Skip to content

Refresh webmcpify skill to v0.7.0 🤖🤖🤖 - #3420

Open
TueJon wants to merge 5 commits into
github:mainfrom
TueJon:refresh-webmcpify-v0.6.0
Open

TueJon wants to merge 5 commits into
github:mainfrom
TueJon:refresh-webmcpify-v0.6.0

Conversation

@TueJon

@TueJon TueJon commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Pull Request Checklist

  • I have read and followed the CONTRIBUTING.md guidelines.
  • I have read and followed the Guidance for submissions involving paid services.
  • My contribution adds a new instruction, prompt, agent, skill, workflow, or canvas extension file in the correct directory.
  • The file follows the required naming convention.
  • The content is clearly structured and follows the example format.
  • I have tested my instructions, prompt, agent, skill, workflow, or canvas extension with GitHub Copilot.
  • I have run npm start and verified that README.md is up to date.
  • I am targeting the main branch for this pull request.

Description

Refreshes the existing webmcpify skill (added in #2400) from its upstream source, which I maintain: TueJon/webmcpify v0.7.0. The mirrored copy predates the current WebMCP browser surface and verification workflow.

What changes for users of the skill:

  • No automatic package execution. The mirrored version ran npx -y modern-web-guidance@latest before integrating. The skill now reads the official Chrome WebMCP guides and the CG draft directly; the optional CLI needs an exact reviewed version and the user's approval.
  • Pinned verification harness. Setup installs exact Playwright and TypeScript versions recorded by the skill and invokes the checked local binary instead of npx, preventing dependency drift or remote package execution during verification.
  • Scoped browser access. Verification runs in a dedicated test context with approved origins and fixtures, keeps evidence local and redacted, and treats page text and tool output as untrusted data.
  • Current Chrome execution shape. Verification probes whether the browser takes object or legacy JSON-string input with a side-effect-free tool before invoking any real tool.
  • Evidence-aware resume. Recorded app files, tool contracts, runtime and browser inputs decide which verification results stay valid. Interrupted mutations are reconciled through a read path before any retry.
  • Crash-safe mutation checks. A bundled dependency-free host helper durably journals each mutating dispatch and cleanup, reconciles interrupted attempts before retry, and serializes runners through an advisory-lock sidecar.
  • New bundled references and templates: client surfaces, discovery, re-verification, the visual workbench, a browser compatibility helper, and the durable mutation journal.

The skill folder stays self-contained. Frontmatter keeps the single-quoted description convention and the metadata.source link to upstream.


Type of Contribution

  • Update to existing instruction, prompt, agent, plugin, skill, workflow, or canvas extension.

Additional Notes

Validation: npm run skill:validate (419/419 valid) and npm start pass; npm start changes only the regenerated webmcpify row in docs/README.skills.md. Upstream npm run check passes (71 tests plus type and syntax checks). Not re-tested inside GitHub Copilot for this refresh.


By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.

@TueJon
TueJon requested a review from aaronpowell as a code owner September 19, 2026 15:40
@github-actions github-actions Bot added the skills PR touches skills label Sep 19, 2026
@github-actions

github-actions Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

🔒 PR Risk Scan Results

Scanned 20 changed file(s).

Severity Count
🔴 High 0
🟠 Medium 0
ℹ️ Info 9
Severity Rule File Line Match
ℹ️ skill-script-touched skills/webmcpify/scripts/workbench.mjs 1 skills/webmcpify/scripts/workbench.mjs
ℹ️ skill-script-touched skills/webmcpify/templates/mutation-journal.js 1 skills/webmcpify/templates/mutation-journal.js
ℹ️ skill-script-touched skills/webmcpify/templates/mutation-journal.ts 1 skills/webmcpify/templates/mutation-journal.ts
ℹ️ skill-script-touched skills/webmcpify/templates/webmcp-compat.js 1 skills/webmcpify/templates/webmcp-compat.js
ℹ️ skill-script-touched skills/webmcpify/templates/webmcp-workbench.js 1 skills/webmcpify/templates/webmcp-workbench.js
ℹ️ skill-script-touched skills/webmcpify/templates/webmcp.d.ts 1 skills/webmcpify/templates/webmcp.d.ts
ℹ️ skill-script-touched skills/webmcpify/templates/webmcp.spec.ts 1 skills/webmcpify/templates/webmcp.spec.ts
ℹ️ skill-script-touched skills/webmcpify/templates/webmcpify.js 1 skills/webmcpify/templates/webmcpify.js
ℹ️ skill-script-touched skills/webmcpify/templates/webmcpify.ts 1 skills/webmcpify/templates/webmcpify.ts

This is an automated soft-gate report. Findings indicate review targets and do not block merge by themselves.

