Atlas / MCP servers / openai / Apps SDK Examples Gallery

Apps SDK Examples GallerySAFE

mcp/openai/apps-sdk-examples-gallery

Example apps for the Apps SDK

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
7 7r · 0w · 0d
Transport
sse · streamable-http
License
MIT
Stars
2,339
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE)

This repository showcases example UI components to be used with the Apps SDK, as well as example MCP servers that expose a collection of components as tools. It is meant to be used as a starting point and source of inspiration to build your own apps for ChatGPT.

Note: If you are on Chrome and have recently updated to version 142, you will need to disable the `local-network-access` flag to see the widget UI.

How to disable it:

  1. Go to chrome://flags/
  2. Find #local-network-access-check
  3. Set it to Disabled

⚠️ Note 🚨 Make sure to restart Chrome after changing this flag for the update to take effect.

MCP + Apps SDK overview

The Model Context Protocol (MCP) is an open specification for connecting large language model clients to external tools, data, and user interfaces. An MCP server exposes tools that a model can call during a conversation and returns results according to the tool contracts. Those results can include extra metadata—such as inline HTML—that the Apps SDK uses to render rich UI components (widgets) alongside assistant messages.

Within the Apps SDK, MCP keeps the server, model, and UI in sync. By standardizing the wire format, authentication, and metadata, it lets ChatGPT reason about your connector the same way it reasons about built-in tools. A minimal MCP integration for Apps SDK implements three capabilities:

  1. List tools – Your server advertises the tools it supports, including their JSON Schema input/output contracts and optional annotations (for example, readOnlyHint).
  2. Call tools – When a model selects a tool, it issues a call_tool request with arguments that match the user intent. Your server executes the action and returns structured content the model can parse.
  3. Return widgets –
Read from source at commit 73c52aca9e6cOBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add pizzaz-mcp-node --env AUTHORIZATION_SERVER_URL=${AUTHORIZATION_SERVER_URL} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "pizzaz-mcp-node": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AUTHORIZATION_SERVER_URL": "${AUTHORIZATION_SERVER_URL}"
      }
    }
  }
}
03

Exposed tools (7)

7 read · 0 write · 0 destructive.

ToolRiskDescription
AvocadosreadPerfectly ripe
BreadreadFresh and toasty
EggsreadBreakfast basics
TomatoesreadJuicy and bright
kitchen-sink-refreshreadLightweight echo tool called from the widget via callTool.
kitchen-sink-showreadReturns the widget template with the provided message.
kitchen_sink_refreshread# Simple echo tool used by the widget via window.openai.callTool.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cards_against_ai_server_node/src/shared-types.ts:13
} from "../../src/cards-against-ai/types.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
authenticated_server_python/README.md:95
The server listens on `http://127.0.0.1:8000` and exposes the standard MCP endpoint at `GET /mcp`.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
pizzaz_server_python/README.md:31
This boots a FastAPI app with uvicorn on `http://127.0.0.1:8000` (equivalently `uvicorn pizzaz_server_python.main:app --port 8000`). The endpoints mirror the Node demo:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
solar-system_server_python/README.md:31
This boots a FastAPI app with uvicorn on `http://127.0.0.1:8000` (equivalently
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
authenticated_server_python/requirements.txt
fastmcp, mcp, pydantic, python-dotenv, uvicorn
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
cards_against_ai_server_node/package.json
@modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, cors, dotenv, express, zod, @types/cors, @types/express
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
kitchen_sink_server_node/package.json
@modelcontextprotocol/sdk, zod, tsx, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
kitchen_sink_server_python/requirements.txt
fastapi, mcp, uvicorn
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp_app_basics_node/package.json
@modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, cors, express, zod, @types/cors, @types/express, tsx
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
shopping_cart_python/README.md:3
This example shows how to thread state across conversation turns by pairing `_meta["widgetSessionId"]` with `window.openai.widgetState`. The Python server ships a simple `add_to_cart` tool as an examp
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
ngrok-v3-stable-linux-amd64.tgz
ngrok-v3-stable-linux-amd64.tgz
Why it matters. 11382588 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
src/cards-against-ai/assets/card-back-pattern.png
src/cards-against-ai/assets/card-back-pattern.png
Why it matters. 1169927 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha 73c52aca9e6cfull audit observations/trust-audit/mcp-server/openai__apps-sdk-examples-gallery.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2373c52aca9e6cSAFEB89source changed, verdict held
06

Questions

What is the Apps SDK Examples Gallery MCP server?

Example apps for the Apps SDK

What tools does Apps SDK Examples Gallery expose?

7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Apps SDK Examples Gallery safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Apps SDK Examples Gallery need?

It reads AUTHORIZATION_SERVER_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Apps SDK Examples Gallery run?

It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as pizzaz-mcp-node at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (73c52aca9e6c), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement