graphpilot
GraphPilot is a structural code intelligence server that indexes TypeScript/JavaScript repositories into a graph of symbols and call edges, enabling coding agents to answer structural questions without grepping or reading files — reducing token usage and hallucinations.
gp_recall– Find symbol definitions: Look up any function, class, or variable by name (exact or substring) and get its kind, file location (with line number and git SHA), and signature. A sub-millisecond, false-positive-free alternative togrep.gp_callers– List callers or callees: Retrieve every caller of a symbol (who calls X?) or everything a symbol calls (what does X depend on?), using a pre-indexed reverse map — ideal for understanding dependencies before a rename or refactor.gp_impact– Compute blast radius: Analyze the full impact of a rename or signature change, returning direct callers, transitive callers (configurable BFS depth 1–5), affected test files, and public API status. Supports asinceparameter to scope results to files changed since a specific commit or branch — perfect for PR-scoped analysis.gp_index– Re-index the repository: Trigger a fresh index after batch edits so subsequent queries reflect the latest changes, invalidating the query cache in the process.
Additional highlights: Operates entirely locally with no telemetry or remote calls, ensuring code privacy, with sub-millisecond query times after initial indexing and incremental updates in watch mode.
What it is
GraphPilot is a local CLI + MCP server that indexes your TypeScript/JavaScript repo into a structural graph (symbols, callers, callees, blast radius) and exposes it to coding agents — Claude Code, Cursor, Cline, Windsurf, Continue — so they stop re-grepping the same files every conversation.
The problem it solves: agents burn tokens, hallucinate function names, and miss structural relationships ("what calls this?", "what breaks if I rename it?") because each session starts from zero. GraphPilot is the persistent structural memory in between.
Token cost drops. Hallucinations drop. Refactors get safer.
Put a real coding agent (claude-sonnet-4-5) on 40 structural questions about fastify — a ~300-file Node.js framework — and give it nothing but file reads. Then hand it GraphPilot's four tools and ask the same 40. The agent with GraphPilot uses 61 % fewer tokens, costs $3.68 instead of $8.88 — $5.20 saved per session — and gets more of them right, not fewer (37 correct vs 33). Same model, same questions, same repo; the only change is whether the structural index is there. Reproduce it →
A separate correctness benchmark backs the savings with precision: on 10 standardized structural queries GraphPilot scores F1 0.89 vs grep's 0.42 while reading 99.9 % fewer bytes (721 B vs 528 KB), and the byte-cost win holds at scale — indexing microsoft/TypeScript (601 files, 17 k symbols, 70 k call edges in 10 s) gives sub-millisecond queries and a 99.99 % bytes-read reduction. Full methodology →
Related MCP server: state-trace
One binary, two modes
GraphPilot ships as a single npm package (@graphpilot-oss/graphpilot) with two runtime modes — most users run both.
Mode | Command | What it does |
CLI |
| Walks your repo, builds the structural graph, writes it to |
| Keeps the graph fresh (~10 ms per file save) | |
| Health probe — when the graph was last refreshed, file/symbol/edge counts | |
MCP server |
| Speaks MCP over stdio — your coding agent calls into this to query the graph |
The flow: the CLI builds the index once (and watch keeps it warm). The MCP server is what your coding agent talks to — you never invoke it yourself, you just point your agent's MCP config at graphpilot mcp once and the agent spawns it on every session.
If you only want CLI access to your code graph (no agent), run graphpilot index and then graphpilot stats / inspect graph.json directly. If you only want the agent integration, you still need to run graphpilot index once — the MCP server is read-only against the on-disk graph.
