Shaduf.Research preview

Developer guide · public-ZIP channel gate inspected 6 October · annotation conflict 4 October · other readiness 1 October 2026

Submit and review a public plugin

Prepare evidence for a first public release without confusing ZIP upload, final validation, review, approval and the developer’s Publish action.

Choose the channel before preparing review materials

6 October check: not as-is. Current public-submission guidance excludes ZIPs containing lifecycle hooks or registered MCP server mappings (apps / .app.json). A locally supported or optional helper does not make that same bundle eligible.

Submission · Automatically provide submission and review information. Newly inspected restriction, not a changed rule or observed upload rejection.

Registered mappings are not optional MCP UI. Adjacent guidance uses direct MCP URLs and dashboard setup; any service needs legitimate server/control/provider authority and applicable verification, authentication and scans. Local package support is a different scope—not a blanket UI, script or local-plugin ban.

Packaging · Path rules / Publish official public plugins, Submission · Complete metadata examples / Connect and scan your MCP server, Errors · MCP server reference errors. Narrow channel check, 6 Oct.

What the sources do not resolve

The conversion guide directs hook adaptation in both submission-path support tables, followed by preparation/submission steps. This conflicts in implication with the explicit ZIP exclusion; no exception, source precedence or controlling real path is established. It is not “local-only” guidance. Withhold a hook-bearing public eligibility claim pending authoritative clarification.

Errors' skills-only exclusions and reference-removal/import warnings are scoped, not a hook workaround. No universal optional/disabled/untrusted, unselected/undeclared or empty-scaffold exemption is established. Local default discovery makes deleting a manifest key no reliable general remedy. Actual public parsing, normalization and enforcement were not observed.

Conversion · Review what OpenAI supports / Prepare and upload / Prepare and submit, Errors · ZIP upload / MCP references / Package warnings, Packaging · Bundled MCP servers and lifecycle hooks. Dated comparison and exact scope.

Upload and submit. Checked 1 Oct 2026.

Different gates, different meanings
  1. Complete ZIP
  2. Automated upload checks
  3. Final submission
  4. Review
  5. Approval
  6. Choose Publish

An upload pass is not final submission acceptance. Approval is not an automatic Publish action, an estimated review time or a distribution guarantee.

Upload and submit, MCP review and distribution, Submission error reference. Checked 1 Oct 2026.

Check the submitter and release identity

  • Platform eligibility. Use the appropriate organization/project, Apps Management Write role and verified identity; package files do not supply these.
  • Truthful public listing. Prepare publisher/interface metadata, required disclosures, current listing text bounds and a primary square icon. A relaxed skills-only metadata URL-import check is not permission to omit the privacy policy or other applicable disclosures.
  • One complete package root. Valid UTF-8/JSON/skill files, referenced assets and the final semantic version. Local portable schema requirements and final listing requirements differ.
  • Distinctive production utility. Demonstrate a real purpose and quality beyond a trial or teaching demo. Do not invent test output, approval, third-party authorization or enhanced placement.

Upload and submit, Submission error reference, Plugin guidelines. Checked 1 Oct 2026.

Skills-only and MCP require different evidence

Skills-only release
Skill checks/safety scans and broader listing/policy eligibility still apply. MCP reviewer credentials, tool demo video and five-positive/three-negative MCP cases are not required merely because the package includes a skill. Our ten host specifications are original QA, not mandatory portal cases.
Public MCP release
Prepare a stable production publicly accessible HTTPS endpoint, domain verification, suitable auth, accurate tool schemas and annotations. Provide a dedicated reviewer sample account, an accessible demo and exactly five positive/three negative MCP cases.
UI-bearing review material
Directory screenshots no longer being displayed does not eliminate all UI review-material rules. Guidelines and submission-error references concern different contexts; verify the actual portal requirements.

Upload and submit, MCP review and distribution, Submission error reference, Plugin guidelines. Checked 1 Oct 2026.

Meeting Evidence: the honest gap list

The unchanged source is a portable authoring example, not a completed public product. The new release-rehearsal kit establishes only finite offline observations: 33 TOOLING assertions passed, not host or safety results.

Portable manifest syntax
The schema requires $schema and name. Our four-field identity/version/description profile is stricter in selected ways and not complete JSON Schema validation.
Codex package compatibility
Current guidance requires logo and composerIcon. This two-file source has neither; host compatibility is NOT RUN. Adding metadata/assets needs a broader profile and recorded host acceptance.
Portable upload versus public submission
Portable upload may omit those icon fields, but primary icon, truthful listing/identity/disclosures, final name/version rules and current final validation still apply before submission. Upload success is not final acceptance.
Behavior, safety and production utility
All ten host cases are NOT RUN. No secret/safety scan, public validation, review or approval ran for this sample. Distinctive production utility is unproven; a teaching demo does not establish policy eligibility.
Approval versus publication
Applicable review and approval must precede a separate chosen Publish. No sample submission or plugin publication was performed.

Portable schema, Host metadata and submission, Final validation errors, Production utility and privacy policy. Checked 1 Oct 2026.

Readiness worksheet

Release identity / semantic version / package root:
Submitter organization, project, write role, verified identity:
Distinct user task and demonstrated production utility:
Listing/publisher metadata, square icon, disclosures:
Codex logo/composerIcon compatibility; primary submission icon:
Bundled assets and complete package checks:
Actual local behavior records and unresolved failures:
Skill scan findings (when available):
MCP endpoint/domain/auth/reviewer account (if applicable):
MCP five positive + three negative cases and demo (if applicable):
Live portal conflicts still requiring clarification:
Review outcome and separate Publish decision: NOT PERFORMED

This is our preparation template, not a portal schema or evidence that any row has passed.

Advertise the full behavior; do not guess required explanation fields

Narrow check · 4 October 2026. Explicit readOnlyHint, destructiveHint and openWorldHint values must describe all supported modes/defaults and indirect effects—not a favorable dry run or tool name. The flags are independent; explanations cannot override scanned values. A saved draft, job or outbound send cannot hide behind “read-only preview.” Inspect the conditional three-operation example.

Guidelines · MCP requirements → Tools → Correct annotation, MCP review · Metadata stored during tool scanning / annotation mismatch. Only consequential behavior/annotation sections refreshed; no scan performed.

Correct annotation, Final directory submission / annotations_required / justification_required, Review FAQs · annotation mismatch. Paired annotation-only conflict checked 4 Oct. No changed rule established; other readiness material retains 1 Oct.

After approval, choosing Publish remains a separate action. Exact-name/direct-link discovery is not discretionary enhanced placement; no review SLA or approval promise was established.

MCP review and distribution. Checked 1 Oct 2026.

Next: choose distribution and maintain the release → · Revisit the trust boundary

Maintaining a public release? Separate the complete versioned-bundle/Publish record from live scans and deployments. Publish replacement is documented; universal old-package retention during pending review is not directly established. Public submission and updates. Checked 2 Oct 2026.

Search published pools, pages, reports, and evidence.