Atlas / Skills / alpic-ai / Chatgpt App Builder

Chatgpt App BuilderBLOCK

skills/alpic-ai/chatgpt-app-builder

Skybridge is a full-stack TypeScript framework for MCP Apps and ChatGPT Apps. Type-safe. React-powered. Platform-agnostic.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
3 documented
License
MIT
Stars
2,150
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Manual evaluations for the chatgpt-app-builder skill.

Format

Each eval file is a JSON array:

[
{
"query": "User input to test",
"expected_behavior": "OUTCOME. What the response should do."
}
]

Running Evals

In Claude Code:

Run the evals in evals/.json. For each query, spawn a Sonnet agent with the relevant skill context and compare the response against expected_behavior. Feed the whole SKILL.md and evaluated reference file without compression. Report pass/fail for each.
Read from source at commit 83def994089fOBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

claude mcp add chrome-devtools --scope user -- \
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
cursormentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: chatgpt-app-builder
description: |
  Guide developers through creating and updating ChatGPT plugins.
  Covers the full lifecycle: brainstorming ideas against UX guidelines, bootstrapping projects, implementing tools/views, debugging, running dev servers, deploying and connecting plugins to ChatGPT.
  Use when a user wants to create or update a ChatGPT plugin (formerly called a ChatGPT app) / MCP server for ChatGPT, or use the Skybridge framework.
---

# Creating Plugins For LLMs

ChatGPT plugins are conversational experiences that extend ChatGPT through tools and custom UI views. They're built as MCP servers invoked during conversations.

⚠️ The plugin is consumed by two users at once: the **human** and the **ChatGPT LLM**. They collaborate through the view—the human interacts with it, the LLM sees its state. Internalize this before writing code: the view is your shared surface.

SPEC.md keeps track of the plugin's requirements and design decisions. Keep it up to date as you work on the plugin.

**Building an ecommerce plugin?** → Read [ecommerce.md](references/ecommerce.md) first.

**No SPEC.md?** → Read [discover.md](references/discover.md) first. Nothing else until SPEC.md exists.

**SPEC.md exists?** → Read SPEC.md, then follow [architecture.md](references/architecture.md) to design the change. Update SPEC.md, then read the relevant Implementation references below before writing code.

**Migrating from Skybridge `< 0.36.x`?** → Read [migrate-to-v1.md](references/migrate-to-v1.md) first. Users may reference `skybridge >= 0.36.x` as v1.

**Migrating from Skybridge `1.x` to `2.x`?** → Fetch the [v2.0.0 release notes](https://github.com/alpic-ai/skybridge/releases/tag/v2.0.0) first and follow them.

## Setup

1. **Copy template** → [copy-template.md](references/copy-template.md): when starting a new project with ready SPEC.md
2. **Run locally** → [run-locally.md](references/run-locally.md): when ready to test, need dev server or ChatGPT connection
3. **Evals** → [evals.md](references/evals.md): when checking that a real model reaches the right tools from natural prompts, in a test

## Architecture

Design or evolve UX flows and API shape → [architecture.md](references/architecture.md)

## Implementation

- **Fetch and render data** → [fetch-and-render-data.md](references/fetch-and-render-data.md): when implementing server handlers and view data fetching
- **State and context** → [state-and-context.md](references/state-and-context.md): when persisting view UI state and updating LLM context
- **Prompt LLM** → [prompt-llm.md](references/prompt-llm.md): when view needs to trigger LLM response
- **UI guidelines** → [ui-guidelines.md](references/ui-guidelines.md): display modes, layout constraints, theme, device, and locale
- **External links** → [open-external-links.md](references/open-external-links.md): when redirecting to external URLs or setting "open in app" target
- **OAuth** → [oauth.md](references/oauth.md): when tools need user authentication to access user-specific data
- **Assets and styling** → [assets-and-styling.md](references/assets-and-styling.md): when adding images, fonts or CSS to views
- **CSP** → [csp.md](references/csp.md): when declaring allowed domains for fetch, assets, redirects, or iframes
- **Events** → [events.md](references/events.md): when ChatGPT should react to activity in the app without the user, such as new comments or incidents
- **OpenAI MCP extensions** → [openai-extensions.md](references/openai-extensions.md): when the view should open from the ChatGPT sidebar, a conversation side panel, a file, or a deep link, or use ChatGPT at-mentions, titled messages or local files

## Deploy

- **Ship to production** → [deploy.md](references/deploy.md): when ready to deploy via Alpic
- **Publish to ChatGPT Directory** → [publish.md](references/publish.md): when ready to submit for review

Full API docs: [https://docs.skybridge.tech/api-reference.md](https://docs.skybridge.tech/api-reference.md)

Release notes & changelog: [https://skybridge.tech/changelog.md](https://skybridge.tech/changelog.md)
05

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
references/ecommerce.md:260
The view layer under `src/components/` and `src/views/`, built on the design system. Preview any component in Ladle (`{pm} run ladle`; each `*.stories.tsx` is a story); the devtools emulator shows a v
Why it matters. asks the agent to act without the user's knowledge
MEDIUMInventory / provenance · inv.symlink · CWE-1104
skills/mcp-app-builder/references
skills/mcp-app-builder/references
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
skills/skybridge/references
skills/skybridge/references
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
references/evals.md:34
`start` serves the app in process: no port, no HTTP server. This only works because `src/server.ts` exports the app and `src/index.ts` runs it; never put `run()` in `server.ts`. Each `send` is one use
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 83def994089ffull audit observations/trust-audit/skill/alpic-ai__chatgpt-app-builder.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-0883def994089fBLOCKD69first audit
07

Questions

What does the Chatgpt App Builder skill do?

Skybridge is a full-stack TypeScript framework for MCP Apps and ChatGPT Apps. Type-safe. React-powered. Platform-agnostic.

Is Chatgpt App Builder safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Chatgpt App Builder access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Chatgpt App Builder work with?

Its documentation mentions claude-code, codex and cursor. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (83def994089f), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement