All skills
openai avatar

/chatgpt-apps

@cb9153a official
by openaiopenai/skills28k stars
1,891

Build, scaffold, refactor, and troubleshoot ChatGPT Apps SDK applications that combine an MCP server and widget UI. Use when Codex needs to design tools, register UI resources, wire the MCP Apps bridge or ChatGPT compatibility APIs, apply Apps SDK metadata or CSP or domain settings, or produce a docs-aligned project scaffold. Prefer a docs-first workflow by invoking the openai-docs skill or OpenAI developer docs MCP tools before generating code.

Use this Skill: https://skilld.dev/gh/openai/skills/chatgpt-apps

This session only. Nothing lands on disk.

referencesrepo-contract-and-validation.md

≈741 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Repo Contract And Validation

Load this reference when scaffolding or reviewing a generated ChatGPT app repo.

The goal is not “files were created.” The goal is “the repo is plausibly runnable and follows a stable working-app contract.”

Minimum Working Repo Contract

Every generated repo should satisfy the relevant parts of this contract.

1. Shape

  • The repo shape matches the chosen archetype.
  • The repo structure is simple enough that a user can identify where the server and widget live.

2. Server

  • There is a clear MCP server entry point.
  • The server exposes /mcp.
  • The server registers tools intentionally.
  • If a UI exists, the server registers a resource/template with the MCP Apps UI MIME type.

3. Tools

  • Each tool maps to one user intent.
  • Descriptions help the model choose the tool.
  • Required annotations are present and accurate.
  • UI-linked tools use _meta.ui.resourceUri.
  • _meta["openai/outputTemplate"] is treated as optional compatibility, not the primary contract.
  • When the app is connector-like, data-only, sync-oriented, or intended for company knowledge or deep research, it implements standard search and fetch tools instead of custom substitutes.

4. Widget

  • The widget initializes the MCP Apps bridge when needed.
  • The widget can receive ui/notifications/tool-result.
  • The widget renders from structuredContent.
  • Interactive widgets use tools/call.
  • Baseline follow-up messaging uses ui/message.
  • window.openai is optional and additive.

5. Local Developer Experience

  • There is a clear way to start the app locally.
  • There is at least one low-cost check command when the stack supports it.
  • The response explains how to connect the app in ChatGPT Developer Mode when relevant.

Validation Ladder

Run the highest level you can without overfitting to a single stack.

Level 0: Static contract review

Check for:

  • chosen archetype is sensible
  • repo shape matches archetype
  • /mcp route is present
  • tool/resource/widget responsibilities are coherent
  • if the app is connector-like or sync-oriented, search and fetch are present with the expected standard shape

Level 1: Syntax or compile checks

Use the stack-appropriate cheapest check available, for example:

  • Python syntax check
  • TypeScript compile check
  • framework-specific lint or build sanity check if already installed

Level 2: Local runtime sanity

If feasible:

  • start the server
  • confirm the health route or /mcp endpoint responds

Level 3: Host loop validation

If feasible:

  • inspect with MCP Inspector
  • test through ChatGPT Developer Mode
  • confirm widget updates after tool results

Reporting Rule

Always say which validation level was reached and what was not run.

That makes the skill more reliable because it separates:

  • “repo shape looks right”
  • “syntax is valid”
  • “server starts”
  • “host integration was actually exercised”

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a robust framework for scaffolding ChatGPT Apps SDK applications, including MCP servers and widget UIs. It includes a built-in scaffolding script and detailed guidance on security best practices like Content Security Policy (CSP) and domain validation.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    4/11 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at cb9153a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Activeupdated 7 months ago

README badge

README badge for openai/skills/chatgpt-apps

Scaffolds ChatGPT Apps SDK implementations with MCP server and widget UI, using a docs-first workflow that references current Apps SDK guidance before generating code. Targets tool planning, MCP server registration, widget scaffolding with the MCP Apps bridge, and validation against the Apps SDK contract. Integrates with the openai-docs skill to keep generated code aligned with official examples and patterns.

Generated from the current SKILL.md.

Does this skill work with Python MCP servers or only Node.js?
The skill supports both. It defaults to Node.js examples and includes a Node fallback scaffold, but explicitly asks about backend language during planning and can scaffold Python MCP servers when requested.
What's the relationship between this skill and the openai-docs skill?
This skill requires a docs-first workflow and must be paired with openai-docs (or the OpenAI docs MCP server directly) before generating code. Always fetch current Apps SDK docs before writing scaffolds.
Does this help with apps already built, or only greenfield projects?
It handles both. The skill can scaffold new apps, refactor existing ones against current docs, validate repos against the minimum working contract, and plan tool surfaces or architecture changes.
What happens if I want to use React for the widget?
The skill can scaffold React widgets. It prefers official OpenAI examples first when they match your stack, or adapts ext-apps React examples, and falls back to vanilla HTML only when no closer match exists.
Can this skill help with submission to the ChatGPT directory?
Yes. The skill includes an `submission-ready` archetype and can generate production-ready scaffolds with tool annotations, CSP, URI versioning, and guides for deployment and submission workflows.

Generated from the current SKILL.md. These answers refresh after source changes.