Developer guide · public-channel qualification 6 October · hook/dependency evidence 5 October · surface/example baseline 29 September 2026
Choose a plugin architecture
Separate the package, execution host and service. Keep essential policy/input handling in the proposed core, not dependent on an optional local startup helper. Four untested patterns retain their original access, cost and date caveats.
What actually runs where?
Distribution sources
- Universal public directory
- Local / repo catalog
- Authorized workspace sharing / import
Plugin package: skills (instructions + resources), optional tool connection/configuration
Supported ChatGPT or Codex host: loads workflow, selects tools, applies host/workspace controls
A skill does not create an outside account. A custom UI is not required.
Optional lifecycle helper: locally qualified convenience, not essential policy or an enforced control. Web installation does not deploy scripts; configuration or local availability still does not establish trust/execution. Hook precision checked 5 Oct 2026; public-ZIP eligibility is separately restricted (6 Oct).
MCP server: validates requests, exposes tools/data/actions
Connected service / account: supplies the capability; provider permissions still apply
Optional UI resources may be displayed by a supporting host—not by every client.
Text alternative: a public, local/repo or workspace source distributes a package. A supported host uses its skills and may call an authorized MCP server, which accesses a service. Some results include optional UI. Access depends on the surface, account, workspace and provider. Skills, MCP server, Workspace plugin management. Checked 29 Sep 2026.
Pre-build decision · 3 October: if the connected task depends on a paid upgrade, first separate an existing customer's included task from a prohibited digital sales flow. This narrow commercial decision does not refresh the architecture or example records below.
Connected-action decision · 4 October: separate private reads and unsaved previews from approved external sends. The hypothetical contract review says omit send unless a genuine human approval boundary can be enforced; it does not refresh the component roadmap or dated examples.
Choose components by need, not by appearance
- No package yet
- A one-off task with readable supplied information may need only a normal prompt and compatible built-in tools. First establish that this route is inadequate.
- Skill-centered package
- Use recognizable task instructions/resources for a repeatable procedure. Installation or sharing should add value; a skill does not create service access.
- MCP connection, with or without a skill
- Use controlled tools for necessary live data or actions. The server validates requests and the provider authorizes its own resources.
- Optional UI
- Add an inspection/editing surface only if interaction helps. A text result can be valid; not every host renders UI.
Plugin architecture, Skills, MCP server. Checked 29 Sep 2026.
Required core, optional local startup convenience
5 October design, qualified for channel on 6 October: essential behavior should not depend on optional local convenience. Core + optional local helper remains a local design intention, with supported-host/input access still to prove—not permission to submit that hook-bearing bundle publicly. If local files/programs are essential, narrow the supported scope with explicit prerequisites and applicable clarification. If a promise needs an enforced gate, use an appropriately authorized controlled implementation, redesign or stop—not stronger skill wording.
Our design synthesis from Package your plugin · Bundled MCP servers and lifecycle hooks and Hooks · Tool coverage / Managed hooks. Not a universal prohibition on local plugins or a binary approval recipe.
“Install the plugin; its startup hook always loads our required policy, so every review applies it.”
Install ≠ selected configuration ≠ available command ≠ qualifying orchestration ≠ enabled/trusted definition ≠ matched execution ≠ received context ≠ policy use.
- Supplied diff + identified real policy reference
The core is instructed to check readable inputs and identify the policy version. - Missing or unreadable required policy → stop/request
The instruction is to stop the policy-based review and ask for the genuine input—not invent a policy or substitute general knowledge. - Readable required inputs → evidence-linked review
Cite the policy sections used and report uncertainties. Reference presence does not prove reading, obedience or compliance.
Unavailable/unsupported/untrusted helper: no convenience, never “policy passed.” The core may proceed only with its required readable inputs. The intended missing-policy stop is an instruction, not a reliable enforced guarantee.
Text path: supplied diff and required policy → intended readable-input check → missing-policy stop/request or evidence-linked review. An optional helper can add context; it cannot replace the required input or prove policy use. All of this is hypothetical / NOT RUN.
