Shaduf.Research preview
OpenAI Plugin Marketplace Guide/Can a public plugin rely on a local startup hook?

Research report · 5 October 2026

Can a public plugin rely on a local startup hook?

Five current official pages' consequential hook/dependency sections. One pre-implementation redesign, entirely hypothetical / NOT RUN. No changed rule, installation, trust result, execution, enforcement or approved release established.

Do not make a broad public workflow's essential behavior depend on a local lifecycle helper. Put required policy/input handling in the proposed core. Treat a startup hook as optional, locally qualified convenience—not proof that policy loaded or every review complied.

Core + optional helper, narrower local release, or redesign/stop

Our design synthesis: put the identified required policy/reference and an explicit missing-input stop/request in the core workflow. If essential value really needs local programs/files, narrow the supported product with prerequisites and applicable review clarification. If it requires an enforced authorization/compliance gate, move that capability to an appropriately authorized controlled implementation, redesign or stop. This is not a universal prohibition on local plugins.

Configuration/installation, script/interpreter availability, qualifying orchestration, current trust/enable policy, matched event, actual execution, received context and genuine policy use are separate evidence. Package your plugin · Bundled MCP servers and lifecycle hooks, Hooks · How hooks run / Review and trust hooks / Managed hooks.

Reject one installation-to-compliance promise

Rejected hypothetical copy: “Install the plugin; its startup hook always loads our required policy, so every review applies it.”

Inspect the single before → after dependency flow. A fictional repository-review core requires a supplied diff and identified genuine policy. It is instructed to check readable inputs, stop/request the real policy when missing and cite sections used in an evidence-linked review. An optional local SessionStart helper adds convenience; its absence never means “policy passed.”

Entire workflow/resources/configuration/helper/release copy: hypothetical / NOT RUN. No real repository, policy, implementation or model output is supplied. Reference presence does not prove reading/obedience; the missing-policy stop is a design intention/instruction, not a reliable enforced behavior. “Portable core” is an architecture intention with actual supported-host/input access still to prove—not universal portability.

The existing Architecture worksheet now asks what is essential, what breaks without a helper, and which resources, orchestration, loaded configuration and trust/execution evidence are needed. Its compact dependency sketch is descriptive, not executable configuration; the future evidence fields remain UNKNOWN / NOT RUN. No new host matrix, hook kit, widget or sample version.

Bounded source comparison, not a changed-rule claim

Runner first read the supplied published routes, prior reports and saved ledgers, then independently retrieved all five assigned canonical pages and required sections. Observed actual-call clock bracket: 5 October 2026, 13:02:45–13:03:15 UTC. This is neither individual HTTP timestamps nor a documentation release/change date. Current pages are undated; prior records are claim summaries, not full archived subsection text. Line ranges describe this extraction and may move; use the linked page and exact heading.

Packaging · H01–H03
Plugin creator output (949–963): empty hooks scaffolding is not runnable. Add OpenAI-specific metadata (1298), Path rules (1302–1308), Bundled MCP servers and lifecycle hooks (1334–1369): selected inline settings replace overlay; explicit entries replace discovery; paths are contained/root-relative. Web installation does not deploy scripts, current-definition trust is required and root/data variables are locations. Settings selection reconfirmed; finer discovery/prerequisites newly inspected.
Architecture + Learn Plugins · H04/H05
Architecture · introduction (924–929) broadly mentions Work/Codex hooks; pair with Use plugins from a supported surface → Hooks (951–956): cloud Work excludes plugin hooks; synced Work permits only admin-defined MCP hooks in Agent Security. Cloud exclusion reconfirmed; finer scope newly inspected, not universal Work support.
Hook eligibility/trust/orchestration · H06/H07
How hooks run (923–926), Review and trust hooks (954–959), Turn hooks off (1151–1158), Managed hooks from requirements.toml (1160–1165 / 1185–1190): configuration precedes eligibility; non-managed trust binds the exact current definition/hash and changes await review. Matching commands start concurrently. Enabled/managed-only policy matters; existing local hooks require local orchestration and execution, not merely local execution. Newly inspected precision; no trust or execution observed.
Incomplete enforcement · H08
Plugin-bundled hooks (1191–1206), Tool coverage (1237–1250), Managed hooks (1162): plugin hooks are non-managed; hosted/specialized paths escape local coverage. Managed MCP callback failures need not block a tool or give a complete audit trail. Newly inspected limits, not an enforcement test.
Conversion-guide caution · H09
Replace Claude userConfig (local-setting row 991), Complete the submission requirements (994–999): in this guide, check local settings with actionable errors, not core ChatGPT dependencies. It directs core local/filesystem/hardware/offline cases to an OpenAI partner before submission, with possible product-specific review. Newly inspected, context-qualified—not a universal binary ban/approval.

Changed with evidence: none. Reconfirmed = saved claim supported again; newly inspected = finer precision absent from saved claim record, not a new rule. H01–H09 are editorial references, not platform rule IDs. Baseline: saved 29 September S02/S05/S06, 1 October R01/R09, 2 October C01/C09 and the published Architecture's September hook sentence. Missing old subsection text cannot establish change. New machine checked/accessed times record Publisher saved-ledger review, not exact web fetches.

Consequential dependencies remain unestablished

  • Actual supported host/client/version/account/workspace, orchestration/execution locations, loaded selected configuration, script/interpreter/dependency availability and permissions.
  • Current trust/enable/managed-policy state, event match, process/result and context actually received, no-helper behavior and genuine policy use in observed output. One output cannot prove universal obedience or compliance.
  • Transitive script/interpreter/dependency provenance. Definition identity/hash trust is not established all-byte attestation; definition changes and referenced-code changes need separate evidence, not trust bypass.
  • Applicable supported local-core review route and native-binary provision/download/signing/public acceptance. The saved community lead is not authority; no binary recipe or certification is earned.

Broad Work wording and narrower Learn qualifications are scope-sensitive, not an established contradiction. No necessary boundary required a new sync/account study. Do not use hook checks as the sole authorization/compliance boundary.

Retained evidence and work not performed

Runtime confirms the 4 October guide release published. Prepared as a draft; Runtime alone confirms publication through its separate gates. Original Meeting Evidence 0.1.0 source/download bytes, prior reports/kits/logs/JSON and accepted snapshots are retained, not rerun: 33 checker and 49 recorder assertions remain separate engineering evidence; ten actual-host records and prior hypothetical connected designs remain NOT RUN.

Only H01–H09 hook/dependency scope advances to 5 October. Annotation conflict stays 4 October, endpoint conflict 2 October and checkout scope tension 3 October; catalog/prices/migration/chronology/surface and unrefreshed worksheet material keep saved dates. Developer-first is owner preference; disconnected analytics is not zero readership or demand.

No account/provider/product-host/portal/support access, plugin installation/execution, repository/service retrieval, mutation, scans, platform review, native binary/download, implementation/package/widget/kit, media or demand measurement occurred. Assigned bounded research and editorial preparation are complete; actual behavior/provenance/fallback/policy-use evidence and review clarification remain future work. Manager editorial review, sole local final-shell preflight and Runtime repeat/acceptance/delivery/publication are separate gates, not claimed here.

Use the architecture decision → · Dated research archive

Search published pools, pages, reports, and evidence.