Research report · 5 October 2026
Can a public plugin rely on a local startup hook?
Do not make a broad public workflow's essential behavior depend on a local lifecycle helper. Put required policy/input handling in the proposed core. Treat a startup hook as optional, locally qualified convenience—not proof that policy loaded or every review complied.
Core + optional helper, narrower local release, or redesign/stop
Our design synthesis: put the identified required policy/reference and an explicit missing-input stop/request in the core workflow. If essential value really needs local programs/files, narrow the supported product with prerequisites and applicable review clarification. If it requires an enforced authorization/compliance gate, move that capability to an appropriately authorized controlled implementation, redesign or stop. This is not a universal prohibition on local plugins.
Configuration/installation, script/interpreter availability, qualifying orchestration, current trust/enable policy, matched event, actual execution, received context and genuine policy use are separate evidence. Package your plugin · Bundled MCP servers and lifecycle hooks, Hooks · How hooks run / Review and trust hooks / Managed hooks.
Reject one installation-to-compliance promise
Rejected hypothetical copy: “Install the plugin; its startup hook always loads our required policy, so every review applies it.”
Inspect the single before → after dependency flow. A fictional repository-review core requires a supplied diff and identified genuine policy. It is instructed to check readable inputs, stop/request the real policy when missing and cite sections used in an evidence-linked review. An optional local SessionStart helper adds convenience; its absence never means “policy passed.”
Entire workflow/resources/configuration/helper/release copy: hypothetical / NOT RUN. No real repository, policy, implementation or model output is supplied. Reference presence does not prove reading/obedience; the missing-policy stop is a design intention/instruction, not a reliable enforced behavior. “Portable core” is an architecture intention with actual supported-host/input access still to prove—not universal portability.
The existing Architecture worksheet now asks what is essential, what breaks without a helper, and which resources, orchestration, loaded configuration and trust/execution evidence are needed. Its compact dependency sketch is descriptive, not executable configuration; the future evidence fields remain UNKNOWN / NOT RUN. No new host matrix, hook kit, widget or sample version.
Bounded source comparison, not a changed-rule claim
Runner first read the supplied published routes, prior reports and saved ledgers, then independently retrieved all five assigned canonical pages and required sections. Observed actual-call clock bracket: 5 October 2026, 13:02:45–13:03:15 UTC. This is neither individual HTTP timestamps nor a documentation release/change date. Current pages are undated; prior records are claim summaries, not full archived subsection text. Line ranges describe this extraction and may move; use the linked page and exact heading.
- Packaging · H01–H03
- Plugin creator output (949–963): empty hooks scaffolding is not runnable. Add OpenAI-specific metadata (1298), Path rules (1302–1308), Bundled MCP servers and lifecycle hooks (1334–1369): selected inline settings replace overlay; explicit entries replace discovery; paths are contained/root-relative. Web installation does not deploy scripts, current-definition trust is required and root/data variables are locations. Settings selection reconfirmed; finer discovery/prerequisites newly inspected.
- Architecture + Learn Plugins · H04/H05
- Architecture · introduction (924–929) broadly mentions Work/Codex hooks; pair with Use plugins from a supported surface → Hooks (951–956): cloud Work excludes plugin hooks; synced Work permits only admin-defined MCP hooks in Agent Security. Cloud exclusion reconfirmed; finer scope newly inspected, not universal Work support.
- Hook eligibility/trust/orchestration · H06/H07
- How hooks run (923–926), Review and trust hooks (954–959), Turn hooks off (1151–1158), Managed hooks from requirements.toml (1160–1165 / 1185–1190): configuration precedes eligibility; non-managed trust binds the exact current definition/hash and changes await review. Matching commands start concurrently. Enabled/managed-only policy matters; existing local hooks require local orchestration and execution, not merely local execution. Newly inspected precision; no trust or execution observed.
- Incomplete enforcement · H08
- Plugin-bundled hooks (1191–1206), Tool coverage (1237–1250), Managed hooks (1162): plugin hooks are non-managed; hosted/specialized paths escape local coverage. Managed MCP callback failures need not block a tool or give a complete audit trail. Newly inspected limits, not an enforcement test.
- Conversion-guide caution · H09
- Replace Claude userConfig (local-setting row 991), Complete the submission requirements (994–999): in this guide, check local settings with actionable errors, not core ChatGPT dependencies. It directs core local/filesystem/hardware/offline cases to an OpenAI partner before submission, with possible product-specific review. Newly inspected, context-qualified—not a universal binary ban/approval.
Changed with evidence: none. Reconfirmed = saved claim supported again; newly inspected = finer precision absent from saved claim record, not a new rule. H01–H09 are editorial references, not platform rule IDs. Baseline: saved 29 September S02/S05/S06, 1 October R01/R09, 2 October C01/C09 and the published Architecture's September hook sentence. Missing old subsection text cannot establish change. New machine checked/accessed times record Publisher saved-ledger review, not exact web fetches.
Consequential dependencies remain unestablished
- Actual supported host/client/version/account/workspace, orchestration/execution locations, loaded selected configuration, script/interpreter/dependency availability and permissions.
- Current trust/enable/managed-policy state, event match, process/result and context actually received, no-helper behavior and genuine policy use in observed output. One output cannot prove universal obedience or compliance.
- Transitive script/interpreter/dependency provenance. Definition identity/hash trust is not established all-byte attestation; definition changes and referenced-code changes need separate evidence, not trust bypass.
- Applicable supported local-core review route and native-binary provision/download/signing/public acceptance. The saved community lead is not authority; no binary recipe or certification is earned.
Broad Work wording and narrower Learn qualifications are scope-sensitive, not an established contradiction. No necessary boundary required a new sync/account study. Do not use hook checks as the sole authorization/compliance boundary.
Retained evidence and work not performed
Runtime confirms the 4 October guide release published. Prepared as a draft; Runtime alone confirms publication through its separate gates. Original Meeting Evidence 0.1.0 source/download bytes, prior reports/kits/logs/JSON and accepted snapshots are retained, not rerun: 33 checker and 49 recorder assertions remain separate engineering evidence; ten actual-host records and prior hypothetical connected designs remain NOT RUN.
Only H01–H09 hook/dependency scope advances to 5 October. Annotation conflict stays 4 October, endpoint conflict 2 October and checkout scope tension 3 October; catalog/prices/migration/chronology/surface and unrefreshed worksheet material keep saved dates. Developer-first is owner preference; disconnected analytics is not zero readership or demand.
No account/provider/product-host/portal/support access, plugin installation/execution, repository/service retrieval, mutation, scans, platform review, native binary/download, implementation/package/widget/kit, media or demand measurement occurred. Assigned bounded research and editorial preparation are complete; actual behavior/provenance/fallback/policy-use evidence and review clarification remain future work. Manager editorial review, sole local final-shell preflight and Runtime repeat/acceptance/delivery/publication are separate gates, not claimed here.