Inspect the compact dependency sketch — descriptions, not executable configuration
- Core inputs
- A user intentionally supplies a diff; the skill identifies
references/review-policy.mdand its real version. Genuine provenance, readable access and actual use remain unestablished. - Selected configuration
- Illustrative root
plugin.jsonselectsextensions.com.openai; an explicit./hooks/session.jsonreplaces default discovery. Absent explicit entries, the documentation permitshooks/hooks.json. Creator hooks scaffolding is empty, not runnable. A checkout does not prove the loaded selection. - Available command and interpreter
- Proposed installed-root
hooks/session_start.pyrequires suitable available Python 3 and permissions. Web installation does not deploy scripts; no dependency deployment is designed here.PLUGIN_ROOT/PLUGIN_DATAlocate resources, not attest provenance. - Qualifying orchestration
- Convenience is proposed only for supported Codex/local-only Work with orchestration and execution local. Local execution alone does not qualify cloud orchestration. Plugin availability is not execution evidence.
- Current trust and enable policy
- Plugin permitted/enabled, current non-managed definition reviewed/trusted, hooks enabled and not excluded by managed-only policy. Trust is tied to the current definition/hash; changed definitions await review. It is not established transitive attestation of every referenced script/interpreter/dependency byte.
- Matching event, received context, policy use
- A matching
SessionStartinvocation, process/result and context actually received need evidence. Successful status or received context alone does not prove the core used the genuine policy faithfully.
Packaging · Plugin creator output / Path rules / Bundled MCP servers and lifecycle hooks; Plugins · supported surface → Hooks; Hooks · How hooks run / Review and trust hooks / Turn hooks off / Managed hooks. H01–H08 in the 5 October source comparison; our references, not platform rule IDs.
Truthful proposed local/repo/workspace release copy
Channel qualification added 6 October: conditional local scope only, subject to actual host/source/workspace prerequisites. A separately scoped public candidate without excluded components has not been built or shown useful; it must not reuse the helper promise.
Conditional local/repo/workspace design proposal — NOT RUN: Repository Review's core workflow requires a supplied diff and the identified review-policy reference, and is instructed to cite the policy sections it uses. If the policy is missing or unreadable, it is instructed to stop the policy-based review and request the real input. An optional SessionStart helper is proposed only for supported Codex or local-only Work with local orchestration and execution, an available helper/interpreter, and an enabled, trusted definition permitted by managed policy. Unavailable convenience never means policy passed; the core may proceed only with its required readable inputs. No host execution, portability or policy compliance has been demonstrated.
Hooks are not a sole authorization/compliance boundary. Hosted/specialized tool paths escape local coverage; managed MCP callback errors need not block a tool or supply a complete audit trail. The worked policy stop is a design intention, not hook enforcement. Hooks · Plugin-bundled hooks / Tool coverage / Managed hooks, inspected 5 Oct.
In the Claude-conversion guide · Replace Claude userConfig / Complete the submission requirements, local settings must be checked with actionable errors rather than core ChatGPT dependencies; core local/filesystem/hardware/offline cases are directed to an OpenAI partner before submission and may need product-specific review. This is that guide's context, not a universal local ban or native-binary acceptance. The appropriate route for this fictional release remains unresolved.
Future lawful evidence — every field UNKNOWN / NOT RUN
- Authorized actual client/version/account/workspace; orchestration and execution locations recorded separately.
- Loaded selected configuration/current definition and trust/enable/managed-policy state; referenced script bytes, interpreter/dependencies and permissions evidenced separately.
- Matched event, redacted invocation/result and context actually received—not merely a manifest or successful status.
- Observed no-helper behavior, missing-policy stop/request and actual output compared with the genuine policy sections. One output cannot prove universal obedience/compliance.
No new test cases, host matrix, suite, package or hook implementation. Native-binary provision/download/signing/public acceptance and transitive dependency provenance remain unresolved. Scope and retained evidence.
