Official MCP RegistryListed
RepoPilot
Repository evidence for agents before they adopt dependencies, enter codebases, compare, or merge.
First seen 2 Oct 2026. Evidence as of 7 Oct 2026.
8
Tools
From an anonymous probe
1
Source listings
Each with its own history
1
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| analyze_repo | CALL to investigate behavior in public source: supply question and relevant path_hints found from actual usages, for up to four files with commit-pinned line citations. checked_sha selects a commit; base_sha adds before/after excerpts; pr selects a public PR and observes its head's GitHub check runs. source_ranges retrieves missing context at pinned revisions, up to 40 lines per range. Selection is bounded, not exhaustive or proof of compatibility. Without question, returns the cached repository decision brief. Pass exactly one of repo or package. Example: {repo:'expressjs/multer',question:'How are file size limits handled?',path_hints:['lib/make-middleware.js']}. | Read-only |
| check_change_risk | CALL before merging a pull request or after producing a local diff. Returns a deterministic 0-10 change-shape score with receipts for size, spread, missing tests, sensitive paths, hotspots, and blast radius. Pass repo+pr OR diff; repo may accompany diff for cached hotspot context. This prioritizes review and never approves a merge. | Read-only |
| check_dependency | CALL when the user or agent is about to add, upgrade, trust, fork, or deploy an npm package or public GitHub repository. Returns a lean repository-level recommendation, confidence, evidence gaps, CVEs, maintenance, ownership, license, CI/tests, Scorecard, freshness, and next actions. DO NOT use for code navigation. Pass exactly one of repo or package. A favourable result does not validate an exact package version or compatibility. | Read-only |
| compare_repos | CALL when the user is choosing between exactly two dependencies or repositories. Returns the preferred candidate for each use case, material trade-offs, confidence, and evidence gaps. Each target is owner/repo, a GitHub URL, an npm package name, or npm:@scope/pkg. Cached full analyses are preferred; a miss uses bounded live GitHub/OpenSSF evidence with limited confidence and explicit unknowns rather than guessing. | Read-only |
| evaluate_dependency_change | CALL immediately before adding or upgrading an npm dependency. Answers "is this exact version safe to take on" from registry metadata, advisory deltas (for the version itself and for every package in the dependency tree a fresh install resolves to), provenance, license, and repository evidence, and returns blockers, warnings, a recommendation, and a verification plan. Example: {"dependency":"lodash","to_version":"4.17.21"} — every field is top-level, never nested under a "change" key. Only `dependency` is required — omit to_version to evaluate the latest published version, exactly as `npm install <pkg>` would. to_version also accepts a dist-tag ("latest") or a SemVer range ("^4.17.0"); it resolves to one exact version, reported back in change.to_version. Everything RepoPilot can infer is inferred, and every default, repair, and resolution is listed in input_adjustments. Evaluates only; never installs or edits anything. | Read-only |
| get_artifact | CALL before substantial code work in an unfamiliar repository when the agent needs key files, entry points, architecture hypotheses, a reading order, and verify-before-trusting guidance. Returns the cached CLAUDE.md-style artifact or Cursor rules. Do not call again if the artifact is already in context. Takes NO artifact id: name the repository itself. Minimal call: {"repo":"vercel/next.js"}. Pass exactly one of repo or package, each a plain string. | Read-only |
| plan_repo_task | CALL before editing an unfamiliar public repository, or to find where a bug or feature lives. Pass the issue or task text (up to 4000 characters; include the error and expected behaviour) and checked_sha when you know it. Returns files ranked for the task at that commit (provenance task_localizer), the owning layer, a bounded reading order, dependency consumers, test/verification obligations, analyzed-vs-checked SHA relation, evidence provenance, and a short-lived verification contract. To rank files, task text is sent to RepoPilot's model provider; it is never persisted or echoed. Rankings are suggestions: read the files before acting. | Read-only |
| verify_dependency_change | CALL after changing the manifest/lockfile and running local checks. Compares the exact evaluated target with the resolved result and caller-reported proof receipts, checks every version in resolved_changes for advisories (list all packages the lockfile change added or changed), reports missing/failed evidence and residual risk, and labels receipts as caller asserted. It never runs commands or stores diff/check output. | Read-only |
Change history
- verify_dependency_change: input schema changed
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | app.repopilot/repopilot | 2 Oct 2026 | 7 Oct 2026 | 1 |