Grandpa MCP Server
Supports GitHub Copilot as an AI coding agent, offering skills and guardrails that reduce token usage, prevent unnecessary dependencies, and enforce defensive coding patterns.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Grandpa MCP Serverscan this repo for dependency bloat and give me a health score"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Why Grandpa?
Your AI coding agent is powerful. But it wastes too much.
Every time you give a prompt to Claude Code, Cursor, Windsurf, Devin, or GitHub Copilot, you are paying in tokens and latency for four invisible forms of waste:
Reading too much: Dumps entire repositories into prompt context when a single file mattered.
Speaking too much: Spits out 5-paragraph architectural essays for a 2-line CSS fix.
Building too much: Pulls in bloated third-party npm packages (
axios,lodash,uuid) when modern native runtime primitives exist.Retrying too much: "Lazy" one-line code-golf rules strip timeouts, drop
res.ok, and skip null safety—causing runtime 500 crashes and expensive multi-turn debugging cycles.
Grandpa is not code golf. Correctness is a hard requirement.
Grandpa minimizes TCS (Tokens to Correct Solution) across the whole development loop by giving your coding agent four simple instincts:
SPEAK LESS → Precise, zero-chatter code generation
READ LESS → Relevance-bounded context retrieval (<3 files)
BUILD LESS → Native standard library primitives first (Zero npm bloat)
RETRY LESS → Hardened production safeguards (res.ok, timeouts, null checks)NORMAL AGENT
reads 18 files
loads 21K context tokens
adds external npm dependency
writes bloated patch
runs entire test suite
fails on stalled network
feeds huge 4,000-line error log back
repairs over multiple turns
TOTAL: 6,840 tokens | 2 attempts | 9.8 sec
GRANDPA (Quick / Standard / Deep)
identifies relevant target file (<3 files)
reuses native runtime stdlib
generates defensive patch (status checks, timeouts preserved)
runs targeted isolated verification
PASSES on first turn & STOPS immediately
TOTAL: 270 tokens | 1 attempt | 74 msKey Pillars & What Ponytail Doesn't Have
Feature | Ponytail | Grandpa Standard | Why It Matters |
Supported Agents | 20 agents | 25+ agents | Cursor, Windsurf, Claude Code, Copilot, Cline, Codex, Devin, Grok, Kiro, OpenClaw, OpenCode, Qoder, Antigravity, Roo Code, Aider, Zed, Continue, Pi |
Architectural Skills | 6 skills | 8 skills | Core, Audit, Review, Debt, Guard, Migrate, Gain, Help |
Active CLI Scanner | ❌ None |
| Scans real repos, grades codebases (A+ to F), catches fragile fetch patterns |
Git Pre-Commit Guard | ❌ None |
| Mechanically blocks AI models from committing unapproved dependencies |
MCP Server | Basic | Full Model Context Protocol | Native JSON-RPC server with tools: |
Real-Time Guard Hook | ❌ None | Active PreTool Hook | Intercepts |
Benchmark Suite | LOC-only (golfing) | Multi-dimensional | Measures bloat, LOC, adversarial robustness, and defensive safety (92% vs 73%) |
Before/After Demos | 11 examples | 16 examples | Real-world diffs across frontend, backend, CLI, Python, React |
Live CLI Demonstration
Run Grandpa directly in any project directory:
npx github:bytewhisker/grandpa scan┌ ┐
Welcome to Grandpa
▄███▄ ████▄ ▄███▄ ██ ██ ████▄ ████▄ ▄███▄ ▄▄██████▄▄
██ ▀ ██ ██ ██ ██ ███ ██ ██ ██ ██ ██ ██ ██ ▄██▀██████▀██▄
██ ▄▄▄ ████▀ ███████ ██ █ ██ ██ ██ ████▀ ███████ ██ ██▀█▄▄█▀██ ██
██ ██ ██ ██ ██ ██ ██ ███ ██ ██ ██ ██ ██ ██ ██▄█▀▀█▄██ ██
▀███▀ ██ ██ ██ ██ ██ ██ ████▀ ██ ██ ██ ▀██▄██████▄██▀
▀████████▀
└ CLI Version 1.0.0 ┘
Version 1.0.0 · Engineered by Mahadi (@bytewhisker)
Target Directory: /workspace/my-app
--- DEPENDENCY AUDIT ---
Found 3 package(s) that can be replaced with native built-ins:
• uuid (v9.0.1)
Grandpa's Native Fix: crypto.randomUUID()
Native standard library in Node.js and all modern browsers. (Supported in Node 14.17+)
• lodash.clonedeep (v4.5.0)
Grandpa's Native Fix: structuredClone(obj)
Native deep cloning built into modern JavaScript runtimes. (Supported in Node 17.0+)
• rimraf (v5.0.5)
Grandpa's Native Fix: fs.rmSync(path, { recursive: true, force: true })
Native recursive directory deletion in Node.js fs. (Supported in Node 14.14+)
┌── AUDIT SUMMARY ──────────────────────────────────────┐
│ Codebase Score: 55/100
│ Health Rating: C (Noticeable dependency bloat)
│ Dependency Bloat: 3 package(s)
└───────────────────────────────────────────────────────┘Head-to-Head Comparison
Metric | Vanilla AI Agent | "Lazy" Prompt (Ponytail) | Grandpa Standard |
New Dependencies Added | Heavy (npm bloat) | Low | Zero (Stdlib First) |
Code Verbosity | 100% (Over-engineered) | ~40% (Golfed one-liners) | ~45% (Focused & Readable) |
HTTP Status Checking | Inconsistent | ❌ Frequently stripped | Guaranteed ( |
Network Timeout Aborts | Rarely included | ❌ Omitted | Guaranteed ( |
Framework Awareness | Generic | ❌ Breaks on hydration | Next.js & React 19 safe |
Active CLI Scanner | None | None | Built-in ( |
Git Pre-Commit Guard | None | None | Built-in ( |
MCP Server Integration | None | Basic | Built-in ( |
The 8 Specialized Skills
Grandpa includes 8 specialized skills for every stage of development:
grandpa: Core architectural engine and decision ladder.grandpa-audit: Scans whole codebase for bloat, fragile patterns, and framework debt.grandpa-review: Line-by-line PR & diff review for unnecessary complexity.grandpa-debt: Tracks and schedules payoff of architectural exception receipts.grandpa-guard: Real-time safety guard against dangerous AI generation patterns.grandpa-migrate: Step-by-step migration plans from bloated dependencies to native stdlib.grandpa-gain: Quantifies dependencies, bundle size, and maintenance hours saved.grandpa-help: Instant cheat sheet and replacement reference table.
Grandpa Model Context Protocol (MCP) Server
Connect Grandpa directly to Claude Desktop, Cursor, Windsurf, or any MCP client:
{
"mcpServers": {
"grandpa": {
"command": "npx",
"args": ["-y", "@bytewhisker/grandpa", "mcp"]
}
}
}Exposes tools:
grandpa_scan: Scans repo for bloat & fragile patterns.grandpa_audit: Returns scored codebase report (A+ to F).grandpa_guard: Pre-execution validation of code and bash commands.grandpa_migrate: Provides stdlib drop-in code for bloated packages.grandpa_rules: Injects intensity-specific system instructions.
16 Battle-Tested Examples
Browse our collection of 16 real-world before/after demonstrations in examples/:
Empirical Benchmark Results
We benchmarked Grandpa against Ponytail, Caveman, and Bare AI across two rigorous environments: Live Real-LLM inference with exact provider token accounting and a 500-run multi-turn repair suite across 25 production tasks.
1. Live Real-LLM Benchmark (Google Gemini Live API)
Evaluated live with real provider token accounting (prompt_tokens, completion_tokens), real model network latency, isolated subprocess execution, and automated multi-turn repair loops.
Strategy | Success Rate (Gate) | 1st-Pass Rate | Median TCS | p75 TCS | Failure-Aware Efficiency(Tokens / Solved Task) | Median TTCS |
Grandpa (Quick) | 100.0% (30/30) | 100.0% (30/30) | 356 t | 462 t | 403 t / solved | 1,530 ms |
Ponytail | 83.3% (25/30) | 63.3% (19/30) | 225 t | 340 t | 592 t / solved | 1,223 ms |
Caveman | 100.0% (30/30) | 63.3% (19/30) | 335 t | 749 t | 598 t / solved | 1,613 ms |
Bare AI (Vanilla) | 100.0% (30/30) | 53.3% (16/30) | 1,011 t | 2,041 t | 1,490 t / solved | 3,669 ms |
$$\text{Failure-Aware Efficiency} = \frac{\text{Total Tokens Consumed Across Entire Workflow}}{\text{Tasks Successfully Solved}}$$
Why Grandpa Wins the Workflow:
Minimalist "code-golf" approaches look cheap on turn 1, but frequently strip status checks, timeouts, or clean exports—causing 37% first-pass failure rates on real LLMs. Multi-turn repair loops rapidly burn tokens.
