-
-
Local knowledge changes the result — a WebMCP route constraint becomes visible and affects later analysis.
-
Intent-level Site Tools — six WebMCP tools expose domain verbs instead of brittle click sequences.
-
One shared surface — public La Palma terrain and Copernicus history stay separate from the synthetic exercise.
-
Human authority by design — the agent can stage a plan, but only the exercise director can approve it.
Inspiration
Wildfire readiness needs a rehearsal space before the crisis. Exercises combine sensor evidence, local knowledge, changing assumptions and high-consequence decisions. Traditional dashboards are built for human clicks, while chat assistants reason in a separate window and quickly lose the state visible on the map. We wanted a safer collaboration model: an agent can help inspect and compare, but the human keeps context, authority and the final decision.
La Palma is the visual setting because its steep terrain, interfaces and limited access make the value of a shared spatial artifact immediately understandable. The product is grounded in public terrain and a historical observed burn scar, while the active incident, wind, spread, risk and response scenario remain explicitly synthetic.
What it does
PyroScan Incident Twin opens a deterministic wildfire exercise board with four sectors, the real outline of La Palma, a public 25 m SITCAN/GRAFCAN terrain hillshade, the corrected Copernicus EMSR671 burn scar from the July 2023 wildfire, animated synthetic fire/smoke/spread cues, modeled attention contours, local annotations, response options and an activity record.
Through six WebMCP site tools, ChatGPT can:
- read the compact current board with separately labeled public-data provenance;
- focus one exercise sector;
- run a 30, 60 or 90-minute bounded wind what-if;
- compare two or three predefined reversible response options;
- add a local route, asset or knowledge annotation;
- stage a visible response plan for review.
Every agent action changes the same interface the human sees. Human annotations affect later scores and appear in the staged plan. A monotonic board version rejects stale proposals. Final approval is deliberately not exposed as a tool and remains in the human interface.
How we built it
The app is a static React 19, TypeScript and Vite application with no backend or API key. A Zustand vanilla store is the shared source of truth for React controls and WebMCP execute callbacks. The incident map is custom SVG with three locally bundled public layers: a simplified OpenStreetMap coastline, a hillshade derived from the SITCAN/GRAFCAN 25 m terrain model, and a projected Copernicus EMSR671 corrected burn-scar geometry. The critical demo therefore has no runtime tile or network dependency. A motion system renders synthetic fire, smoke, embers, wind vectors, scan passes and animated attention contours. The scenario engine is deterministic and uses a small set of synthetic fixtures.
Public context is a first-class part of the WebMCP contract: read_incident_board returns each source, observation date and role with drivesSimulation: false. The interface uses a separate blue historical layer, while the active what-if remains orange and explicitly synthetic. Exact source products, hashes, update dates and derivation steps are committed in docs/PUBLIC_DATA_PROVENANCE.md.
The six tools are registered imperatively with document.modelContext.registerTool in the top-level page. Inputs use strict JSON Schemas with additionalProperties: false, plus independent runtime validation. Read-only and untrusted-content hints describe behavior. One AbortController owns the registration lifecycle. Tests verify registration, shared-state mutations, stale-state rejection, human-only approval and compatibility with current browser callback behavior.
Why WebMCP
Without WebMCP, an agent must infer a complex spatial workflow from labels and pixels or reproduce the whole application inside chat. With WebMCP, the website exposes domain intent — inspect_zone, simulate_spread, compare_response_options — while preserving the normal visual product, current session and human control.
This creates a loop that was previously awkward: the person adds local knowledge on the map; the agent reads it, explores alternatives and stages a structured artifact; the person sees exactly what changed and chooses whether to approve. The value comes from sharing state and complementary roles, not from automating more clicks.
Challenges
- Designing tools that express domain intent without exposing unsafe emergency actions.
- Keeping every agent-driven state change synchronized with all human controls.
- Preventing a plausible proposal from silently surviving after the human changes evidence.
- Making synthetic provenance impossible to miss while still delivering a visually compelling demo.
- Integrating authentic public evidence without implying that historical observations are live inputs or forecasts.
- Supporting an experimental browser API whose runtime callback behavior is slightly looser than its current TypeScript definitions.
Accomplishments
- A complete human-and-agent collaboration loop on one visual artifact.
- Deterministic, browser-only execution with no fragile external dependency.
- Runtime-tested Site Tools discovered and invoked in the ChatGPT/Codex built-in browser.
- Monotonic state lineage, reversible drafts, undo and human-only approval.
- A polished responsive workbench and open-source test suite.
- A geographically authentic La Palma surface with 25 m public terrain, a real historical Copernicus burn scar and cinematic but restrained exercise motion.
What we learned
The strongest WebMCP tools are not wrappers around buttons. They expose a product's real verbs and make side effects visible. We also learned that undo must create a new version rather than restore an old version; otherwise a stale proposal can accidentally become valid again. Finally, human input should visibly change the downstream artifact, not merely influence an invisible score.
What's next
The competition build intentionally keeps the active scenario synthetic and browser-only. A future research version could connect authorized live or exercise datasets, introduce facilitator-authored scenarios, compare team decisions across rehearsals and export after-action reports — while keeping the same human authority, provenance and stale-state safeguards.
Built With
- chatgpt
- codex
- openai
- react
- svg
- typescript
- vite
- vitest
- webmcp
- zustand

Log in or sign up for Devpost to join the conversation.