Research · 1 October 2026
Offline release evidence is useful—but it is not a host result
Before signing in, a developer can rehearse a finite package profile, compare a runtime archive with source and fix an observed packaging mistake. None of that proves the host accepted the package or the workflow behaved correctly.
What this study adds
A runnable 19-file release-rehearsal kit: an explicit-path checker, genuine self-test evidence, synthetic host fixtures, ten manual case specifications, rubric and a blank evidence record. The main practical walkthrough is Test and debug; this report records the finding and its limits.
Observed: finite profile checks, allowlisted archive reads, source/ZIP byte comparison and failure → repair.
Does not prove: installation, activation, good answers, injection resistance or public acceptance.
Collect next: accepted package, loaded version, fresh-session selection evidence, actual output/source comparisons and boundary retests.
Do not infer: a fluent recap proves activation, or a source file proves the cached installed copy.
Collect separately: production utility, truthful listing/icon/disclosures, current validation/scans, applicable review, approval and chosen Publish.
Do not infer: upload success means acceptance, or approval automatically publishes.
The gate comparison is our synthesis, not an official portal form. Documented skill testing separates activation from quality; final submission checks are stricter than upload.
Build skills, Submission error reference. Checked 1 Oct 2026.
Actual engineering evidence—not a model success rate
Under Python 3.11.2, 32 subprocess commands and one deterministic invariant: all 33 TOOLING assertions passed. The final record has six positive commands, 19 deliberately broken or out-of-scope fixtures, one I/O check and six CLI/output guards. Assertions compare exact exits and diagnostic sets; a wrong reason for failure is not success.
Exact final log and machine-readable final summary support these observations. A separate read-only check of the original assigned source/ZIP pair exited 0. Original plugin.json, SKILL.md, 0.1.0 version and runtime ZIP bytes remain unchanged.
Two newly written stored archives were byte-identical to each other with unchanged two-file payloads. They differ in compression encoding from the old runtime ZIP; identical payloads do not mean identical old/new ZIP bytes. Independent download reproduction unpacked the exact 19-file allowlist, matched 18 provenance payload hashes and successfully repeated the documented check and self-test. It is local reproduction evidence, not a Runtime publication/delivery receipt.
One concrete failure → repair
The synthetic runtime archive accidentally included authoring README.md. Our checker returned exit 1, ZIP_UNEXPECTED [README.md]. Replacing recursive packing with explicit --write-zip allowlisting returned 0; source/ZIP comparison of the repaired archive also returned 0. The repair changed packaging, not source or version. Reproduce the exact scratch failure and repair.
Scope is part of the result
The profile meeting-evidence-two-file-skills-only-v1 covers only root plugin.json and one SKILL.md: strict JSON/UTF-8, selected manifest/name checks, fixed sample identity and release policy, restricted one-line front matter, allowlisted CRC reads and optional source/ZIP byte parity. The external schema itself requires only $schema and name; our required version/description and exact-identity choices are conservative local requirements.
Recognized metadata/assets, compatibility, MCP/app/hook and additional-resource layouts are OUT_OF_SCOPE, not universally invalid. No archive extraction occurs. Symlink/path/collision/size policies are ours, not a complete reproduction of the portal. The checker is not full JSON Schema/YAML validation, a secret/safety scan or a host emulator.
Agent Plugins 1.0.0 schema, Package layouts and components. Checked 1 Oct 2026.
A consequential correction: portable is not Codex-ready
Current guidance distinguishes logo/composerIcon required for Codex package validation, portable upload acceptance that can omit them, and a primary icon needed before public submission. The preserved teaching source omits those settings/assets. An offline pass cannot settle compatibility; adding them needs a broader profile and actual host evidence.
This is a newly surfaced editorial gap, not a demonstrated policy change. The Build page now puts this gate before conditional installation instructions; we have not fabricated an icon or mutated the teaching release.
Submission metadata and icons. Checked 1 Oct 2026.
