You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
My contribution adds a new instruction, prompt, agent, skill, workflow, or canvas extension file in the correct directory.
The file follows the required naming convention.
The content is clearly structured and follows the example format.
I have tested my instructions, prompt, agent, skill, workflow, or canvas extension with GitHub Copilot.
I have run npm start and verified that README.md is up to date.
I am targeting the main branch for this pull request.
Description
Refreshes the existing webmcpify skill (added in #2400) from its upstream source, which I maintain: TueJon/webmcpify v0.7.0. The mirrored copy predates the current WebMCP browser surface and verification workflow.
What changes for users of the skill:
No automatic package execution. The mirrored version ran npx -y modern-web-guidance@latest before integrating. The skill now reads the official Chrome WebMCP guides and the CG draft directly; the optional CLI needs an exact reviewed version and the user's approval.
Pinned verification harness. Setup installs exact Playwright and TypeScript versions recorded by the skill and invokes the checked local binary instead of npx, preventing dependency drift or remote package execution during verification.
Scoped browser access. Verification runs in a dedicated test context with approved origins and fixtures, keeps evidence local and redacted, and treats page text and tool output as untrusted data.
Current Chrome execution shape. Verification probes whether the browser takes object or legacy JSON-string input with a side-effect-free tool before invoking any real tool.
Evidence-aware resume. Recorded app files, tool contracts, runtime and browser inputs decide which verification results stay valid. Interrupted mutations are reconciled through a read path before any retry.
Crash-safe mutation checks. A bundled dependency-free host helper durably journals each mutating dispatch and cleanup, reconciles interrupted attempts before retry, and serializes runners through an advisory-lock sidecar.
New bundled references and templates: client surfaces, discovery, re-verification, the visual workbench, a browser compatibility helper, and the durable mutation journal.
The skill folder stays self-contained. Frontmatter keeps the single-quoted description convention and the metadata.source link to upstream.
Type of Contribution
Update to existing instruction, prompt, agent, plugin, skill, workflow, or canvas extension.
Additional Notes
Validation: npm run skill:validate (419/419 valid) and npm start pass; npm start changes only the regenerated webmcpify row in docs/README.skills.md. Upstream npm run check passes (71 tests plus type and syntax checks). Not re-tested inside GitHub Copilot for this refresh.
By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.
✓ [spec-compliance] All 1 skill(s) are spec-compliant.
ℹ️
✓ spec-compliance: All spec checks passed.
ℹ️
✓ [valid-refs] All file references across 1 skill(s) are valid.
ℹ️
✓ valid-refs: All file references resolve to existing files within the skill directory.
ℹ️
1 skill(s) linted, 1 passed
Full linter output
### Linting skills/webmcpify
✅ webmcpify (2/2 checks passed)
✓ [spec-compliance] All 1 skill(s) are spec-compliant.
✓ spec-compliance: All spec checks passed.
✓ [valid-refs] All file references across 1 skill(s) are valid.
✓ valid-refs: All file references resolve to existing files within the skill directory.
1 skill(s) linted, 1 passed
The risk-scan package-exec-command finding is addressed in this v0.7.0 refresh: the verification harness installs exact versions and runs its checked local binary instead of npx.
Addressed both review points: removed the unsupported source metadata, removed the ChatGPT-specific client reference and its remaining links, and merged the latest upstream main. All 425 skills validate, and the generated skill index is clean.
Risk tier:merge-risk:high — Privileged execution, automation, or review-policy change Required to merge: passing submission-gate checks plus 2 approvals from reviewers with write access, including a maintainer with admin or maintain permission.
Why this tier
skills/webmcpify/scripts/workbench.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
Spawns processes or evaluates code in skills/webmcpify/scripts/workbench.mjs
Spawns processes or evaluates code in skills/webmcpify/templates/mutation-journal.js
Spawns processes or evaluates code in skills/webmcpify/templates/mutation-journal.ts
The contributor check succeeded but its result artifact was missing, unreadable, or for another commit · logs
Action needed
Address the changes requested by aaronpowell, then push an update.
🔧 Contributor risk signal hit an automation problem that is not caused by your contribution. Comment /rerun-checks to retry; maintainers are notified if it keeps failing.
Review
Approvals: 0/2
Assigned reviewer: not assigned yet — comment /request-review to ask for one
Review target date: not set
Still needed: 2 more approval(s); an approval from a maintainer with admin or maintain permission; resolution of changes requested by aaronpowell
The core-maintainers pool is not staffed yet; an approver with admin or maintain permission is required instead.
Commands
Command
Who
What it does
/rerun-checks
PR author, maintainers
Re-runs failed or incomplete checks and re-evaluates this gate
/request-review
PR author, maintainers
Asks the review rotation to assign a reviewer (adds needs-reviewer)
Updated for 0596ffe · This comment is maintained automatically — see submission gate docs.
This branch has not been deployed
No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request Checklist
npm startand verified thatREADME.mdis up to date.mainbranch for this pull request.Description
Refreshes the existing
webmcpifyskill (added in #2400) from its upstream source, which I maintain: TueJon/webmcpify v0.7.0. The mirrored copy predates the current WebMCP browser surface and verification workflow.What changes for users of the skill:
npx -y modern-web-guidance@latestbefore integrating. The skill now reads the official Chrome WebMCP guides and the CG draft directly; the optional CLI needs an exact reviewed version and the user's approval.npx, preventing dependency drift or remote package execution during verification.The skill folder stays self-contained. Frontmatter keeps the single-quoted
descriptionconvention and themetadata.sourcelink to upstream.Type of Contribution
Additional Notes
Validation:
npm run skill:validate(419/419 valid) andnpm startpass;npm startchanges only the regeneratedwebmcpifyrow indocs/README.skills.md. Upstreamnpm run checkpasses (71 tests plus type and syntax checks). Not re-tested inside GitHub Copilot for this refresh.By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.