ZBS Index What actually exists in applied AI, with the source next to it

mcp server

RepoPilot

Repository evidence for agents before they adopt dependencies, enter codebases, compare, or merge.

Description as published by the maintainer. Source

  • version 2.0.1
  • active

active — Registry entry last updated 2026-08-02.

What this server can do

8 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.

analyze_repo(repo, package)
CALL when entering an unfamiliar repository or deciding whether to depend on, fork, learn from, or deploy it. Returns a concise four-use-case brief, watchouts, evidence confidence, architecture summary, freshness, and next actions without dumping the full generated artifact. Use get_artifact when file-level orientation is needed. Pass exactly one of repo or package.
check_change_risk(pr, diff, repo, files, proofs, base_sha, head_sha, contract_id)
CALL before merging a pull request or after producing a local diff. Returns a deterministic 0-10 change-shape score with receipts for size, spread, missing tests, sensitive paths, hotspots, and blast radius. Pass repo+pr OR diff; repo may accompany diff for cached hotspot context. This prioritizes review and never approves a merge.
check_dependency(repo, package)
CALL when the user or agent is about to add, upgrade, trust, fork, or deploy an npm package or public GitHub repository. Returns a lean repository-level recommendation, confidence, evidence gaps, CVEs, maintenance, ownership, license, CI/tests, Scorecard, freshness, and next actions. DO NOT use for code navigation. Pass exactly one of repo or package. A favourable result does not validate an exact package version or compatibility.
compare_repos(a, b)
CALL when the user is choosing between exactly two dependencies or repositories. Returns the preferred candidate for each use case, material trade-offs, confidence, and evidence gaps. Each target is owner/repo, a GitHub URL, an npm package name, or npm:@scope/pkg. Cached full analyses are preferred; a miss uses bounded live GitHub/OpenSSF evidence with limited confidence and explicit unknowns rather than guessing. Required: a, b.
evaluate_dependency_change(change, intent, project, policy_profile)
CALL immediately before adding or upgrading an npm dependency. Requires an exact published target version plus a bounded, source-free project snapshot. Applies the named permissive, balanced (default), or strict team policy to advisories, provenance attestations, and npm install-hook names. Checks exact metadata, Node/peer/license compatibility, repository evidence, and returns blockers plus a verification plan. This tool evaluates; it never installs or edits anything. Required: change, project.
get_artifact(repo, format, package)
CALL before substantial code work in an unfamiliar repository when the agent needs key files, entry points, architecture hypotheses, a reading order, and verify-before-trusting guidance. Returns the cached CLAUDE.md-style artifact or Cursor rules. Do not call again if the artifact is already in context. Pass exactly one of repo or package.
plan_repo_task(repo, task, intent, package, max_files, path_hints, checked_sha)
CALL before editing an unfamiliar public repository. Returns a bounded reading order, relevant files, dependency consumers, test/verification obligations, analyzed-vs-checked SHA relation, evidence provenance, and a short-lived verification contract. Task text is used only for bounded local matching and is never persisted raw. Required: task.
verify_dependency_change(diff, after, checks, evaluation)
CALL after changing the manifest/lockfile and running local checks. Compares the exact evaluated target with the resolved result and caller-reported proof receipts, reports missing/failed evidence and residual risk, and labels receipts as caller asserted. It never runs commands or stores diff/check output. Required: evaluation, after, checks.

Last successful function declaration observed on . Source: https://repopilot.app/api/mcp. We list what the server declared; we do not call any of these functions.

Endpoint status observed on . Source: https://repopilot.app/api/mcp.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
Latest published version 2.0.1 Latest version string the maintainer published to the registry. as of fetch Model Context Protocol
Registry record last updated 2026-08-02 When the registry record was last updated by its maintainer. point in time Model Context Protocol
First listed in the MCP Registry 2026-08-02 Date this server was first published to the official MCP Registry. Not a usage or quality measure. point in time Model Context Protocol
mcp tools declared 8 tools Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. as of probe repopilot.app
mcp endpoint status ok The server listed 8 functions when asked. as of probe repopilot.app

Where to get it

This record as data

Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.

GET /api/v1/entries/mcp_server.json

Sources

  1. Official MCP Registry — Model Context Protocol, observed , trust tier 1.
  2. Tools declared by the MCP server at https://repopilot.app/api/mcp — repopilot.app, observed , trust tier 1.