@github-actions

Copy link
Copy Markdown
Contributor

🔍 Vally Lint Results

✅ All checks passed

Scope Checked
Skills 1
Agents 0
Total 1
Severity Count
❌ Errors 0
⚠️ Warnings 0
ℹ️ Advisories 0

Summary

Level Finding
ℹ️ ✅ webmcpify (2/2 checks passed)
ℹ️ ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
ℹ️ ✓ spec-compliance: All spec checks passed.
ℹ️ ✓ [valid-refs] All file references across 1 skill(s) are valid.
ℹ️ ✓ valid-refs: All file references resolve to existing files within the skill directory.
ℹ️ 1 skill(s) linted, 1 passed
Full linter output
### Linting skills/webmcpify
✅ webmcpify (2/2 checks passed)
    ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
        ✓ spec-compliance: All spec checks passed.
    ✓ [valid-refs] All file references across 1 skill(s) are valid.
        ✓ valid-refs: All file references resolve to existing files within the skill directory.

1 skill(s) linted, 1 passed

@TueJon TueJon changed the title Refresh webmcpify skill to v0.6.0 🤖🤖🤖 Refresh webmcpify skill to v0.7.0 🤖🤖🤖 Sep 19, 2026
@TueJon

TueJon commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

The risk-scan package-exec-command finding is addressed in this v0.7.0 refresh: the verification harness installs exact versions and runs its checked local binary instead of npx.

Comment thread skills/webmcpify/SKILL.md
license: MIT
metadata:
source: https://github.com/TueJon/webmcpify
tags:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't part of the supported frontmatter in the skills spec and should be removed.

Comment thread skills/webmcpify/references/client.md Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't relevant to GitHub Copilot.

@TueJon

TueJon commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Addressed both review points: removed the unsupported source metadata, removed the ChatGPT-specific client reference and its remaining links, and merged the latest upstream main. All 425 skills validate, and the generated skill index is clean.

@github-actions github-actions Bot added merge-risk:high requires-submitter-fixes Submission has quality-gate findings that submitter must fix before maintainer review labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

🚦 Submission status: 🛠️ Requires submitter fixes

Risk tier: merge-risk:high — Privileged execution, automation, or review-policy change
Required to merge: passing submission-gate checks plus 2 approvals from reviewers with write access, including a maintainer with admin or maintain permission.

Why this tier
  • skills/webmcpify/scripts/workbench.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • Spawns processes or evaluates code in skills/webmcpify/scripts/workbench.mjs
  • Spawns processes or evaluates code in skills/webmcpify/templates/mutation-journal.js
  • Spawns processes or evaluates code in skills/webmcpify/templates/mutation-journal.ts

Automated checks

Check Status Details
Line endings ✅ Passed Passed · logs
Spelling ✅ Passed Passed · logs
Generated README consistency ✅ Passed Passed · logs
Skill validation ⏳ Pending Waiting for the check to start
Skill lint (vally) ✅ Passed Passed · logs
Risk scan ✅ Passed Passed · logs
Contributor reputation ✅ Passed Passed · logs
Duplicate resource scan ✅ Passed Passed · logs
PR quality signal ⏭️ Skipped Skipped by its workflow · logs
Contributor risk signal 🔧 Infrastructure failure The contributor check succeeded but its result artifact was missing, unreadable, or for another commit · logs

Action needed

  • Address the changes requested by aaronpowell, then push an update.
  • 🔧 Contributor risk signal hit an automation problem that is not caused by your contribution. Comment /rerun-checks to retry; maintainers are notified if it keeps failing.

Review

  • Approvals: 0/2
  • Assigned reviewer: not assigned yet — comment /request-review to ask for one
  • Review target date: not set
  • Still needed: 2 more approval(s); an approval from a maintainer with admin or maintain permission; resolution of changes requested by aaronpowell
  • The core-maintainers pool is not staffed yet; an approver with admin or maintain permission is required instead.

Commands

Command Who What it does
/rerun-checks PR author, maintainers Re-runs failed or incomplete checks and re-evaluates this gate
/request-review PR author, maintainers Asks the review rotation to assign a reviewer (adds needs-reviewer)

Updated for 0596ffe · This comment is maintained automatically — see submission gate docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk:high requires-submitter-fixes Submission has quality-gate findings that submitter must fix before maintainer review skills PR touches skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants