metric behind it is the piece to check first.

The published crate is curated by hand through an exclude list

Cargo.toml declares version 0.14.0, edition 2021 and rust-version 1.88, and the manifest version matches the newest release tag, v0.14.0, published on 2026-09-08 after v0.13.1 and v0.13.0 the week before, so at least those numbers agree. The licence line reads MIT OR Apache-2.0 and the tree carries both LICENSE-MIT and LICENSE-APACHE, while the crate listing shows Apache-2.0 on its own.

The exclude list is where the project admits to mess. Demo assets are dropped because the README serves them from raw GitHub URLs rather than shipping them in the tarball, the Nix dev-environment files are dropped as irrelevant to crate consumers, and `src/pipeline.rs` is excluded with a comment explaining that it is local work in progress, untracked but not gitignored, which `cargo package` would otherwise sweep into every publish. The comment adds that the exclusion is enforced on each publish, and that the build fails loudly on the missing file if it ever becomes a real module. The list also names `showcase.gif` and `showcase.png`, neither of which sits among the top-level entries, while `showcase.tape` does.

Editorial conclusion

Use it as a scoping pass, not a clearance. Before wiring it into a gate, decide whether exit 1 means crowded or means broken in your pipeline, because the tool reports both as non-zero, and remember that it can only ever argue against novelty. Check the list of sources it reached in each run, since the registry set is chosen per query and eleven of the nineteen sources are never named, and keep the local Ollama path or `--fast` if the query text should stay on your machine.

Frequently asked questions

What sources does the patent crate search?

One query fans out across 19 sources: crates.io, npm, PyPI, Homebrew, Packagist and Hex from the package registries, plus GitHub and Hacker News, with the tool choosing which registries are relevant to the idea. Any selected source that failed is surfaced as not reached.

Can patent prove that my dev tool idea is still new?

No. It can prove something exists but never that something does not, because it searched only some sources. Every verdict is scoped to the sources checked, that list is always shown, and a clean Open result means keep looking before you commit.

Why does installing patent fail on an older Linux distribution?

Both the prebuilt binaries and a from-source build need glibc 2.38 or newer, because the bundled ONNX Runtime behind local semantic search depends on it. On Ubuntu 22.04 with glibc 2.35, the documented workaround is a debian:13 or ubuntu:24.04 container.

What do the patent exit codes mean when used in CI?

Zero is Open, one is Crowded and two is Saturated, all derived from the verdict. Usage errors and unreachable backends also exit non-zero, so code one does not separate a crowded space from a bad command line.

Official sources

  1. License: Apache-2.0
  2. Project website
  3. r14dd/patent on GitHub
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/r14dd-patent.svg)](https://hysenlabs.com/projects/r14dd-patent)