{"id":13845,"plugin_id":"plugin_asdk_app_6a8b7bbd015c8191b94d8cee58beef3e","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:08:17.947Z","digest":"ca7c3a6ef8b8dde2b760a31aaa45a8294dfccd94e059aa096c16cf2ff99cb96a","against":null,"payload":{"name":"choosecruise-chatgpt-app","description":"Build, debug, review, deploy, or prepare submissions for the ChooseCruise ChatGPT app in this repository. Use for MCP tools, the cruise carousel widget, Apps SDK metadata, ownership verification, analytics behavior, production descriptors, and submission artifacts; do not use for unrelated ChooseCruise backend or mobile work.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":241},{"relative_path":"references/app-contract.md","size_in_bytes":3496}],"skill_md_contents":"---\nname: choosecruise-chatgpt-app\ndescription: Build, debug, review, deploy, or prepare submissions for the ChooseCruise ChatGPT app in this repository. Use for MCP tools, the cruise carousel widget, Apps SDK metadata, ownership verification, analytics behavior, production descriptors, and submission artifacts; do not use for unrelated ChooseCruise backend or mobile work.\n---\n\n# ChooseCruise ChatGPT App\n\nWork on the existing submission-ready React-widget app under `mcp-gateway/`. Preserve its established registry, stateless HTTP transport, compact result format, and shared backend integrations.\n\nBefore changing Apps SDK or MCP Apps behavior, use the OpenAI Developers `build-chatgpt-app` guidance and current official documentation. Prefer current standards, but inspect the deployed compatibility requirements before removing aliases or changing the widget MIME type.\n\n## Start with the real surface\n\nRead the files involved in the requested change rather than inferring behavior from names. Begin with:\n\n- `mcp-gateway/src/mcpServer.ts` and `mcp-gateway/src/toolRegistry.ts` for the public tool surface.\n- `mcp-gateway/src/tools/<tool>/definition.ts`, handler, service, and called helpers for behavior and side effects.\n- `mcp-gateway/src/resourceRegistry.ts` and `mcp-gateway/web/src/CruiseCarousel/` for widget metadata and host integration.\n- `mcp-gateway/src/analytics.ts` when annotations, privacy, or data use are relevant.\n- `mcp-gateway/docs/chatgpt-app-listing.md` for deployment and listing context, checking source when it is stale.\n\nRead [references/app-contract.md](references/app-contract.md) before changing tools, widget metadata, the challenge endpoint, or submission artifacts.\n\n## Implementation rules\n\n- Keep `search_cruises` and `get_cruise_details` as the public consumer tools unless the requested product scope changes.\n- Do not register `ping` in production. `/health` is the operational health surface.\n- Give every exposed tool explicit `readOnlyHint`, `openWorldHint`, and `destructiveHint` values based on the full implementation, including analytics writes.\n- Give every exposed tool an `outputSchema` that matches `structuredContent`; update the schema and implementation together.\n- Keep model-facing `structuredContent` compact. Put large widget-only payloads in `_meta`.\n- Do not expose an unauthenticated `userId` or another personalization identifier through the public tool schema.\n- Keep CSP allowlists exact. Do not add ChatGPT, API, wildcard, frame, or asset domains unless widget code actually needs them.\n- Preserve the ownership challenge route and serve its configured token as plain text. Replace the token only when the user supplies a new one.\n- Treat analytics as a real side effect and data transfer. Keep tool descriptions, annotations, privacy disclosures, and submission justifications consistent with it.\n- Preserve the existing URI versioning and legacy widget URI alias unless a verified migration plan covers already-connected hosts.\n\n## Submission work\n\nUse the OpenAI Developers `chatgpt-app-submission` skill for a submission audit or JSON generation. Inspect deployed descriptors after deployment; a portal rescan cannot see local source changes.\n\nThe import file must describe exactly the currently exposed production tools. Remove entries for tools that are no longer registered, and never make JSON annotations differ from `tools/list`.\n\n## Verification\n\nExercise the smallest relevant checks while building, then run:\n\n```bash\ncd mcp-gateway\nnpm test -- --runInBand\nnpx tsc --noEmit --incremental false\n```\n\nFor descriptor changes, add or update an in-memory MCP client test that checks `tools/list`. For HTTP routes, add an HTTP test. For widget changes, build the widget and exercise the rendered flow; apply the repository's UI guidelines to anything users see.\n\nReport tests or builds that were skipped or blocked. Deployment and portal rescanning are separate actions and require explicit user authorization.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}