chatgpt-app-builder
Build ChatGPT Apps with MCP Widgets
ChatGPT app builders need clear patterns for MCP servers, widget state, and Apps SDK metadata. This deprecated skill provides mcp-use references and migration guidance for interactive widget projects.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "chatgpt-app-builder" from https://skillstore.io/skills/mcp-use-chatgpt-app-builder.md and its manifest at https://skillstore.io/api/skills/mcp-use-chatgpt-app-builder/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "chatgpt-app-builder". I want a restaurant reservation app inside ChatGPT.
Expected outcome:
A discovery brief that identifies the user goal, required API access, widget need, core reservation actions, and next architecture questions.
Using "chatgpt-app-builder". My product search widget needs filters and refresh actions.
Expected outcome:
A widget plan that separates the search server tool, product list widget, filter state, refresh tool call, and loading behavior.
Using "chatgpt-app-builder". I need to migrate legacy Apps SDK metadata.
Expected outcome:
A migration checklist covering unified metadata, CSP domains, ChatGPT-specific fields, widget descriptions, and testing steps.
Security Audit
SafeMost static detections are false positives from Markdown examples, template literals, placeholder URLs, UI guidance, and non-secret environment variable examples. One medium issue is confirmed: the deprecated skill front matter includes an executable npx install command for a replacement skill, which could trigger external installation in untrusted contexts. No prompt injection, credential exfiltration, or malicious intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (12)
๐ Network access (14)
๐ Env variables (2)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/mcp-use-chatgpt-app-builder/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/mcp-use-chatgpt-app-builder?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/mcp-use-chatgpt-app-builder?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/mcp-use-chatgpt-app-builder/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/mcp-use-chatgpt-app-builder.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
mcp-use. (2026). chatgpt-app-builder security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/mcp-use-chatgpt-app-builder/audits/6BibTeX citation
@techreport{mcp-use-mcp-use-chatgpt-app-builder-2026,
author = {mcp-use},
title = {chatgpt-app-builder security audit report (audit version 6)},
institution = {Skillstore},
year = {2026},
number = {6},
url = {https://skillstore.io/skills/mcp-use-chatgpt-app-builder/audits/6},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "chatgpt-app-builder security audit report (audit version 6)"
version: "unspecified"
type: report
authors:
- name: "mcp-use"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/mcp-use-chatgpt-app-builder/audits/6"
identifiers:
- type: other
value: "skillstore:mcp-use-chatgpt-app-builder:audit:6"
description: "Skillstore immutable audit report identifier"
Compare variants
4 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
mcp-use-chatgpt-app-builder
2026-09-09
alpic-ai-chatgpt-app-builder
2026-09-22
shubhamsaboo-chatgpt-app-builder
2026-09-09
bayramannakov-chatgpt-app-builder
2026-09-09
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Plan a ChatGPT App Concept
Validate whether an idea needs a ChatGPT app, a widget, or a simpler website or tool flow.
Implement MCP Widget Flows
Use mcp-use examples to connect server tools, React widgets, widget props, and LLM-visible output.
Review Apps SDK Compatibility
Check widget metadata, CSP domains, display modes, and legacy Apps SDK fields during migration.
Try These Prompts
Help me decide whether this idea should be a ChatGPT app. Ask one question at a time and identify the core user action.
Design the MCP tools and widgets for this ChatGPT app. Separate tool-only flows from flows that need an interactive widget.
Create an implementation plan for a mcp-use server tool and React widget. Include props, output, loading state, and tool calls.
Review this ChatGPT app design for widget state, LLM-visible context, CSP metadata, display modes, and Apps SDK compatibility.
Best Practices
- Start with the user action and decide whether the flow needs UI before designing widgets.
- Keep sensitive or detailed data in widget props and expose only useful summaries to the LLM output.
- Use exact CSP domains, clear widget metadata, loading states, and explicit error handling.
Avoid
- Do not port a full dashboard or large website into ChatGPT without narrowing the core tasks.
- Do not expose private data in LLM-visible output when widget props can hold it instead.
- Do not rely on placeholder URLs, broad CSP wildcards, or automatic install commands in production guidance.
Frequently Asked Questions
Is this skill current?
What does this skill help build?
Does it generate a complete app automatically?
Can it help with Apps SDK metadata?
Does it support Claude, Codex, and Claude Code?
What should I verify before publishing an app?
Developer Details
Author
mcp-useLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
0519034dad657fb1f7706e0550e962beeda73fdf
Maintenance freshness
7/18/2026
Usage
5 downloads ยท 141 views
File structure
๐ evals/
๐ architecture.json
๐ discover.json
๐ README.md
๐ skill.json
๐ ui-guidelines.json
๐ widgets.json
๐ references/
๐ architecture.md
๐ components-api.md
๐ csp-and-metadata.md
๐ discover.md
๐ setup.md
๐ state-and-context.md
๐ ui-guidelines.md
๐ widget-patterns.md
๐ LICENSE.txt
๐ SKILL.md