Inspiration

Cyber investigations are fragmented across evidence folders, specialist tools, notes, and reports. AI can organise this work, but an investigator still needs to understand what the agent used, why it reached a conclusion, and who authorised the final decision.

NetSpectre Challenge Edition explores a safer collaboration model: the person and agent share one visible investigation workspace. The agent can read structured case facts, explain signals, and prepare a finding, while the investigator retains final approval.

What it does

The demonstration follows a fictional supplier-impersonation and payment-diversion case. NetSpectre exposes five focused WebMCP tools that let an agent:

  • obtain a structured case briefing;
  • list safe metadata for preserved synthetic evidence;
  • retrieve explainable signals above a chosen confidence level;
  • create a reviewable draft finding; and
  • generate an incident summary reflecting the current human-review state.

The agent cannot approve its own output. Approval happens through the visible interface, and the activity record identifies whether each action came from the agent or the investigator.

Why WebMCP

A conventional browser agent must infer meaning from cards, labels, and buttons. WebMCP gives the agent narrow, typed operations tied directly to the live case. Evidence references, confidence thresholds, and review state become explicit instead of depending on visual guesswork.

Before this workflow, an investigator might manually copy evidence details into an AI conversation and then copy the response back into a separate case system. That loses provenance and blurs the line between an AI suggestion and an authorised finding. NetSpectre keeps context, evidence, recommendations, and approval state together.

How we built it

The challenge edition is a standalone TypeScript and React application. It feature-detects document.modelContext.registerTool and registers five tools with narrow JSON schemas. Read-only operations are annotated accordingly; the drafting operation declares its side effect and returns an awaiting_human_review state.

The WebMCP tools and interface share the same application state, so agent actions are immediately visible to the person. The site also remains usable as a normal web application when WebMCP is unavailable.

Challenges we ran into

The hardest part was making agent assistance genuinely useful without allowing it to become the decision-maker. We designed a strict draft-and-review boundary, preserved evidence provenance, kept the public challenge edition separate from private NetSpectre code, and used synthetic data throughout.

Accomplishments we're proud of

  • A working human-agent investigation rather than a scripted chatbot demo
  • Five discoverable, narrowly scoped WebMCP tools
  • Visible agent activity and preserved evidence references
  • Mandatory human approval for consequential findings
  • A public, reproducible, MIT-licensed challenge repository

What we learned

WebMCP works best when it exposes domain actions, not generic UI automation. Typed tools make the agent more reliable, while shared visible state keeps the person informed and in control.

What's next

Next we would extend the pattern to multi-case queues, configurable investigation playbooks, exportable audit records, and integrations with authorised security-data sources—without weakening the human approval boundary.

Safety and privacy

All organisations and evidence are synthetic. The demo opens no arbitrary files, scans no networks or devices, and contains no customer data, production credentials, or private commercial NetSpectre engine code.

Challenge work

NetSpectre existed previously as a private Windows-first product. This separate browser-based WebMCP edition, its five tools, synthetic case, approval workflow, activity record, deployment, and submission materials were created during the challenge period. The public repository contains only this new challenge work.

Built With

Share this project:

Updates

Submission history