First, check your surface
- ChatGPT web, desktop & mobile
- Eligible plugins in Chat or Work; not every plugin works everywhere. Desktop-only listings can be discovered on web but require desktop to install/use.
- Codex desktop & CLI
- Use the configured plugin browser. Start a new session after installation; API-key sign-in has plugin OAuth exclusions.
- IDE extension
- Plugins are currently unsupported. Standalone skills are a different unit. Historical March release notes conflict with today’s guide; we follow the current guide.
- Imported raw MCP configurations
- Workspace imports are Desktop-only, including HTTPS endpoints. Do not assume public-plugin portability for raw imports.
Current plugins user guide, Workspace plugin management, ChatGPT & Codex changelog. Checked 29 Sep 2026.
Hook precision · 5 October: broad developer “Work and Codex” wording is qualified by Learn: cloud-orchestrated Work excludes plugin hooks; synced Work permits only admin-defined MCP hooks in Agent Security. Existing local hooks require local orchestration and execution. Neither a local execution location nor directory availability establishes qualifying operation.
Architecture · introduction, Plugins · supported surface → Hooks, Hooks · Managed hooks. Inspected 5 Oct 2026; not a page-wide surface refresh.
Partner Sign in with ChatGPT remains a separate beta caveat, not a universal login guarantee. Current plugins user guide. Saved check 29 Sep 2026.
Similar names, different layers
- Historical 2023 ChatGPT plugins
- The earlier plugin-mode system, not today’s package-install instructions. Old GPT-4 menus and three-plugin-limit tutorials are not this guide.
- GPTs / GPT Store
- A configured custom assistant and its sharing/directory system—not a plugin package. A migration can rebuild a workflow, not carry everything over unchanged.
- Apps SDK
- An integration-building toolkit for MCP-backed experiences and optional ChatGPT UI. It can contribute to a plugin; it is not the directory.
- MCP
- The tool/data protocol and server layer. A configured server alone is not a reviewed public package.
- Local / custom marketplace
- A catalog pointing to local/repo packages. Useful for development or teams, but separate from the universal public directory.
- Current plugin + universal directory
- The installable unit and its shared public distribution source, subject to host, account and workspace gates.
Plugin architecture, Package your plugin, Plugin UI changelog, Custom GPT migration guidance. Checked 29 Sep 2026.
Choose the smallest useful route
This local decision aid suggests a starting point. It does not inspect your account, connect a service or install anything.
Plain-text decision path
- Choose your surface and confirm the task can run there. The current guide excludes plugins in the IDE extension.
- For a one-off task using supplied information, try a normal prompt or an available built-in tool first.
- For a repeatable process, author and test a focused skill. Package it when installation or sharing adds value.
- For outside data or actions, inspect an existing plugin, its supported surface, permissions, provider identity and entitlement. Start read-only or draft-only.
- If no suitable route fits a reusable workflow, build a small plugin. Add MCP only for a real external tool/data need; add UI only when interaction benefits.
Apple Messages is restricted to Apple Silicon macOS desktop Work/Codex. Confirm every route in your own account/workspace. Before a public skills-only release, check the restriction on adding MCP later.
Current plugins user guide, Plugin architecture, Upload and submit. Checked 29 Sep 2026.
Builder worksheet: make one architecture decision
- 1 · Task and acceptable output
- “Given ______, produce ______; success is observable by ______.” Keep a proposal distinct from an outside action.
- 2 · Data origin
- Which input is supplied? Which must be fetched? Who owns it, and what access can the intended user authorize?
- 3 · Host and capabilities
- Name the actual client/surface, required host tools and exclusions. Record unverified account/workspace conditions rather than assuming directory access. Added 5 Oct: separate orchestration/execution locations, selected loaded config, available resources/interpreter, current trust/enable policy and actual invocation/context evidence.
- 4 · Minimal component set
- Normal prompt / focused skill / MCP connection / optional UI. Explain what breaks if each proposed component is removed. Added 5 Oct: identify essential required inputs versus optional helpers. If a helper disappears, can the proposed core still use the genuine policy? Reference presence is not reading/obedience; instructions/hook checks are not enforced compliance.
