## Inspiration
Repository review is usually split between a web interface and a detached AI conversation. Browser agents can attempt to interpret the DOM, while remote MCP servers can expose repository APIs, but neither naturally shares the exact transient workspace state the person is viewing.
GitHub Web MCP, presented as RepoScope, explores a different approach: the webpage itself exposes structured, context-sensitive capabilities to the agent. The human and agent review the same file, findings, proposal, and approval state in one visible workspace.
## What it does
RepoScope is a controlled GitHub-like repository review application demonstrating human-agent collaboration through WebMCP.
A person opens a file and asks an agent to review the repository. The agent:
- Reads the live workspace context.
- Investigates relevant repository files.
- Identifies the most serious substantiated problem.
- Places a visible annotation on the relevant line.
- Prepares an editable issue proposal without creating it.
The person can edit, approve, or dismiss the proposal. Approval authorizes one exact draft revision but does not execute it. After the person tells the agent “Approved,” the agent creates the reviewed issue and the result immediately appears in the interface.
The page’s tool surface changes with its state:
- Fresh repository: 7 tools
- Reviewable file open: 9 tools
- Exact proposal approved: 10 tools
- Issue created or proposal dismissed: 7 tools
This dynamic capability model demonstrates why the experience benefits from WebMCP instead of being a conventional API wrapper.
## How we built it
RepoScope is a client-only React and TypeScript application built with Vite and deployed using Cloudflare Workers Static Assets.
The React interface and WebMCP tools share one observable application service. This ensures that human actions and agent actions use the same application logic and produce immediate visible updates.
The dedicated WebMCP adapter:
- Registers tools with
document.modelContext.registerTool() - Separates read-only and state-changing capabilities
- Reconciles registrations when workspace state changes
- Cleans up registrations with abort signals
- Verifies discovery using
document.modelContext.getTools() - Records agent calls in a visible activity feed
- Updates the interface before mutating calls finish
The final issue-creation capability accepts only a reference to the exact approved proposal. It rejects pending, edited, dismissed, stale, unknown, or previously completed proposals.
The project intentionally uses local fixture data rather than a backend or GitHub API. This keeps the demonstration focused on live page context, dynamic capabilities, and human approval.
## Challenges we ran into
The first challenge was making WebMCP essential to the experience. An early version allowed an agent to inspect files and create an issue, but a remote MCP server could have provided the same functionality. We redesigned the workflow around live workspace state, dynamic tool discovery, visible annotations, and in- page approval.
Designing a reliable approval boundary was another challenge. Clicking Approve and executing the action are intentionally separate. Editing an approved proposal revokes its approval, and the agent cannot change its contents during the final creation call.
WebMCP is also an experimental browser API. We isolated all experimental integration code behind a small adapter, made the normal interface work when WebMCP is unavailable, and added visible discovery status and automated lifecycle tests.
Finally, agent activity is normally difficult to demonstrate on video. We added a bounded activity feed so viewers can see the agent investigate, annotate, propose, and complete its work directly in the application.
## Accomplishments that we're proud of
We built a complete two-turn human-agent workflow that requires no tool names, schemas, or internal identifiers in the human conversation.
The person can make a natural request, review the agent’s evidence in context, approve an exact proposal, and complete the action by saying only “Approved.”
We are especially proud of:
- Dynamic discovery that visibly transitions 7 → 9 → 10 → 7
- Inline findings connected to the relevant source line
- An editable and revocable approval workflow
- Exact-revision authorization for issue creation
- Immediate UI updates from agent actions
- A visible and safely summarized agent activity feed
- Graceful behavior when WebMCP is unavailable
- A native ChatGPT Site tools rehearsal of the complete workflow
The automated suite includes 28 unit and component tests plus three Playwright browser scenarios, alongside TypeScript, ESLint, and production-build verification.
## What we learned
Our main lesson was that WebMCP is more than a browser-accessible API. Its strongest value appears when an agent’s capabilities reflect the transient state, permissions, and workflow of the page a person is actively using.
Dynamic discovery can provide both context and control. It reduces irrelevant options for the agent and ensures sensitive capabilities appear only when their prerequisites are satisfied.
We also learned that successful tool execution is not enough for good collaboration. People need to see what the agent inspected, what it found, what it proposes, and exactly where human authority begins and ends.
## What's next for Github web mcp
The next step is to evolve RepoScope from a focused competition demonstration into a reusable pattern for safe, context-aware repository collaboration.
Potential extensions include:
- Optional integration with real GitHub repositories
- Persistent review sessions and findings
- Pull-request review workflows
- Line-range and multi-file annotations
- Multiple independently reviewable proposals
- Repository-specific authorization policies
- Richer evidence links between findings, code, issues, and pull requests
- Improved compatibility as the WebMCP standard evolves
The approval model could also be applied beyond repository review. Document editors, design tools, administrative dashboards, and investigation workspaces could expose context-sensitive agent capabilities while preserving their existing human controls and authorization boundaries.
Built With
- chatgptsitetools
- cloudflareworker
- css3
- html
- playwright
- react
- typescript
- vite
- vitest
- webmcp
- wrangler
Log in or sign up for Devpost to join the conversation.