Agent skill

Chatgpt App Submission

by nteract in nteract/semiotic

Inspect a ChatGPT Apps MCP server codebase and generate chatgpt-app-submission.json with app info suggestions, tool hint justifications, test cases, and negative test cases, then report review-check…

Apache-2.0Auto-check passedTesting & QA

Install Chatgpt App Submission

skills CLI
$ npx skills add nteract/semiotic --skill chatgpt-app-submission -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nteract/semiotic chatgpt-app-submission --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nteract/semiotic.git skills-src && mkdir -p .claude/skills && cp -r skills-src/chatgpt-app-submission .claude/skills/chatgpt-app-submission && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
chatgpt-app-submission
GitHub stars
2.7k
Token cost
~2.8k tokens
SKILL.md length
1,315 words
Files
2
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Inspect a ChatGPT Apps MCP server codebase and generate chatgpt-app-submission.json with app info suggestions, tool hint justifications, test cases, and negative test cases, then report review-check…

  • Works in 8 steps: Inspect the MCP server codebase from the… → Read repo metadata, package metadata,… → Find every exposed MCP tool, its… → …
  • Tasks that involve Test generation
  • SKILL.md covers Workflow, App Info Rules, Hint Rules and Output Schema Warnings, plus 6 more sections
  • Reaches modelcontextprotocol.io and developers.openai.com

What it does

Chatgpt App Submission is an agent skill from nteract/semiotic. Inspect a ChatGPT Apps MCP server codebase and generate chatgpt-app-submission.json with app info suggestions, tool hint justifications, test cases, and negative test cases, then report review-check findings and outputSchema warnings for submission review.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Testing & QA, covering Test generation and MCP servers. It works with OpenAI and Model Context Protocol. The repository describes itself as: React data visualization library for streaming, networks, and AI-assisted development. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Test generation
  • Tasks that involve MCP servers

Example prompts

  • “/chatgpt-app-submission”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Inspect the MCP server codebase from the current working directory.
  2. Read repo metadata, package metadata, README files, app manifests, tool descriptors, resource templates, and widget metadata needed to…
  3. Find every exposed MCP tool, its declared readOnlyHint, openWorldHint, and destructiveHint annotations, and whether it declares…
  4. Read each tool implementation and any called helper functions needed to understand side effects.
  5. Compare tool annotations, tool names, tool descriptions, and CSP values against actual behavior. If any value is missing, stale…
  6. Generate concise review-facing app info suggestions, tool hint justifications, positive test cases, and negative test cases.
  7. Write chatgpt-app-submission.json in the current working directory.
  8. Print review-check findings and any missing outputSchema warnings in the final response, and explain what the developer should do with…

What it can do on your machine

Read from SKILL.md and the folder at commit 13e933d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • modelcontextprotocol.io
    • developers.openai.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Chatgpt App Submission loads about 2.8k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 1,315 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nteract/semiotic at commit 13e933d, republished under its Apache-2.0 licence (© nteract). 1,315 words, ~2,814 tokens.

Download SKILL.mdSave it as .claude/skills/chatgpt-app-submission/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
chatgpt-app-submission
description
Inspect a ChatGPT Apps MCP server codebase and generate chatgpt-app-submission.json with app info suggestions, tool hint justifications, test cases, and negative test cases, then report review-check findings and outputSchema warnings for submission review.

ChatGPT App Submission

Use this skill when a developer needs a chatgpt-app-submission.json file for a ChatGPT Apps submission. The file is uploaded in the Apps submission form to fill out parts of App Info, MCP Server, and Testing.

Workflow

  1. Inspect the MCP server codebase from the current working directory.
  2. Read repo metadata, package metadata, README files, app manifests, tool descriptors, resource templates, and widget metadata needed to understand the app.
  3. Find every exposed MCP tool, its declared readOnlyHint, openWorldHint, and destructiveHint annotations, and whether it declares outputSchema.
  4. Read each tool implementation and any called helper functions needed to understand side effects.
  5. Compare tool annotations, tool names, tool descriptions, and CSP values against actual behavior. If any value is missing, stale, misleading, or inconsistent, ask the developer for approval before updating source.
  6. Generate concise review-facing app info suggestions, tool hint justifications, positive test cases, and negative test cases.
  7. Write chatgpt-app-submission.json in the current working directory.
  8. Print review-check findings and any missing outputSchema warnings in the final response, and explain what the developer should do with each finding before submission.