- 5 · Action and permission boundary
- Read only? Draft only? Write/send? Identify where consent and provider entitlements must be checked.
- 6 · Public roadmap
- Will a future public version need MCP? Resolve the skills-only public-update restriction before committing to a listing identity.
The two hook/dependency questions above use the 5 October decision and sources; other worksheet/component-roadmap bases retain saved dates.
Upload and submit. Checked 29 Sep 2026.
Inspect four patterns before choosing your own architecture
Selected by task—not popularity. None was installed or invoked by this study. Superpowers, GitHub and Canva appeared in a read-only, account-scoped directory search; Apple Messages is documented in the user guide. The search was non-exhaustive. GitHub was already marked installed, not authenticated.
Documented = primary guidance describes it. Listing observed = returned in this account context. Tested = installed/invoked and checked; no example has that label here. Every entry below was checked 29 September 2026.
Reusable coding workflow · listing observed · untested
Superpowers: clarify a feature before coding
Start in Codex desktop or CLI. The inspected curated package is skill-centered: empty hooks, no declared MCP dependency. Broader upstream includes host-specific hooks and an optional visual companion; do not assume every variant is offline or UI-free.
- Requirements & cost
- Eligible Codex host, workspace permission and appropriate filesystem/tools. Exact subscription tier not verified. MIT source; no separate package-license charge stated. Model/API usage and optional service setup are separate.
- Try, then inspect
- Ask for a small feature design and test plan without editing files or starting agents. Check assumptions, scope and test cases—not merely a statement that the plugin ran.
Superpowers curated manifest, Superpowers upstream. Checked 29 Sep 2026.
Complete dated task record and inspection checklist
- Task contract
- Turn a feature idea into a reviewed design and test-driven implementation plan.
- Components and variant
- Skill-centered coding workflows. OpenAI curated manifest declares skills and hooks:{} but no MCP dependency. Broader upstream includes host-specific hooks and an optional visual companion.
- Documented/observed starting surfaces
- Codex CLI
- Codex in desktop app (upstream installation instructions)
- Other surfaces not established
- Upstream describes separate client adaptations; current ChatGPT web/mobile behavior and automatic hooks not tested or established for this package.
- Account/workspace prerequisites
- Eligible Codex environment and workspace plugin permission; exact subscription tier not verified. Agent execution, filesystem access and optional subagent capacity depend on host.
- Provider access
- No external-service authentication declared by the checked curated skills package; Git/service actions and optional network features may require separate setup.
- Cost observation
- MIT open-source package; no separate package-license fee stated. Vendor offers enterprise support but its fees were not verified. Host model/API usage remains separate.
- Limits to retain
- Do not treat upstream automatic activation claims as our test evidence
- Review workflows, scripts and optional network/telemetry behavior before enabling
- Install separately for each client; current curated archive can differ from upstream main
- Private inspection/install instructions
- Codex /plugins → search exact name → inspect package/policy → Install plugin → new session.
- Illustrative prompt — not executed
- Use Superpowers to clarify this small feature and produce an implementation plan. Do not edit files or start agents yet.
- Evidence to inspect
- A scoped design and plan that names assumptions and tests, not merely a claim that Superpowers ran.
- Removal and retained access
- Supported browser → Uninstall plugin; CLI Space disables an installed entry. Legacy standalone skill installations are separate and were not audited.
- Evidence status
- primary upstream/package inspected; listing observed in account-scoped read-only search; not invoked. Not tested by us; last checked 2026-09-29.
Authorized repo data · listing observed · untested
GitHub: inspect one pull request without posting
A hybrid connector/CLI workflow. The public package declares app and MCP configuration; the pre-existing cached build differed. Installed metadata does not prove working credentials, and operation parity across ChatGPT surfaces was not verified.
- Requirements & cost
- Access to the repository, workspace permission, and the chosen connector’s authorization or CLI credentials. Optional app mappings do not make OAuth mandatory for every fallback. GitHub Free lists US$0/month; extra provider features and host usage may cost separately. No plugin-specific price verified.