Grandpa achieves 100% first-pass pass rate with standard defensive guards, saving ~32% total workflow tokens over Ponytail/Caveman and 73% over unsteered Bare AI.
2. Comprehensive 500-Run Suite (25 Tasks × 5 Repetitions)
Data source: 500 isolated runs across 8 software engineering domains recorded in benchmarks/results/latest-summary.json.
Strategy | Success Rate | First-Pass Rate | Median TCS | p75 TCS | p95 TCS | Median TTCS | Dependencies Added |
Grandpa | 100.0% | 96.0% | 270 t | 298 t | 363 t | 74 ms | 0 |
Ponytail | 96.0% | 88.0% | 242 t | 270 t | 328 t | 75 ms | 0 |
Caveman | 96.0% | 88.0% | 196 t | 226 t | 259 t | 74 ms | 0 |
Bare AI (Vanilla) | 100.0% | 96.0% | 268 t | 306 t | 347 t | 74 ms | 0 |
"Output tokens are cheap. Debugging turns aren't. Grandpa optimizes the whole coding loop."
See complete methodology, per-task breakdowns, and failure analysis in benchmarks/REPORT.md.
Run the benchmarks:
# Run 500-run comprehensive suite
npm run benchmark
# Run live real-LLM benchmark (requires API key in .env)
node --env-file=.env benchmarks/live-harness.jsQuick Start
1. Install Globally (Run grandpa anywhere in any terminal)
# Install globally from GitHub (always latest)
npm install -g github:bytewhisker/grandpa
# Or run instantly without installing
npx github:bytewhisker/grandpa scanOnce installed globally, you can type grandpa in any terminal:
grandpa --help # Display full interactive help guide and options
grandpa scan # Audit project for dependency bloat & fragile code
grandpa init # Install zero-bloat rules for Cursor, Windsurf, Claude Code
grandpa hook # Install git pre-commit guard against AI dependency bloat
grandpa mcp # Launch Model Context Protocol server for AI assistants
grandpa gain # View cumulative token & architecture savings2. Install Rules Into Your Workspace (25+ Agents)
Installs configurations for Cursor (.cursor/rules), Windsurf (.windsurfrules), Claude Code, Antigravity (AGENTS.md), and 20+ other agents in one command:
grandpa init
# Or targeted: grandpa init cursor | grandpa init windsurf | grandpa init agents3. Enable Git Pre-Commit Guard
Blocks AI coding assistants from silently adding unvetted dependencies to package.json:
grandpa hookContinuous Integration (CI/CD)
Enforce zero-bloat architecture automatically in your GitHub Actions pipeline:
name: Grandpa Architecture Audit
on: [push, pull_request]
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
- run: npx github:bytewhisker/grandpa scan --strictLicense
Distributed under the MIT License. See LICENSE for details.
Author & Credits
╭──────────────────────────╮
│ GRANDPA 🧓 │
│ AI Coding Optimizer │
│ │
│ Engineered by Mahadi │
│ @bytewhisker │
╰──────────────────────────╯Designed & engineered by Mahadi (@bytewhisker)
© 2026 Grandpa / ByteWhisker. All rights reserved.
This server cannot be deployed
Maintenance
Related MCP Connectors
Lints + auto-fixes how AI coding agents discover any new product. 24 rules, 6 tools, score 0-100.
Code intelligence platform for AI agents. 20 tools for architecture, security & impact analysis.
Lets coding agents check their own code for leaked secrets, risky dependencies and AI-code mistakes
11Enforces architectural invariants and code quality rules inside your AI agent's edit loop.
318
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceProvides LLM-optimized tools for advanced code analysis, repository complexity evaluation, and call graph generation. It enables users to visualize directory structures, detect code patterns, and build semantic context with significant token savings.11 npmMIT
- AlicenseAqualityDmaintenanceEnables CLI agents to detect and remove dead code, manage complexity, and enforce hygiene rules in TypeScript/JavaScript projects through tools like scanning, cleansing, and reporting.56 npmISC
- AlicenseCqualityBmaintenanceEquips AI coding agents with 62 production-grade tools across 28 modules for persistent memory, live GitHub scouting, UI/UX design, DevOps, security, performance auditing, and SEO/AEO/GEO optimization, enabling automated, development workflows.631MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI coding assistants to inspect local and remote repositories through sandboxed tools that surface project overviews, structure, dependency audits, Git churn hotspots, and a heuristic health score. It also supports safe GitHub issue searching and creation with built-in duplicate preflight checks, while blocking sensitive files, binary content, and path traversal attacks.38 npmMIT