Do not infer behavior from the tool name alone. Use the real tool implementation and declared annotations. If a tool calls into another module or API client, inspect enough of that path to know whether it reads, writes, deletes, sends, publishes, or changes external state.

App Info Rules

Suggest app info from source-of-truth project metadata and the tool behavior you inspected. Keep it plain-language and submission-review-facing.

  • display_name: use the product or app name from repo metadata, package metadata, README, manifest, or existing configuration. Keep it short enough for the submission form.
  • subtitle: summarize what the app does in one short functional phrase, not marketing copy. It must be 30 characters or less.
  • description: describe concrete user value and the main workflows the tools support.
  • category: choose one of BUSINESS, COLLABORATION, DESIGN, DEVELOPER_TOOLS, EDUCATION, ENTERTAINMENT, FINANCE, FOOD, LIFESTYLE, NEWS, PRODUCTIVITY, SHOPPING, or TRAVEL.

Hint Rules

Use the Apps SDK review meanings:

  • readOnlyHint: true only when the tool strictly fetches, looks up, lists, retrieves, or computes data without changing state. false if it can create, update, delete, send, enqueue, run jobs, write logs, start workflows, or otherwise mutate state.
  • destructiveHint: true if the tool can delete, overwrite, send irreversible messages or transactions, revoke access, or perform destructive admin actions, including via some modes or parameters. Otherwise false.
  • openWorldHint: true if the tool can change publicly visible internet state or external third-party systems, such as sending emails or messages, posting/publishing content, creating public tickets/issues, pushing code/content, or submitting external forms. false if it only operates in closed/private systems.

ChatGPT Apps submissions require every tool to set all three hints explicitly. Missing or null hints are submission blockers, even if MCP clients may have protocol-level defaults.

If a hint is missing, null, or does not match the actual behavior you found in code, stop before writing the JSON and ask the developer for approval to update the MCP server source. In the approval request, list each affected tool, the missing/current hint value, the behavior you observed, and the recommended explicit hint value. If the developer approves, make the smallest source change that sets the correct hint explicitly, then generate JSON using the updated values. If the developer does not approve or the correct edit location is ambiguous, do not generate misleading JSON; report the mismatch and the blocked update.

Output Schema Warnings

While inspecting exposed MCP tools, record each tool whose descriptor or source definition omits outputSchema or sets it to null. Missing outputSchema is not a blocker for generating chatgpt-app-submission.json, and the submission JSON does not include output schemas.

Do not infer or invent output schemas for this warning. Use the actual MCP tool descriptor or source definition. In the final response, include a concise warning for any missing tools: Add an outputSchema so models can use this tool's results more reliably. See https://modelcontextprotocol.io/specification/draft/server/tools#tool. Include the affected tool names. If every tool declares outputSchema, do not include an outputSchema warning.

Tool Descriptor and CSP Rules

Check tool names, tool descriptions, and widget CSP metadata while inspecting the app.

  • Tool input schemas should not solicit sensitive data unless that data is strictly necessary for the app's stated user-facing workflow. Flag fields that ask for PHI, PCI, SSNs, credentials, MFA codes, government IDs, biometrics, or similarly sensitive identifiers.
  • Tool names should match the action the tool performs and should not imply capabilities the implementation does not provide.
  • Tool descriptions should accurately describe inputs, side effects, and user-visible results.
  • CSP values should be as narrow as the implementation supports. Flag wildcard domains, unused domains, broad resource/connect domains, and missing domains required by actual widget behavior.

If tool names, descriptions, or CSP values appear missing or inconsistent with actual behavior, prompt the developer for approval before editing source. If the developer declines or the correct edit is ambiguous, keep the generated JSON truthful and report the finding in the final response.

Show full SKILL.md (485 more words)Show less

Test Case Rules

Generate exactly five positive test cases and exactly three negative test cases.

  • Positive test cases must use exact MCP action names in tools_triggered.
  • Positive prompts should cover the main tool-backed workflows and edge conditions that review should exercise.
  • Negative test cases should describe prompts where the app should not trigger, including nearby-but-out-of-scope requests.
  • Keep expected outputs review-facing and concise. Do not include secrets, credentials, source snippets, local paths, request IDs, stack traces, or private implementation details.