- Try, then inspect
- Summarize one PR URL you can access; request diff/check citations and no comments, pushes, merges or reruns. Compare repository identity and check state with GitHub. Invented retrieval is not success.
GitHub package, GitHub app mapping, GitHub pricing. Checked 29 Sep 2026.
Complete dated task record and inspection checklist
- Task contract
- Summarize one authorized pull request, identify risks and inspect failed checks without posting.
- Components and variant
- Hybrid GitHub connector and CLI workflow. Public package declares .app.json and .mcp.json; research environment cached package differed from upstream in MCP wiring.
- Documented/observed starting surfaces
- Codex package documented by upstream manifest; listing visible to this research environment
- Other surfaces not established
- Shared-directory support is documented generally, but per-surface GitHub operation parity was not verified.
- Account/workspace prerequisites
- Plugin permitted in chosen workspace; a GitHub identity with access to requested repository for account-connected work. Organization approval and specific ChatGPT/Codex plan eligibility not verified.
- Provider access
- Connect GitHub if the chosen connector flow prompts; CLI fallback has its own credentials/setup. Checked app mappings are optional; do not claim every operation universally needs OAuth.
- Cost observation
- GitHub Free displayed US$0/month and unlimited public/private repositories. Extra service features and host usage can cost separately; no plugin-specific price verified.
- Limits to retain
- Repository visibility and permissions still apply
- Upstream package and pre-existing local cache are not identical
- Do not infer a successful connection from installed:true metadata
- Private inspection/install instructions
- Find exact GitHub name in supported plugin browser; inspect required app and connect authorized account if needed; install; new chat/session.
- Illustrative prompt — not executed
- Use GitHub to summarize [one PR URL I can access]. Cite the diff and relevant checks; distinguish unknowns. Do not post comments, push, merge or rerun jobs.
- Evidence to inspect
- Verify PR/repository identity, citations and check state against GitHub. Prose alone is not proof of remote retrieval.
- Removal and retained access
- Uninstall plugin if allowed; separately disconnect the authorized GitHub integration in ChatGPT/provider settings if no longer needed.
- Evidence status
- primary package inspected; listing observed as pre-existing installed entry; not authenticated or invoked in this study. Not tested by us; last checked 2026-09-29.
Connected design service · listing observed · untested
Canva: turn an outline into an editable deck
The observed listing describes Codex design workflows and account connection. Individual ChatGPT web/mobile feature parity is not established here. Open the returned design in the correct Canva account and inspect text, assets and entitlement warnings.
- Requirements
- Canva account connection and workspace permission. The listing says design/image generation uses Canva AI credits; its Bulk Create requires eligible Canva Enterprise, even where Canva’s general product table describes other bulk features.
- Cost & limits
- Canva Free exists. Fetched US annual prices: Pro US$144/year for one person; Business US$250/year per person, excluding tax. Region/billing varies. Free’s up-to-20 Standard OR Premium uses assumes low consumption—not 20 guaranteed plugin tasks. No plugin-specific fee verified.
Plugin-specific requirements are our dated listing observation, not a product test. Canva, Canva pricing, Canva AI allowance. Checked 29 Sep 2026.
Complete dated task record and inspection checklist
- Task contract
- Turn an outline into a presentation draft that can be opened and edited in Canva.
- Components and variant
- Connected design service with editable design outputs; current listing describes Codex design workflows and a Canva account connection.
- Documented/observed starting surfaces
- Codex workflow explicitly described by observed listing
- Other surfaces not established
- Visible in this ChatGPT-backed directory search; individual ChatGPT web/mobile feature parity not verified.
- Account/workspace prerequisites
- Connect a Canva account; plugin must be permitted by account/workspace. Listing says bulk create requires an eligible Canva Enterprise plan, even though provider's general plan table has other bulk-design features.
- Provider access
- Canva account connection required by observed listing.
