MCP App Clinic — MCP Apps review & OpenAI Apps SDK migration
Paste an MCP App — the server-side tool and ui:// resource registration plus the UI code that runs in the host's sandboxed iframe — and get a senior MCP Apps engineer's review: a host-readiness posture (host-ready / hardening-recommended / host-breaking), the inventory of every tool, resource, lifecycle handler, transport, declared CSP domain and build step, prioritized findings with corrected TypeScript, and a before-and-after migration map off the OpenAI Apps SDK. A free instant prescan flags leftover window.openai globals, openai/* metadata keys, the text/html+skybridge MIME type, snake_case connect_domains, handlers registered after connect(), raw registerTool calls, tools with no _meta.ui.resourceUri, results with no text fallback, every origin missing from the CSP declaration, localStorage inside the sandboxed iframe, builds with no single-file bundling, ignored safe areas and hardcoded styling before you run anything. Derived from the @tldraw/tldraw skill set (its create-mcp-app, convert-web-app, migrate-oai-app and add-app-to-server skills for the MCP Apps SDK).
Details
gpt-terra Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.