Mcp App BuilderCAUTION
Skybridge is a full-stack TypeScript framework for MCP Apps and ChatGPT Apps. Type-safe. React-powered. Platform-agnostic.
Overview
Skybridge is a full-stack TypeScript framework for MCP Apps and ChatGPT Apps. Type-safe. React-powered. Platform-agnostic.
83def994089fOBSERVED · 2026-10-08What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: mcp-app-builder description: | Guide developers through creating and updating MCP Apps. Covers the full lifecycle: brainstorming ideas against UX guidelines, bootstrapping projects, implementing tools/views, debugging, running dev servers, deploying and connecting apps to ChatGPT. Use when a user wants to create or update a MCP App, MCP server or use the Skybridge framework. --- # Creating MCP Apps Those are conversational experiences that extend AI assistants through tools and custom UI views. They're built as MCP servers invoked during conversations. ⚠️ The app is consumed by two users at once: the **human** and the **AI Assistant LLM**. They collaborate through the view—the human interacts with it, the LLM sees its state. Internalize this before writing code: the view is your shared surface. SPEC.md keeps track of the app's requirements and design decisions. Keep it up to date as you work on the app. **No SPEC.md?** → Read [discover.md](references/discover.md) first. Nothing else until SPEC.md exists. **SPEC.md exists?** → Read SPEC.md, then follow [architecture.md](references/architecture.md) to design the change. Update SPEC.md, then read the relevant Implementation references below before writing code. **Migrating from Skybridge `< 0.36.x`?** → Read [migrate-to-v1.md](references/migrate-to-v1.md) first. Users may reference `skybridge >= 0.36.x` as v1. **Migrating from Skybridge `1.x` to `2.x`?** → Fetch the [v2.0.0 release notes](https://github.com/alpic-ai/skybridge/releases/tag/v2.0.0) first and follow them. **Building an ecommerce app?** → Read [ecommerce.md](references/ecommerce.md) first. ## Setup 1. **Copy template** → [copy-template.md](references/copy-template.md): when starting a new project with ready SPEC.md 2. **Run locally** → [run-locally.md](references/run-locally.md): when ready to test, need dev server or ChatGPT/Claude connection 3. **Evals** → [evals.md](references/evals.md): when checking that a real model reaches the right tools from natural prompts, in a test ## Architecture Design or evolve UX flows and API shape → [architecture.md](references/architecture.md) ## Implementation - **Fetch and render data** → [fetch-and-render-data.md](references/fetch-and-render-data.md): when implementing server handlers and view data fetching - **State and context** → [state-and-context.md](references/state-and-context.md): when persisting view UI state and updating LLM context - **Prompt LLM** → [prompt-llm.md](references/prompt-llm.md): when view needs to trigger LLM response - **UI guidelines** → [ui-guidelines.md](references/ui-guidelines.md): display modes, layout constraints, theme, device, and locale - **External links** → [open-external-links.md](references/open-external-links.md): when redirecting to external URLs or setting "open in app" target - **Download file** → [download-file.md](references/download-file.md): when saving content to the user's filesystem - **OAuth** → [oauth.md](references/oauth.md): when tools need user authentication to access user-specific data - **CSP** → [csp.md](references/csp.md): when declaring allowed domains for fetch, assets, redirects, or iframes ## Deploy - **Ship to production** → [deploy.md](references/deploy.md): when ready to deploy via Alpic - **Publish to ChatGPT/Claude Directories** → [publish.md](references/publish.md): when ready to submit for review Full API docs: [https://docs.skybridge.tech/api-reference.md](https://docs.skybridge.tech/api-reference.md) Release notes & changelog: [https://skybridge.tech/changelog.md](https://skybridge.tech/changelog.md)
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
skills/mcp-app-builder/references
skills/skybridge/references
CLAUDE.md
Gates applied: no_behavioural_pass.
83def994089ffull audit observations/trust-audit/skill/alpic-ai__mcp-app-builder.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 83def994089f | CAUTION | B | 89 | first audit |
Questions
What does the Mcp App Builder skill do?
Skybridge is a full-stack TypeScript framework for MCP Apps and ChatGPT Apps. Type-safe. React-powered. Platform-agnostic.
Is Mcp App Builder safe to install?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Mcp App Builder access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (83def994089f), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.