← Files ArtlistARCHIVED FILE

dev-review/package-audit.txt

2.97 KB · Oct 9, 2026 · 12:28 UTC

↓ Download file

PACKAGE AUDIT — 2026-10-02

Verified locally: portable root plugin.json/mcp.json layout and schema declarations; streamable-http MCP entry; icon file and relative paths; listing field lengths; three starter prompts <=128 characters; five positive and three negative cases; all referenced test tool names match supplied tools; ZIP integrity. This is not a Platform validation or live-server test.

Applied fixes: root package summary shortened from 1,035 characters to the opening paragraph to avoid the 1,024-character limit in the submission-error reference. Full marketplace longDescription is preserved. Added publication.release_notes without claiming the proposed server changes are deployed.

Remaining
- Confirm package name matches existing Platform plugin; preserve assigned identity. Version is still 1.0.0. Choose a newer semantic version if required relative to the published release.
- Supply a reviewer-accessible reference image for image-to-video. Align expected tools with the chosen input: stored generation reference versus upload + confirm_upload.
- Provide sample audio for the transcription negative case, or test rejection without uploading audio. Replace the placeholder YouTube URL with a reproducible input and verify actual URL rejection.
- Run all eight cases, including any model configuration/selection calls and cost confirmation steps, with the dedicated reviewer account. Confirm six-second and 9:16 outputs on the chosen model.
- Verify video recordings are accessible and demonstrate these cases. Primary URL is web; Android/iOS links are in submission notes.
- Complete reviewer login instructions/credentials in the secure dashboard, not the ZIP. Verify adequate credits and no inaccessible MFA step.
- Verify OAuth discovery, scopes, PKCE/client-registration settings, resource/audience validation, and sign-in flow. auth.artlist.io is recorded in notes, not invented as an auth field in mcp.json.
- Review proposed tool definitions against implementation, especially upload_widget invocation, create_style_kit behavior, irreversible charges and originals-preserving edits. Deploy final definitions and rescan MCP server.
- Supplied tools exports include only name, description, inputSchema and annotations. Review live tool security schemes, output schemas for structuredContent, UI _meta/resource links and CSP, and MCP server instructions. Their absence in an export does not prove the server omits them.
- Confirm public website, support, terms and privacy URLs work and identify the publisher. Complete developer and server domain verification in Platform.

Skills, hooks, .app.json, extra screenshots, translations and separate Codex compatibility manifest are not required for this portable remote-MCP package. No need to add unused components.

Official references
https://developers.openai.com/plugins/build/plugins
https://developers.openai.com/plugins/deploy/submission
https://developers.openai.com/plugins/deploy/submission-errors
https://developers.openai.com/plugins/deploy/app-review

SHA-256: 034ef5c7374e6cd9656b42a6639851c8a3bd34549362685a74ccfa38f23bbba5