Research report · 6 October 2026
Can a hook-bearing local bundle enter public submission?
Not as-is under the current documented public-ZIP rule. A locally supported or optional hook does not establish eligibility of the same bundle. Choose the release channel before investing in review materials.
Correct the active advice, not the historical study
Use the early gate and single channel-choice card. Our advice: retain a truthfully bounded local/repo/workspace variant; consider a separate public scope without excluded components only if meaningful core survives; otherwise stop, narrow/redesign or seek authoritative clarification. The separate public option is unimplemented, not proven useful or accepted.
The 5 October core-plus-optional-helper design and proposed copy are now qualified as conditional local scope. Its fictional workflow, intended missing-policy stop and all host behavior remain NOT RUN; a skill instruction is not enforced compliance. The original report remains unchanged. Removing excluded components does not pass the remaining host, behavior, utility, security, identity/metadata, setup/scan, review/approval or Publish gates.
Source comparison: different scopes and a genuine tension
- Z01–Z02 · newly inspected public input constraint
- Submission excludes ZIPs containing lifecycle hooks or registered MCP mappings (
apps/.app.json). Adjacent guidance and examples use direct MCP URLs plus dashboard setup. A needed service still requires legitimate control/provider authority and applicable verification/authentication/scans. - Z03–Z07 · local support is not public permission
- Packaging documents local/repo components separately from public submission. Registered mappings are not optional UI. Selected settings and local default hook discovery are reconfirmed; deleting a key alone is no reliable general removal remedy. No blanket UI, script or local-plugin ban follows.
- Z08–Z10 · unresolved submission-context tension
- Errors' skills-only exclusions and registered-reference stripping/import warnings are scoped. Conversion tables direct hook adaptation within both submission paths, then give preparation/submission steps. This is in tension with the explicit ZIP exclusion—not “local-only” guidance or an established exception. No source precedence or actual controlling portal path is known.
Submission · Automatically provide submission and review information / Complete metadata examples / MCP setup; Packaging · Path rules / OpenAI-specific metadata / Bundled MCP servers and lifecycle hooks / Public publication; Errors · ZIP upload warnings / MCP references / Package warnings; Conversion · Review what OpenAI supports / archive and MCP submission preparation. Z references are ours, not official error IDs.
Independent official-domain search/canonical reads; observed research-call bracket 6 Oct 12:56:27–12:57:24 UTC, not individual HTTP timestamps or documentation dates. Reconfirmed local layout/discovery and separate gates; newly inspected ZIP restriction and submission pairing; scope-sensitive normalization; unresolved conversion tension. Changed with evidence: none. Old ledgers summarize claims, not full archived page text.
Keep unknowns and dates attached
Public parsing, normalization and enforcement were not observed. Optional/disabled/untrusted hooks, unselected settings, undeclared files and empty scaffolds have no established universal exemption. No adapted ZIP, useful alternative, new package/tool/widget, host installation/invocation, endpoint, upload/rejection, scan/review/approval, support answer, real footage or media/render result was produced.
Only public-channel claims advance to 6 October. Host/trust remains 5 Oct, annotation conflict 4 Oct, endpoint conflict 2 Oct and checkout tension 3 Oct; unrelated catalogue/prices/migration/chronology retain saved dates. Original 0.1.0 source/downloads and prior reports are unchanged; 33 checker and 49 recorder assertions remain separate offline engineering evidence, all ten actual-host cases NOT RUN. The no-hook teaching ZIP is not established submission-ready.
Runtime confirms the 5 October guide published. Report completion describes bounded research/editorial preparation, not Runtime acceptance or plugin publication; delivery/publication are separate host events. Actual useful variants, host/provenance evidence, necessary authoritative clarification and public gates remain future work. Developer-first is owner preference; disconnected analytics is not zero demand. Footage/ingestion/rendering/delivery prerequisites remain unmet.