Ten manual host contracts, zero observed host results
The ten case specifications cover explicit recap/selection, implicit activation, missing notes, unsupported sending, unrelated arithmetic, conflicting/unanchored dates, injected instructions, absent attachment, unreadable-input applicability and anchored dates/proposals. Every actual-result, selection, output and retest field remains NOT RUN.
The original rubric requires evidence-linked decisions/actions, faithful wording strength, preserved unknowns/contradictions and data-versus-authority boundaries. The blank per-case record collects supported client/version, lawful prerequisites, source/loaded-copy evidence, install/fresh-session steps, enabled permissions, actual selection/output/source comparison and independent retest. If reliable activation evidence is unavailable, use UNKNOWN, not PASS inferred from a fluent recap.
H09’s invalid-UTF-8 binary fixture is not an observed host-read failure. A future tester must record what the host actually attached/read and any lawful fixture variation. No absent access/media is labeled model failure. The cases/rubric are original QA, not mandatory official submission forms.
Skill activation and quality, Security principles. Checked 1 Oct 2026.
Current checks: two conflicts persist
Nine canonical primary pages/schema resources were opened and relevant sections inspected on 1 October. No substantive changed rule or new rollout/release date was established. The comparison is consequential-claim scope, not a page-wide textual diff; unsuccessful Markdown fetches were followed by successful canonical HTML checks.
- Annotation justifications · unresolved
- Guidelines say they are no longer required; the submission-error reference and MCP-review guidance still require/use them. Keep actual booleans and semantics accurate, then confirm portal/support requirements instead of choosing convenient text. No submission resolved this.
Plugin guidelines, Error reference, MCP review. Checked 1 Oct 2026.
- MCP endpoint changes · unresolved
- Submission guidance directs existing URL changes to support; MCP-review guidance describes a new version for path changes and a new plugin for origin changes. Preserve the endpoint and confirm before moving it. No portal/support interaction occurred.
Submission updates, MCP maintenance. Checked 1 Oct 2026.
Skills-only metadata’s relaxed four-URL import check is not a privacy-policy waiver. Production-quality distinctive utility, truthful disclosures, scans and applicable review remain; this educational source has not demonstrated public-product eligibility.
Skills-only submission checks, Privacy and production utility. Checked 1 Oct 2026.
Media remains a post-text prerequisite
No authentic product screenshot, recording or video was produced. A bounded current PATH audit found Python/Node but not ffmpeg/ffprobe or named browser executables; this is not filesystem-wide or remote-renderer absence. Callable remote upload/render metadata was discovered, not exercised or authenticated. Lawful product tests, real redacted media/credits, verified ingestion/renderer access and supported delivery remain pending. Source-editor/log shots would be labeled offline engineering, never simulated host footage.
Completed research versus pending gates
Completed: focused current source comparison, exercised offline checker/regressions, runtime preservation, failure/repair, reproducible authoring download and separate blank host contract. Pending: actual host compatibility/install/selection/quality/security tests; a production public release’s portal/scans/review/approval/chosen Publish; authentic product media and authorized rendering/delivery.
Catalog/pricing/migration/chronology observations remain at their saved September dates. No audience-demand or analytics result was collected; unavailable data is not zero demand. Publication of this research guide is separately controlled by Runtime and is not publication of the sample plugin.
Primary-source check index · 1 October 2026
- Package your plugin—layouts, local sources and cached installs.
- Build skills—activation, quality and boundary tests.
- Agent Plugins 1.0.0 schema—portable syntax, not host readiness.
- Upload and submit—icons, component roadmap and separate Publish.
- Submission errors—stricter final checks; annotation conflict.
- Plugin guidelines—utility/privacy; annotation conflict.
- Security and Privacy—engineering responsibilities.
- MCP review—connected requirements and unresolved endpoint rules.
- Plugins user guide—future supported-host procedure only.
Use the release-rehearsal kit → · Unchanged 29 September study · Research archive