Output Contract

Write exactly one JSON file named chatgpt-app-submission.json:

json
{
  "$schema": "https://developers.openai.com/apps-sdk/schemas/chatgpt-app-submission.v1.json",
  "schema_version": 1,
  "app_info": {
    "display_name": "Example App",
    "subtitle": "Find and update records",
    "description": "Example App helps users find records, inspect details, and update workspace data through ChatGPT.",
    "category": "PRODUCTIVITY"
  },
  "tools": {
    "tool_name": {
      "annotations": {
        "readOnlyHint": true,
        "openWorldHint": false,
        "destructiveHint": false
      },
      "justifications": {
        "read_only_justification": "Only retrieves matching records and does not modify data.",
        "open_world_justification": "Does not write to public internet state or third-party systems.",
        "destructive_justification": "Does not delete, overwrite, revoke access, or perform irreversible actions."
      }
    }
  },
  "test_cases": [
    {
      "description": "Find records that match a specific user request.",
      "user_prompt": "Find my open records for this week.",
      "file_attachment_urls": null,
      "tools_triggered": "tool_name",
      "expected_output": "Returns matching records with enough detail for the user to choose the next action.",
      "expected_output_url": null
    }
  ],
  "negative_test_cases": [
    {
      "description": "Do not trigger for unrelated calendar requests.",
      "user_prompt": "What meetings do I have tomorrow?",
      "file_attachment_urls": null,
      "tools_triggered": null,
      "expected_output": "The app should not be invoked because the request is outside its supported workflows.",
      "expected_output_url": null
    }
  ]
}

$schema identifies the import file shape for editors and importers; Codex does not need to fetch it. tools is required. app_info, test_cases, and negative_test_cases are optional in the schema, but generate them whenever the repo contains enough information. Do not include review-check findings in this JSON file.

Writing Justifications

  • Keep each justification to one sentence.
  • Be specific about the actual behavior, not the annotation itself.
  • For write tools, state what system is changed and whether the change is bounded/private or public/external.
  • For destructive tools, name the irreversible action and mention any real safeguard only if it exists in the code.
  • Do not include source snippets, secrets, tokens, request IDs, local paths, stack traces, or private implementation details in the JSON.

Good examples:

  • Only retrieves project metadata and returns it without creating or updating records.
  • Creates a private task in the user's workspace and cannot publish content to public URLs.
  • Deletes the selected workspace document, which cannot be recovered after confirmation.

Bad examples:

  • readOnlyHint is true because the tool is read-only.
  • Probably safe.
  • The function calls client.delete_item(...) in src/server.py.

Reporting Review Checks

Report these checks in the final response after writing chatgpt-app-submission.json. Do not write them into the JSON file.

  • Sensitive data solicitation: flag tool input schema fields that request PHI, PCI, SSNs, credentials, MFA codes, government IDs, biometrics, or similarly sensitive identifiers. Include the tool name and input field in the finding.
  • Tool data use: flag tools that collect, expose, mutate, or transmit sensitive data in a way the descriptor or tests do not clearly explain.
  • Tool naming: flag names or descriptions that are too vague, misleading, overbroad, or inconsistent with implementation behavior.
  • Weak CSPs: flag broad, wildcard, unused, or missing CSP domains in widget metadata.

For each finding, explain the practical next step: update source, update submission copy, narrow CSP, remove or justify a sensitive input, or manually review before submitting. If there are no findings, say that these checks did not find obvious issues from source inspection.

Final Response

After writing the file, summarize the app info fields generated, number of tools covered, positive test case count, and negative test case count. Then include a Review findings section with any sensitive data solicitation, tool data use, tool naming, weak CSP findings, or missing outputSchema warnings and what to do with each one. If generation is blocked, lead with the exact missing hints or source ambiguity.

© nteract, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in chatgpt-app-submission of nteract/semiotic.

  • SKILL.md
  • LICENSE.txt

Open the folder on GitHubat commit 13e933d

Compare with similar skills

Chatgpt App Submission next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Chatgpt App Submission compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Chatgpt App Submission this skillnteract/semiotic2.7k—~2.8kAutomated safety check: PassApache-2.0
Opik Verifycomet-ml/opik-mcp220—~2.8kAutomated safety check: NotesApache-2.0
Opik Testcomet-ml/opik-mcp220—~2.8kAutomated safety check: NotesApache-2.0
Create Test Runjeremylongshore/tons-of-skills-marketplace2.8k—~3kAutomated safety check: PassMIT
Agent QA Authoringvostride/agent-qa904—~569Automated safety check: PassCustom licence
Agent QA Result Triagevostride/agent-qa904—~394Automated safety check: PassCustom licence