What makes it different
Other code-graph tools treat your repo as a static blob: index once, query forever, no branch awareness, no proof of where an answer came from. GraphPilot is built around three properties none of them ship:
🔍 Evidence anchors. Every tool response carries
file:line @ shaon every symbol and call site. The agent can quote the anchor verbatim and you can verify it instantly — hallucinations get exposed the moment you jump to the line.🌿 Differential impact. Pass
since: <commit|branch>togp_impactand the result is filtered to files your branch actually touches. PR-scoped refactor analysis in one call instead ofgit diff | xargs grep.🪵 Worktree-aware by default. Two
git worktree add-ed branches naturally produce two separate indexes — no manual config. Rungraphpilot index ./src/featurefrom a subdir and it transparently re-roots to the worktree top. Opt out with--no-worktree.
Add to that: local-first (no telemetry, no remote calls, enforced by an ESLint policy on src/ itself), deterministic (same repo → same graph), sub-second incremental updates via watch mode.
Quickstart
Prerequisites
Node.js ≥ 20 (
node --versionto check)An MCP-capable coding agent (Claude Code, Cursor, Cline, Windsurf, or Continue)
A TypeScript or JavaScript repo to index
End-to-end time: ~3 minutes.
1. Install the CLI
npm install -g @graphpilot-oss/graphpilot
# or: pnpm add -g @graphpilot-oss/graphpilot
# or one-shot, no install: npx @graphpilot-oss/graphpilot <command>Verify it landed on your PATH:
graphpilot --version
# → 0.1.0If you see command not found: graphpilot, your global npm bin is not on PATH. Run npm config get prefix and add <prefix>/bin to your shell's PATH, or use the npx form above.
2. Build the structural index for your repo
Run this once per project. It walks your source tree, parses each TS/JS file with tree-sitter, extracts symbols + call edges, and writes the graph to ~/.graphpilot/<repo-id>/graph.json.
graphpilot index ~/code/my-appExpect a one-line summary like indexed 412 files · 3,981 symbols · 7,204 edges · 1.8s.
3. Wire it into your coding agent
GraphPilot speaks MCP over stdio. Add this server entry to your agent's MCP config — every supported client uses the same two-line shape:
{
"mcpServers": {
"graphpilot": {
"command": "graphpilot",
"args": ["mcp"]
}
}
}Where this file lives depends on the client (~/.cursor/mcp.json, ~/.claude.json, Cline's settings panel, etc.). Pre-made configs with the exact file path for each agent are in examples/ — copy the one for your client.
Restart the agent. It now has four new tools: gp_recall, gp_callers, gp_impact, gp_index — see The four tools below for what each one does and when the agent should reach for it.
4. Try it
Ask your agent a structural question instead of letting it grep:
"Use gp_impact to show me everything that breaks if I rename
parseToken."
You should see a response with file:line @ sha anchors you can click straight to. If the agent doesn't reach for the tool, prompt explicitly: "use the gp_ MCP tools." If it can't see them at all, the MCP config wasn't picked up — run graphpilot doctor to pinpoint why (or see docs/troubleshooting.md), then restart the agent.
5. Keep the index fresh as you edit (optional but recommended)
graphpilot watch ~/code/my-appSub-10 ms incremental updates on each file save. Leave it running in a terminal tab.
6. Drop per-editor routing rules into your repo (optional)
graphpilot initAuto-detects which editors you have installed (Cursor, Claude Code, Cline, Windsurf, Continue) and writes the matching rules file (.cursorrules, CLAUDE.md, etc.) to the current directory. The rules teach the agent to reach for gp_* tools before grep.
graphpilot init --all # write rules for every supported editor
graphpilot init --client cursor # one editor only
graphpilot init --dry-run # preview without writingFull 5-minute walkthrough with screenshots: docs/quickstart.md.
The four tools
GraphPilot exposes four MCP tools. Each one answers a structural question your agent would otherwise solve by grepping and reading files.
gp_recall — find a symbol by name
Use this when the agent asks "where is X defined?" or needs to locate a function before reasoning about it.
Input:
{ query, limit?, substring?, path? }Returns: symbols matching the name (exact case-insensitive by default;
substring: truefor partial matches), each withfile:line @ sha.Replaces:
grep -rn "function X"plus reading each hit to find the real definition.
Agent: gp_recall({ query: "parseToken" })
→ parseToken (function) — src/auth.ts:42 @ a1b2c3d
export function parseToken(raw: string): Token | nullgp_callers — list callers (or callees)
Use this when the agent needs to know "who calls X?" or "what does X call?" — the two fundamental questions of refactoring.
Input:
{ symbol, direction?: 'callers' | 'callees', limit?, includeUnresolved?, path? }Returns: every call edge where the symbol is target (callers) or source (callees), with anchors.
Replaces:
grep -rn "X("followed by manual filtering of comments, strings, and renamed shadows.
Agent: gp_callers({ symbol: "authenticate", direction: "callers" })
→ login → authenticate — src/routes/login.ts:18 @ a1b2c3d
→ refreshSession → authenticate — src/session.ts:64 @ a1b2c3dgp_impact — blast radius in one call
Use this when the agent asks "what breaks if I rename X?" or "what depends on this?" — the single most expensive question an agent normally solves.
Input:
{ symbol, depth? (1–5, default 3), since?, path? }Returns: direct callers, transitive callers grouped by BFS depth, tests likely affected, public-API flag, summary stats.
Killer feature: pass
since: 'main'and the result is scoped to files your branch actually touches — PR-scoped refactor review withoutgit diffgymnastics.
Agent: gp_impact({ symbol: "extractSymbols", depth: 2, since: "main" })
→ Direct callers (2): indexDirectory, applyUpdate
→ Depth-2 callers (1): cmdIndex
→ Tests affected (3): tests/indexer.test.ts, tests/symbols.test.ts, tests/cli.test.ts
→ Public API: nogp_index — refresh from inside the agent
Use this after the agent (or the user) has made a batch of structural edits and wants the graph to reflect them without dropping to a shell.
Input:
{ path? }Returns: re-indexes the repo and invalidates the per-path query cache.
Pairs with:
graphpilot watchfor sub-10 ms incremental updates between explicit re-indexes.
How it works
Data flow is one-way: source → tree → symbols + edges → JSON → query → agent. GraphPilot never modifies your code.
Full pipeline writeup with file references: docs/architecture.md.
When to use which tool
If the agent is about to… | Reach for… | Why |
|
| One call, no false positives from comments or strings |
Read 20 files looking for "who calls X" |
| Pre-computed reverse index, sub-millisecond |
Plan a rename or signature change |
| Direct + transitive + tests + public-API in one call |
Review a PR's structural blast radius |
| Differential — only callers your branch touches |
Re-grep after editing several files |
| Incremental: lets the next call see your edits |
For string literals, error messages, config values, or anything in a language other than TS/JS: stay with grep. GraphPilot indexes code structure, not text.
Editor setup
GraphPilot speaks MCP over stdio, so it works with any MCP-capable client. Ready-to-paste configs live in examples/:
Client | Folder |
Claude Code (Anthropic) | |
Cursor | |
Cline (VS Code extension) | |
Windsurf (Codeium) | |
Continue.dev | |
Any other MCP client |
Each folder contains: a README.md walkthrough, a sample config file with the exact JSON to paste, and (where the client supports it) a routing template so the agent automatically reaches for GraphPilot on structural questions.
Privacy & security
GraphPilot is local-first by promise and by build gate.
No telemetry, no remote calls, ever. Verifiable:
src/has zerohttp,fetch,axios, or analytics imports — enforced by an ESLint rule plus a meta-test that proves the rule fires on every banned import.No
child_process, noexec, nospawn. Git facts are read directly from.git/via pure-JS helpers.Source code never leaves your machine. Only structural metadata (names, locations, signatures, call relationships) lives in
~/.graphpilot/.Signatures are redacted for common secret patterns (OpenAI/Anthropic
sk-, GitHubghp_/ghs_, AWSAKIA, JWTs, PEM headers, Slack/Stripe tokens) before they're written to disk.Strict file permissions: dir
0o700, files0o600.Schema validation on load: tampered or corrupt
graph.jsonfalls back to "no index" rather than poisoning the agent.Hand-rolled input validators on every MCP tool — unknown fields are rejected, every field type-checked, numbers range-checked, strings length-capped.