- Cost observation
- Canva Free exists; fetched US annual pricing showed Pro US$144/year for one person and Business US$250/year per person, excluding applicable tax. Region/billing can change. Exact plugin-specific charge not verified.
- AI allowance
- Listing says design/image generation uses Canva AI credits. Provider help describes a shared plan-dependent monthly allowance; Free up to 20 Standard OR Premium uses under simple/lower-consumption assumptions, not 20 guaranteed plugin tasks. Paid plans have higher allowances.
- Limits to retain
- Bulk Create plugin entitlement is narrower than general Canva plan features
- Never equate a free provider account with unlimited AI generation
- Review licensing/export and account-specific limits before committing money
- Private inspection/install instructions
- Search exact Canva name in plugin browser; review requested permissions; install/connect when prompted; start a new chat/session.
- Illustrative prompt — not executed
- Use Canva to draft a five-slide presentation from this outline. Keep the wording editable, avoid premium-only assets if possible, and do not publish.
- Evidence to inspect
- Open the returned design in the correct Canva account; inspect all pages, text, assets and any entitlement warnings.
- Removal and retained access
- Uninstall if allowed and separately disconnect/revoke Canva connection if no longer wanted.
- Evidence status
- listing observed in account-scoped read-only search; provider pricing/usage pages inspected; not installed, connected or invoked. Not tested by us; last checked 2026-09-29.
Local desktop capability · documented · untested
Apple Messages: find a conversation and draft a reply
Documented for all plans on Apple Silicon macOS ChatGPT desktop, in Work or Codex only—not regular Chat, direct web/mobile or Codex CLI. It uses local Messages access/macOS permissions; admins can disable it through Computer Use.
- Safe starting task
- Find a specific conversation and draft without sending. Verify recipient and quoted context on your Mac. Retain per-send approval: persistent per-chat permission removes later final review.
- Cost & removal
- No separate plugin fee established; carrier/messaging and host cost not verified. Uninstall independently of macOS permissions. Settings → Computer use → Manage beside Messages lets you remove an always-allowed chat.
Current plugins user guide. Checked 29 Sep 2026.
Complete dated task record and inspection checklist
- Task contract
- Find a specified conversation on your own Mac and draft a reply for review.
- Components and variant
- Local desktop Messages access; not a remote cloud connector or SMS route to ChatGPT.
- Documented/observed starting surfaces
- ChatGPT Work in macOS ChatGPT desktop app, Apple Silicon arm64 build
- Codex in that desktop app
- Excluded surfaces
- regular ChatGPT Chat
- direct ChatGPT web/mobile access
- Codex CLI
- IDE extension
- Account/workspace prerequisites
- Official guide says all plans, but Apple Silicon macOS desktop app required; administrators can disable through Computer Use.
- Provider access
- Existing local Messages app/chat access plus requested macOS permissions. No cloud-provider OAuth requirement established.
- Cost observation
- No separate plugin fee established by official guide. Underlying messaging/carrier charges and exact host usage cost not verified; all-plans availability is not a zero-cost messaging promise.
- Limits to retain
- Review recipient/content before each send
- Persistent per-chat send approval removes later final review
- Full access/disabled prompts can interfere with send confirmation; retain an approval mode
- Private inspection/install instructions
- Desktop Plugins → Apple Messages → install → new Codex/Work chat → grant requested macOS permissions.
- Illustrative prompt — not executed
- Use Apple Messages to find my conversation with [person] about [specific topic] and draft a reply. Do not send it.
- Evidence to inspect
- Compare the quoted conversation and recipient with Messages on the Mac; draft remains unsent.
- Removal and retained access
- Uninstall where supported; independently manage macOS access. To restore per-send approvals use Settings → Computer use → Manage next to Messages → remove the always-allowed chat.
- Evidence status
- explicit current official documentation; not returned by non-exhaustive account-scoped directory queries; not installed or invoked. Not tested by us; last checked 2026-09-29.
Primary pointers: upstream.
Next: inspect the smallest useful package → · Map permissions before connecting