Similar skills

  • Opik Verify

    comet-ml/opik-mcp

    Decide ship or hold for a candidate from the compare skill's numbers, against an explicit release policy — regressions, pass rate, safety-tagged cases, subgroup consistency, latency and cost…

    220 GitHub stars~2.8k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes
  • Opik Test

    comet-ml/opik-mcp

    Turn a failing Opik trace (or a described failure) into a repeatable regression check — a test-suite item with the trace's input and one or two binary assertions — so a fix can be verified by the…

    220 GitHub stars~2.8k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes
  • Create Test Run

    jeremylongshore/tons-of-skills-marketplace

    Create a Kobiton test run from a test case or suite, then offer to monitor it.

    2.8k GitHub stars~3k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Agent QA Authoring

    vostride/agent-qa

    A skill your agent uses when creating, editing, validating, or running agent-qa tests, suites, or hooks.

    904 GitHub stars~569 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Agent QA Result Triage

    vostride/agent-qa

    A skill your agent uses when investigating failed agent-qa runs, inspecting artifacts, classifying failures, or comparing recent runs.

    904 GitHub stars~394 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Ue Test Authoring

    JasonMa0012/MooaToon

    A skill your agent uses when writing or modifying UE automated tests (Automation, CQTest, Functional, Gauntlet, LowLevel) with Rider MCP available.

    750 GitHub stars~2.1k tokensUpdated 23 days ago
    Testing & QAAuto-check: notes

More from nteract/semiotic

  • Blog Post

    nteract/semiotic

    Author a new entry for the Semiotic blog. An agent skill from nteract/semiotic.

    2.7k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Code Review

    nteract/semiotic

    Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.

    2.7k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Semiotic Charts

    nteract/semiotic

    Build, repair, and verify charts in an existing Semiotic project, when Semiotic is explicitly requested, or when evaluating its documented capabilities against a visualization task.

    2.7k GitHub stars~2.1k tokensUpdated today
    Auto-check passed

Questions about Chatgpt App Submission

What does Chatgpt App Submission do?

Inspect a ChatGPT Apps MCP server codebase and generate chatgpt-app-submission.json with app info suggestions, tool hint justifications, test cases, and negative test cases, then report review-check…. Chatgpt App Submission is an agent skill from nteract/semiotic.json with app info suggestions, tool hint justifications, test cases, and negative test cases, then report review-check findings and outputSchema warnings for submission review.

When should I use Chatgpt App Submission?

Chatgpt App Submission fits situations like: tasks that involve Test generation; tasks that involve MCP servers.

How do I install Chatgpt App Submission in Claude Code?

Run `npx skills add nteract/semiotic --skill chatgpt-app-submission -a claude-code`. Or copy the skill folder (chatgpt-app-submission in nteract/semiotic) into .claude/skills/chatgpt-app-submission in your project. Claude Code loads it when a task matches its description.

How do I install Chatgpt App Submission in Codex?

Run `npx skills add nteract/semiotic --skill chatgpt-app-submission -a codex`. Or copy the skill folder (chatgpt-app-submission in nteract/semiotic) into .agents/skills/chatgpt-app-submission in your project. Codex loads it when a task matches its description.

Can I use Chatgpt App Submission in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nteract/semiotic --skill chatgpt-app-submission -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chatgpt-app-submission, .gemini/skills/chatgpt-app-submission, .github/skills/chatgpt-app-submission and .opencode/skills/chatgpt-app-submission in your project.

What does Chatgpt App Submission need to run?

SKILL.md names no scripts, command-line tools or credentials: Chatgpt App Submission is instructions for the agent only.

Does Chatgpt App Submission access the network?

SKILL.md names 2 domains. In commands or code: modelcontextprotocol.io and developers.openai.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Chatgpt App Submission safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Chatgpt App Submission use?

Chatgpt App Submission is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Chatgpt App Submission use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Chatgpt App Submission?

Skills that share tags, products or a category with Chatgpt App Submission: Opik Verify (comet-ml/opik-mcp, 220 stars), Opik Test (comet-ml/opik-mcp, 220 stars), Create Test Run (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Agent QA Authoring (vostride/agent-qa, 904 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Chatgpt App Submission?

nteract (a GitHub organization) maintains it in nteract/semiotic, which has 2,714 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: nteract/semiotic on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.