MCP server for managing Copilot scheduled jobs, session storage, migration, and related workspace operations
The Narnia MCP server demonstrates solid definition quality with 27 well-named tools using consistent verb_noun naming patterns (export_, list_, get_, create_, update_, delete_, preview_, search_, migrate_, scan_). All tools have descriptions (ranging 50 - 300+ chars, baseline 194). Schemas are explicit with typed parameters and descriptions. However, several critical gaps prevent a higher score: (1) Output schemas are not documented in the visible code, tools return JSON strings serialized via `Serialize()` methods, but the response structure is opaque to the LLM. (2) No input validation guidance or error recovery hints visible in descriptions. (3) Complex nested input types (SchedulePackageJobMcpInput, SchedulePackageDependencyMcpInput) lack inline schema documentation. (4) No enum constraints visible for string parameters like 'profile' ('transfer'|'share') or 'cadenceKind' ('daily'|'weekly'|'monthly'), these are validated server-side but not declared as enums in the schema. (5) Some parameter descriptions lack format constraints (e.g., 'time' as 24-hour HH:mm is explained in create_schedule but should appear in update_schedule too).
Builds a versioned schedule package from canonical job definitions reconstructed from selected non-Narnia tasks. This does not register or modify any scheduled task.
Creates a Narnia-owned scheduled Copilot job. Narnia generates a self-contained wrapper script that runs `copilot -p` with the given prompt on the given cadence, and never edits the user's own scripts. Prefer register=true so the Windows scheduled task is created immediately; use register=false only to hand back the generated script and registration command for the caller to run manually. The prompt IS the job: name the skill to invoke and say exactly what to do with its output (e.g. write a file, then call a specific script for any deterministic follow-up like a database write or an email) -- there is no hidden wrapper behavior beyond what the prompt says. Prefer a self-contained prompt/skill (one that resolves its own secrets, e.g. from a repo .env) over relying on injected environment variables, since the job runs as a plain `copilot -p` with no pre-injected environment.
Permanently deletes validated local Copilot session data through GitHub.Copilot.SDK and can archive successful deletions in Narnia. Synced GitHub copies and Narnia references remain. Always preview first.
Deletes a Narnia-owned scheduled job and its Windows scheduled task. This is irreversible.
Output schemas not documented. Tools serialize responses to JSON strings (via `Serialize()` methods) but the response structure is invisible to the LLM. LLMs cannot infer what fields to expect or plan downstream tool calls.
Enum constraints not declared in schema. Parameters like 'profile' ('transfer'|'share'), 'cadenceKind' ('daily'|'weekly'|'monthly'), and 'confirmMigration' (boolean) are validated server-side but not exposed as enum/const in the input schema. LLMs cannot see valid options and may hallucinate invalid values.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 69 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 58 | - | v1 |
Exports selected Narnia scheduled jobs as one versioned JSON package. Use profile 'transfer' to retain non-secret source path hints for another machine you control, or 'share' to remove source-local hints for another user. Generated wrappers, logs, task XML, databases, and secrets are never included.
Gets a single Narnia-cataloged scheduled job by id, including its full prompt and cadence. Use list_schedules first to find the id, or to see live task status.
Get all checkpoints for a session. Checkpoints contain structured summaries including overview, history, files changed, and next steps.
Get full details for a specific session including metadata and statistics.
Reads a bounded chunk of the Narnia-owned recovery packet associated with a migrated source or successor session.
Gets cached local Copilot session-storage totals, scan health, and the 25 largest local sessions. Sizes are logical bytes and do not include reparse targets.
Get conversation turns (messages) for a session. Returns paginated user/assistant message pairs.
Get read-only Copilot workspace metadata for a session: its Copilot-managed name, whether the user named it, git root, and session artifact files.
Lists the Git worktrees a session could launch into and reports where its Narnia branch override disagrees with real Git state. Read-only: no branch is ever checked out. Use this to find sessions that look separated by their branch label but actually share one working tree.
Imports a package only after a current successful preview. Every destination job receives a new local id and is registered disabled; this tool never enables, runs, auto-installs dependencies, clones repositories, or disables source tasks.
Lists the most recently updated Copilot CLI sessions. Use this to find sessions to resume after a computer restart.
Lists every Narnia-cataloged scheduled Copilot job joined to its live Windows Task Scheduler status (state, last run, next run), plus any tasks found in Narnia's scheduler folder that are not cataloged.
List visible sessions that were started in a specific working directory. Matching follows the operating system's path casing rules and ignores a trailing directory separator.
List visible sessions whose effective remote repository exactly matches an owner/repository value. Narnia repository overrides are applied.
Archives a broken event stream and asks Copilot SDK to reseed the same session ID and folder with a recovery handoff. Chronicle is never modified directly.
Dry-runs local session deletion. Returns allowed, protected, and hard-blocked sessions plus estimated logical bytes. No data is deleted.
Inspects a schedule package against this computer without changing Narnia or Task Scheduler. Returns required path bindings, task-name conflicts, prior imports, timezone warnings, dependency findings, rendered prompts, and a preview fingerprint required by import_schedule_package.
Previews whether a Copilot session can be migrated into a valid successor, including recoverable turns, checkpoints, tasks, and Narnia references. Does not modify either session.
Starts a scheduled job's Windows scheduled task immediately, out of band from its normal cadence. Use this to test a job right after creating or updating it.
Queues a background metadata-only scan of local Copilot session-state storage.
Search visible sessions by Copilot name, Narnia alias, conversation turns, checkpoints, and workspace artifacts. Name and alias matches rank before indexed content. Archived sessions are excluded. This does not filter repository or working-directory metadata; use the exact list tools for those fields.
Enables or disables a scheduled job's Windows scheduled task without deleting it. Prefer this over delete_schedule when a job might be needed again later.
Updates an existing Narnia-owned job, regenerates its wrapper script, and re-registers its Windows scheduled task in place. Every field is replaced -- call get_schedule first and pass through anything you don't want to change.
No error handling guidance in descriptions. Tools return validation errors as plain strings (e.g., 'Error: profile must be...') but descriptions do not explain error cases, recovery steps, or which errors are retryable. LLMs cannot plan recovery.
Complex nested input types lack inline schema documentation. SchedulePackageJobMcpInput, SchedulePackageDependencyMcpInput, and SchedulePackageBindingMcpInput are used in build_schedule_package, preview_schedule_package, and import_schedule_package, but their internal field schemas are not visible in the MCP tool definition.
Inconsistent parameter description detail. create_schedule explains 'time' format (24-hour HH:mm), but update_schedule and other tools with similar parameters do not repeat this constraint. LLMs may infer different formats in different contexts.
No pagination guidance for list tools. list_schedules, list_sessions_by_repository, list_sessions_by_cwd return unbounded results. No limit, offset, or page size parameters visible. Large result sets risk context window exhaustion.
Destructive operations lack confirmation pattern. delete_schedule and delete_local_sessions have 'DESTRUCTIVE' risk annotation but no dry-run or explicit confirmation requirement documented in the description (delete_local_sessions has confirmLocalDeletion param, but delete_schedule does not).
Tool annotation hints missing. According to the server metadata, toolAnnotations=false. readOnlyHint, destructiveHint, and idempotentHint should be declared in the schema for tools like list_*, get_*, create_*, delete_*. This forces LLMs to infer safety from names alone.