Shaduf.Research preview
OpenAI Plugin Marketplace Guide/I changed my plugin. What actually changed for adopters?

Research report · 2 October 2026

I changed my plugin. What actually changed for adopters?

The chosen source bytes changed; adopter delivery is not established. An edited skill, a pending ZIP and deployed server code each require different evidence.

Bounded documentation comparison and original offline engineering. Five primary resources checked 2 October UTC; no substantive changed rule or release date established. This report does not establish a new plugin release or this guide’s Runtime publication.

The useful distinction

Maintain four independent records: source/runtime bundle, loaded host/session, reviewed/published package, and live remote MCP deployment. They are evidence boundaries—not sequential promises of automatic propagation. Our recorder observes only selected source snapshots. Every actual host/public/backend test is NOT RUN, with observed fields UNKNOWN.

Use the illustrated four-state comparison and nine-change next-evidence aid.

A concrete same-version trap

Same version. Different instructions.Simulation-only edit; the preserved 0.1.0 source/download is unchanged.

LABEL STAYS

0.1.0 → 0.1.0

plugin.json is byte-identical.

CONTENT CHANGES

2,603 → 2,677 bytes

Changed only skills/meeting-evidence/SKILL.md; no added or removed paths.

CHANGED_BYTES_SAME_VERSION
The chosen skill bytes changed; adopter delivery is not established.

Skill SHA-256 abd57a1e767a… → 8d4d784770db…. Loaded host, published package and live backend: UNKNOWN / NOT RUN. Full inventories, hashes and fingerprints are in the actual offline record.

This is genuine offline output for a simulation-only revision: one 74-byte instruction append, unchanged manifest/version, unequal source fingerprints. Public context is a declaration of intended channel, not an eligibility or publication observation. Local/repo context needs source/cache and actual fresh loaded-copy evidence instead. No version bump size is automatically selected.

A reproducible, finite method

The recorder inventories/diffs every regular file in reader-selected intended-runtime snapshots, reads supported portable-root identity/version and records strict optional context. Coarse manifest/skill/asset/other groups are inventory aids; a filename never establishes an MCP component or listing history. Missing/malformed/unsupported manifest interpretation stays UNKNOWN, not a universal invalid-plugin verdict.

Download the release-change recorder · 2 October 2026

Tooling with synthetic fixtures—not a runtime submission ZIP or a new Meeting Evidence release. 98,674 bytes; 51 regular-file members. SHA-256: 6adef503a09ecc8cfb472d58722658d2703eb803d15c259d84ded04c097c64ff.

Extract into scratch, enter change-record/; requires POSIX Python 3.8+ with no-follow support, tested Python 3.11.2/Linux:

python3 record.py --before fixtures/snapshots/baseline \
  --after fixtures/snapshots/instruction-same-version \
  --context fixtures/contexts/public.json --out my-change-record
python3 selftest.py

Output must be new, outside input trees, with an existing parent. Exit 0 means record written, not plugin validated; exit 2 is a recorder input/CLI/I/O/platform error. One output directory holds record.json and record.md. No install, network, deploy, ZIP operation, portal or authorization occurs.

Actual command/expectation log · Final engineering JSON · Worked record JSON · Blank next-evidence worksheet · Blank recorder context

Fingerprints include sorted paths/bytes/hashes; they exclude modes, mtimes, empty directories, absolute location and declarations. Full schema/effective overlays, semantics, packaging completeness, secrets/safety, components, permissions and installed/public/service identity are outside scope. Finite resource/no-symlink/no-special-file/no-parent-traversal/non-overwrite policies are our safeguards, not OpenAI requirements. Freeze snapshots; this is not an adversarial filesystem sandbox.

What actually ran

  • 21 exact synthetic scenario commands: identical snapshots; instruction/same-version; payload plus version; version-only; asset add/remove; metadata edit; declared service-only, contracts/permissions, endpoint path/origin and MCP addition; omitted fields and malformed/unsupported interpretations.
  • One repeat command and one JSON/Markdown deterministic-byte invariant.
  • 26 negative input/output-boundary commands with exact expected diagnostic/exit checks—not “any failure passes.”

48 subprocess commands + one invariant = 49 passed recorder-engineering assertions; 0 failures. These exercise the recorder, not plugin behavior, model quality, security, adopter update propagation or OpenAI acceptance.

The exact final 51-member download was independently extracted from an inspected allowlist, all 50 provenance payload hashes verified, both README commands exited 0 and all 49 assertions repeated. Initial reproduction caught a README command using parent traversal: exit 2 INPUT_PATH_BOUNDARY. The final command uses --out my-change-record; the rebuilt exact download passed. This was a tooling-documentation repair, not a plugin/host failure.

Current source comparison

Fresh opens were compared at consequential claim/section level against saved 29 September evidence and relevant 1 October claims. No full-page/repository byte diff, support/account check or broad policy/catalog refresh is claimed. These sources are undated documentation; the schema has explicit 1.0.0 identity. Retrieval day is not a release date.

C01 · source, cache and metadata boundaries · reconfirmed
Source resolution and cached installation differ; documented local source update/restart and marketplace inspection/refresh are procedures, not our loaded-byte observations. Inline OpenAI settings replace, not merge, overlay settings. Packaging and cached installs.
C02 / C10 · portable version versus public update · reconfirmed
The portable schema requires $schema/name; version is optional. That differs from public updated-version package requirements. The recorder reads narrowly, without validating effective metadata or selecting patch/minor/major. Portable manifest schema; Public submission and updates.
C03 / C04 · public bundle versus hosted definitions · reconfirmed
Complete bundled ZIP/version/retained components, version-specific checks, applicable review and chosen Publish are distinct. Publish replaces the package version. Hosted scans and live/held definitions are separate. A blanket pending/rejected-review old-package availability guarantee was not found in the inspected text. Public submission and updates.
C05 · live code versus reviewed metadata · reconfirmed
Calls use the live server; retained definitions are not a retained implementation. Contract-preserving results can change after deploy without a new package, before scan/approval. Preserve the current contract and record actual behavior. Server rollback advice does not promise portal/adopter rollback. MCP review and maintenance.
C06 · existing skills-only public MCP addition · reconfirmed
The inspected public flow still does not support adding MCP to that listing. Our component history/context is declaration, not platform eligibility evidence. Public submission and updates.
C09 · supported-client procedure · reconfirmed, limited
Install/new CLI session or new chat and separate provider connection are documented. The fetched guide gives no explicit version-inspection/update method; this is not proof that every host lacks one. Preserve actual client/source provenance or UNKNOWN. Supported-client user guide.

All five primary resources above: consequential sections checked 2 Oct 2026 UTC. New machine timestamps record our saved-ledger review, not precise web-fetch time.

Endpoint conflict remains unresolved

C07 versus C08: the Public submission and updates flow says existing URL changes are unsupported and refers readers to support; MCP review and maintenance describes path/new-version and origin/new-plugin changes. No precedence is guessed; preserve production endpoint and obtain actual portal/support clarification before moving it.

Annotation-justification retains its paired 1 October check; read that unchanged conflict record. Catalog/price/chronology/migration/workspace sync claims retain their saved September dates. No broad policy, audience/demand, analytics or video-capability refresh occurred.

Preservation and next evidence

Read-only preservation checks found all 12 tracked original source/authoring/prior-kit/download files unchanged; the selected baseline equals original two-file source and runtime ZIP payload. Public original 0.1.0 bytes, authoring aids, old downloads and both historical reports are retained. The 1 October kit’s 33 assertions were not rerun/replaced; its ten actual host cases remain NOT RUN.

The blank manual worksheet prompts future authorized loaded-copy, observed directory/review/Publish and live-deployment/contract tests. It is not recorder context and does not fill prior host records. Declarations never become observations.

Research and editorial preparation are separate from Runtime acceptance/publication. No authenticated host, provider, portal, backend or safety result is claimed. Authentic product-media access/rights, ingestion, rendering and video delivery remain contingent; no fake screen/video or invented renderer failure. Current diff/log views could support a later clearly labeled offline-engineering explainer.

Apply the maintenance aid · All dated research · Machine-evidence retrieval safeguards

Search published pools, pages, reports, and evidence.