Threat model and per-defence test references live in docs/architecture.md. Report security issues per SECURITY.md.
Limitations
GraphPilot v0.1 makes deliberate trade-offs to ship small and sharp:
TS/JS only. Python, Rust, Go, Java are out of scope for v1. Python is demand-gated for v0.2 / v0.3.
Name-based resolver (no import-path tracking, no type-based method dispatch). Expected resolution rate: ~25–35 % of edges resolve to in-repo symbols; the rest are stdlib / third-party. That's enough because the questions agents actually ask ("who calls X in my repo?") are the ones the dumb resolver answers correctly.
No semantic search.
gp_recallis name-only. "Find code similar to this snippet" is deferred until 30+ users ask for it.No
.graphpilotignoreyet (defaults skipnode_modules,dist,build,.git,coverage,.next,.nuxt,.cache,out,*.d.ts).Single repo per query. Workspace abstraction is on the v1.x roadmap.
Full list with mitigations: docs/limitations.md.
FAQ
Does it send my code anywhere?
No. There is no network code in src/, no telemetry, no update check. An ESLint rule blocks adding any of those at the build gate.
Will it slow down my editor? The MCP server is idle until your agent calls a tool. Tool calls are sub-millisecond after the first lazy load. Watch mode adds ~3–10 ms per file save.
What happens to the graph when I switch branches?
If you use git worktree, you automatically get a separate graph per worktree. On a single working copy that you switch with git checkout, the graph reflects the last gp_index (or watch-mode updates). Run gp_index after a branch switch to refresh.
Do I need to re-index every session?
No. The graph persists at ~/.graphpilot/<repo-id>/graph.json. Re-index after sweeping changes; otherwise, watch mode keeps it fresh incrementally.
Why TypeScript/JavaScript first? That's where the maintainer's pain was, and tree-sitter-typescript covers TS, TSX, JSX, and JS in a single grammar. Python is the next likely addition; vote with a GitHub Discussion.
How does this compare to LSP? LSPs are scoped to one editor and one buffer at a time, and they re-compute on each query. GraphPilot is editor-agnostic, persists across sessions, and answers structural questions (who-calls, blast-radius) that LSPs don't expose uniformly.
The agent can't see the tools / something's not working.
Run graphpilot doctor — it checks Node, PATH, the index, the MCP handshake, and per-client config in one shot. Symptom-by-symptom fixes live in docs/troubleshooting.md.
Documentation
docs/quickstart.md— 5-minute walkthroughdocs/mcp-setup.md— per-client config referencedocs/troubleshooting.md— symptom-indexed fixes (start withgraphpilot doctor)docs/architecture.md— pipeline writeup with file refsdocs/limitations.md— v1 caveats (read this)bench/README.md— benchmark methodology + resultsexamples/— ready-to-paste configs for every supported client
Contributing
GraphPilot is small, opinionated, and accepting contributions. Start with CONTRIBUTING.md — especially the "What we are NOT doing in v1" section before you propose a feature.
Found a security issue? Please follow SECURITY.md instead of opening a public issue.
License
Apache-2.0. Copyright 2026 Akshay Sharma — codewithakki@gmail.com
Available Tools
4 toolsgp_callersA
List every caller of a symbol (direction=callers) or everything it calls (direction=callees). ALWAYS use instead of grep -rn "X(" for "who calls X?" — pre-indexed reverse map, sub-millisecond, no false positives from comments or strings. Use direction=callers to find dependents before a rename; direction=callees to understand what a function depends on. Do NOT use for full blast-radius analysis across multiple hops — use gp_impact instead.
| Name | Required | Description | Default |
|---|---|---|---|
| symbol | Yes | Symbol name or full id. | |
| direction | No | Default 'callers'. | |
| limit | No | Max edges (default 50). | |
| includeUnresolved | No | Include external/stdlib calls (default true). | |
| path | No | Repo root with a GraphPilot index. Optional: when omitted, resolves via GRAPHPILOT_ROOT, MCP workspace roots, parent walk, or a single ~/.graphpilot index. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Mentions sub-millisecond speed and no false positives, but lacks explicit statement of read-only nature or side effects; no annotations to compensate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences plus note; front-loaded with core action and efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Covers core functionality and use cases, but lacks description of output format (list structure) given no output schema.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so baseline 3. Description adds no extra parameter info beyond what schema provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Clearly states it lists callers or callees of a symbol, distinguishes from sibling gp_impact by noting multi-hop analysis.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says when to use (e.g., before rename) and when not to use (full blast-radius), even recommends alternative tool gp_impact.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
gp_impactA
Compute the blast radius of a rename or signature change: direct callers, transitive callers up to depth 3, affected tests, and whether the symbol is exported (breaking-change risk). ALWAYS call before proposing a rename, signature change, or behavior change — replaces git diff | xargs grep with a single structured answer. Pass since: <commit|branch> to scope callers to files changed since that ref (ideal for PR review or refactor scoping). Do NOT use just to see direct callers; use gp_callers for that.
| Name | Required | Description | Default |
|---|---|---|---|
| symbol | Yes | Symbol name or full id to analyze. | |
| depth | No | BFS depth over the callers graph. Default 3. | |
| path | No | Repo root with a GraphPilot index. Optional: when omitted, resolves via GRAPHPILOT_ROOT, MCP workspace roots, parent walk, or a single ~/.graphpilot index. | |
| since | No | Optional commit SHA, tag, or branch. When set, restricts callers to files changed between that ref and HEAD. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It describes the computed outputs and scope (depth up to 3), but does not explicitly state whether the tool is read-only or has side effects. It mentions replacing a grep command, implying safety, but direct side-effect disclosure is missing.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is well-structured: start with purpose, then when to use, then special case, then exclusion. Every sentence adds value, no fluff. It is front-loaded with the most important information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description adequately explains what the tool returns (direct callers, transitive callers, affected tests, export status) and how parameters like 'since' affect results. It covers the key aspects for an agent to invoke and interpret the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, baseline 3. The description adds value by explaining default depth (3), the purpose of 'since' for PR review, and path resolution strategy. This context enriches understanding beyond the schema's minimal descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly specifies the tool's purpose: 'Compute the blast radius of a rename or signature change'. It lists specific outputs (direct callers, transitive callers up to depth 3, affected tests, export status) and distinguishes it from sibling gp_callers by stating it is not for direct callers only.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicit guidance: 'ALWAYS call before proposing a rename, signature change, or behavior change' and 'Do NOT use just to see direct callers; use gp_callers for that.' Also includes a special case for the 'since' parameter to scope to changed files, ideal for PR review.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
gp_indexA
Re-index the repo after batch edits so subsequent gp_* calls see your changes. Call after any non-trivial edit session. Do NOT call before every query — indexing is slow; only needed when source files changed.
| Name | Required | Description | Default |
|---|---|---|---|
| path | No | Repo root with a GraphPilot index. Optional: when omitted, resolves via GRAPHPILOT_ROOT, MCP workspace roots, parent walk, or a single ~/.graphpilot index. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Discloses that indexing is slow and only needed after source changes. No annotations exist, so description carries behavioral burden. Could mention what happens if index is stale, but current detail is sufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded with action, then usage guidelines. Every word serves a purpose; no fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, return values are not described, but for a simple re-index action this is acceptable. Covers when, why, and side effects (slowness). Minor gap: no mention of success/failure feedback.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, but description adds value by detailing the resolution order for the optional path parameter: GRAPHPILOT_ROOT, MCP workspace roots, parent walk, or a single ~/.graphpilot index.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses specific verb "re-index" and resource "repo", and distinguishes from sibling tools (gp_callers, gp_impact, gp_recall) by stating when to call (after batch edits) and when not to (not before every query).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states when to use: "after batch edits" and when not to: "Do NOT call before every query". Also provides rationale: "indexing is slow; only needed when source files changed."
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
gp_recallA
Find a symbol definition by name — returns kind, file:line, and signature. ALWAYS use instead of grep -rn "function X" or reading files to locate a definition: pre-indexed, no false positives from comments or strings, sub-millisecond. Pass substring:true for partial-name searches. Do NOT use for "who calls X?" — use gp_callers for that.
| Name | Required | Description | Default |
|---|---|---|---|
| query | Yes | Symbol name to look up. | |
| limit | No | Max results (default 10). | |
| substring | No | Enable substring match (default false). | |
| path | No | Repo root with a GraphPilot index. Optional: when omitted, resolves via GRAPHPILOT_ROOT, MCP workspace roots, parent walk, or a single ~/.graphpilot index. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full burden. It discloses pre-indexed nature, no false positives, sub-millisecond performance, and path resolution behavior. Does not cover error handling (e.g., symbol not found), but overall good context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Highly concise and front-loaded: starts with purpose, then guidelines, then parameter hints. Every sentence adds value with no fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description specifies return values (kind, file:line, signature). All 4 parameters are explained. Sibling tools are listed. Complete for the intended use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% (baseline 3). The description adds meaning by explaining substring usage ('Pass substring:true for partial-name searches') and path resolution behavior, going beyond the simple schema descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it finds a symbol definition by name, returning kind, file:line, and signature. It distinguishes from sibling tools by explicitly stating to use instead of grep and not for 'who calls X?' (use gp_callers).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides explicit when to use ('ALWAYS use instead of grep -rn...') and when not to use ('Do NOT use for "who calls X?" — use gp_callers for that'), along with hints for substring parameter usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
TDQS
Each tool has a clearly distinct purpose: gp_recall finds definitions, gp_callers shows direct callers/callees, gp_impact computes transitive blast radius, and gp_index re-indexes after edits. Descriptions explicitly contrast them, preventing ambiguity.
All tools follow the 'gp_<verb>' pattern with lowercase and underscores. Although the verbs mix nouns (callers, impact) and verbs (index, recall), the overall pattern is consistent and predictable.
With 4 tools, the server is well-scoped for its code analysis purpose. Each tool covers a core task without unnecessary duplication or excessive complexity.
The tool set covers essential workflows: finding definitions, direct dependencies, transitive impact, and re-indexing. Minor gaps like listing all symbols of a type exist, but the set handles the stated replace-grep goals effectively.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Memory that reasons: continual learning for stateful agents. Better context, fewer tokens.
Codebase intelligence for agents: 152 structured artifacts across 21 programs, one call.
Shared memory for coding agents. Stop re-explaining your codebase every session.
Shared distillation cache for AI agents — every fetch ~73-89% fewer tokens via a shared cache.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceProvides local vector-based semantic memory storage for AI assistants to persist context and decisions across sessions using local embeddings and LanceDB. It enables private semantic search and session handoff capabilities to maintain long-term project context.705MIT
- AlicenseNot gradedqualityCmaintenanceGraph-native bounded working memory for coding agents with typed memories, causal retrieval, current-vs-stale state queries, and compact small-model briefs.2MIT
- AlicenseNot gradedqualityAmaintenanceEnables AI coding agents to efficiently query code context via a symbol graph, reducing token usage by up to 20x.1,223469Unlicense - libtelnet variant
- FlicenseNot gradedqualityAmaintenanceLocal-first code retrieval for AI agents — cuts codebase context from thousands of tokens to a few hundred, with zero hallucinated file paths.3
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/graphpilot-oss/graphpilot'
If you have feedback or need assistance with the MCP directory API, please join our Discord server