Atlas / Skills / alpic-ai / Mcp App Builder

Mcp App BuilderCAUTION

skills/alpic-ai/mcp-app-builder

Skybridge is a full-stack TypeScript framework for MCP Apps and ChatGPT Apps. Type-safe. React-powered. Platform-agnostic.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
2,150
01

Overview

Skybridge is a full-stack TypeScript framework for MCP Apps and ChatGPT Apps. Type-safe. React-powered. Platform-agnostic.

Read from source at commit 83def994089fOBSERVED · 2026-10-08
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: mcp-app-builder
description: |
  Guide developers through creating and updating MCP Apps.
  Covers the full lifecycle: brainstorming ideas against UX guidelines, bootstrapping projects, implementing tools/views, debugging, running dev servers, deploying and connecting apps to ChatGPT.
  Use when a user wants to create or update a MCP App, MCP server or use the Skybridge framework.
---

# Creating MCP Apps

Those are conversational experiences that extend AI assistants through tools and custom UI views. They're built as MCP servers invoked during conversations.

⚠️ The app is consumed by two users at once: the **human** and the **AI Assistant LLM**. They collaborate through the view—the human interacts with it, the LLM sees its state. Internalize this before writing code: the view is your shared surface.

SPEC.md keeps track of the app's requirements and design decisions. Keep it up to date as you work on the app.

**No SPEC.md?** → Read [discover.md](references/discover.md) first. Nothing else until SPEC.md exists.

**SPEC.md exists?** → Read SPEC.md, then follow [architecture.md](references/architecture.md) to design the change. Update SPEC.md, then read the relevant Implementation references below before writing code.

**Migrating from Skybridge `< 0.36.x`?** → Read [migrate-to-v1.md](references/migrate-to-v1.md) first. Users may reference `skybridge >= 0.36.x` as v1.

**Migrating from Skybridge `1.x` to `2.x`?** → Fetch the [v2.0.0 release notes](https://github.com/alpic-ai/skybridge/releases/tag/v2.0.0) first and follow them.

**Building an ecommerce app?** → Read [ecommerce.md](references/ecommerce.md) first.

## Setup

1. **Copy template** → [copy-template.md](references/copy-template.md): when starting a new project with ready SPEC.md
2. **Run locally** → [run-locally.md](references/run-locally.md): when ready to test, need dev server or ChatGPT/Claude connection
3. **Evals** → [evals.md](references/evals.md): when checking that a real model reaches the right tools from natural prompts, in a test

## Architecture

Design or evolve UX flows and API shape → [architecture.md](references/architecture.md)

## Implementation

- **Fetch and render data** → [fetch-and-render-data.md](references/fetch-and-render-data.md): when implementing server handlers and view data fetching
- **State and context** → [state-and-context.md](references/state-and-context.md): when persisting view UI state and updating LLM context
- **Prompt LLM** → [prompt-llm.md](references/prompt-llm.md): when view needs to trigger LLM response
- **UI guidelines** → [ui-guidelines.md](references/ui-guidelines.md): display modes, layout constraints, theme, device, and locale
- **External links** → [open-external-links.md](references/open-external-links.md): when redirecting to external URLs or setting "open in app" target
- **Download file** → [download-file.md](references/download-file.md): when saving content to the user's filesystem
- **OAuth** → [oauth.md](references/oauth.md): when tools need user authentication to access user-specific data
- **CSP** → [csp.md](references/csp.md): when declaring allowed domains for fetch, assets, redirects, or iframes

## Deploy

- **Ship to production** → [deploy.md](references/deploy.md): when ready to deploy via Alpic
- **Publish to ChatGPT/Claude Directories** → [publish.md](references/publish.md): when ready to submit for review

Full API docs: [https://docs.skybridge.tech/api-reference.md](https://docs.skybridge.tech/api-reference.md)

Release notes & changelog: [https://skybridge.tech/changelog.md](https://skybridge.tech/changelog.md)
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
skills/mcp-app-builder/references
skills/mcp-app-builder/references
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
skills/skybridge/references
skills/skybridge/references
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 83def994089ffull audit observations/trust-audit/skill/alpic-ai__mcp-app-builder.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-0883def994089fCAUTIONB89first audit
05

Questions

What does the Mcp App Builder skill do?

Skybridge is a full-stack TypeScript framework for MCP Apps and ChatGPT Apps. Type-safe. React-powered. Platform-agnostic.

Is Mcp App Builder safe to install?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Mcp App Builder access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (83def994089f), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement