MCP App Clinic

Paste the tool, the ui:// resource and the iframe UI — posture, inventory, ranked findings, migration map.

Back to SkillSafe
Or pick files: they are read locally, nothing uploads until you run.
Context — which host, which SDK version, what goes wrong
How it works

Nothing to hand? Load the — a window.openai pizza-finder with openai/outputTemplate metadata, the text/html+skybridge MIME type, connect_domains in snake_case, handlers assigned after connect() and localStorage state — or the , where the correct verdict is host-ready and the useful output is what to add next.

1

Paste the app — the prescan is free

No upload, no AI: the prescan reads your source in the browser and lists what it mechanically found. The tool, ui:// resource, handler, transport, declared CSP domain and build inventory, then the flags — leftover window.openai reads, openai/* metadata keys, the text/html+skybridge MIME type, snake_case connect_domains, handlers assigned after connect(), raw server.registerTool, tools with no _meta.ui.resourceUri, ui:// URIs no resource serves, results with no text content fallback, every origin in the code that appears in no CSP domain list, localStorage inside the sandboxed iframe, a build with no single-file bundling, ignored safeAreaInsets, and hardcoded colors and fonts. Each group explains why it matters. A paste-coverage strip names which halves of the app you actually pasted — server registration, iframe app, stylesheet, build config — and which checks cannot fire without the ones you left out, so you know before you pay whether the review will be a full pass. This part costs nothing and happens while you type.

2

The AI reviews it — this is the metered part

A senior MCP Apps engineer's pass: a host-readiness posture with the single most important change named, the inventory with each construct's role, prioritized findings across lifecycle, CSP, server wiring, host integration, migration, build and hygiene — each with the problem, what the host actually does because of it, the fix and a corrected TypeScript fragment — and a before-and-after migration map for every OpenAI Apps SDK pattern in the paste. Every prescan flag is confirmed or explicitly set aside. Findings may only cite tools, resources, handlers and origins that actually appear in your code. Pricing is honest: a worst-case amount is reserved before the run and only what the run actually uses is charged — the meter next to the button shows both.

3

Fix, export, re-run

Every corrected snippet in one paste-ready block, the findings as GitHub PR review comments — single-line fixes in ```suggestion fences GitHub can apply, multi-line ones as plain ```ts to paste into the file — a tickable action checklist that includes the migration map, the findings table as CSV, and Markdown or JSON export of the whole review. Then start fixing: the prescan re-runs as you edit and the strip above the run button counts the flags you have cleared, the ones still open and any you have just introduced — in the browser, for free, before you pay for a second review. Every assumption the reviewer had to make and every question it had to ask is clickable — one click drops it into the context box so the next review has the answer instead of guessing again. If nothing has changed, the run button says so rather than billing you for the same review twice. Reviews are saved to your SkillSafe account when you are signed in, so they follow you to another machine; restore puts the code back in the form too.

Derived from the @tldraw/tldraw skill set — its create-mcp-app, convert-web-app, migrate-oai-app and add-app-to-server skills for the MCP Apps SDK.