Cookwala as a ChatGPT plugin
OpenAI is retiring Custom GPTs (reported for 11 December 2026) and replacing them with plugins: skills (instructions and reference files), connected apps, and optional MCP tools. Custom Actions do not carry over, so Cookwala ships as a plugin whose tools come from its open MCP server. Sources: Build plugins, Package your plugin, Upload and submit your plugin, Remote MCP server review requirements, Plugin guidelines. The older Custom GPT recipe still works until the retirement date.
What is in the repository #
plugins/chatgpt/cookwala/ is the whole package, in OpenAI's portable "Agent Plugins" layout:
| File | What it is |
|---|---|
plugin.json | Name, version, listing text, URLs, brand, icons, the 5 positive and 3 negative review test cases |
mcp.json | Exactly one server: https://mcp.cookwala.ai/open/mcp (streamable HTTP, no sign-in, read-only) |
skills/cookwala/SKILL.md | The workflow and honesty rules (the Custom GPT instructions, rewritten for the MCP tools) |
skills/cookwala/references/filters.md | Everyday words mapped to query_recipes filters |
skills/get-started/SKILL.md | The onboarding skill |
assets/ | Logo and composer icon, light and dark (SVG, square) |
No .app.json, hooks, credentials or screenshots are included (ZIPs with apps or hooks cannot be submitted; the Directory no longer shows screenshots).
python tools/build_chatgpt_plugin.py # validates every documented limit, writes build/cookwala-chatgpt-plugin-<version>.zip
python tools/build_chatgpt_plugin.py --check # validate only; runs in tools/build_site.sh
python tools/build_chatgpt_plugin.py --final # also fails until review.demo_recording_url is filled inWhy the server needs no changes for the review #
- Every tool declares
readOnlyHint: true,destructiveHint: false,idempotentHint: true,openWorldHint: falseand atitle(they read fixed first-party catalogs). OpenAI's scan imports these and a submission justification cannot override them. - No sign-in: reviewers need no account. Responses carry no personal data, session ids or logs.
- The privacy policy (/privacy/), terms (/terms/), support contact (/contribute/) and website (/assistants/) are public.
- The MCP origin cannot change between versions (
https://mcp.cookwala.ai); only the path may. Do not move the endpoint to another host after publishing. - OpenAI rescans the server daily. New tools stay unavailable until approved; changed tools keep their old definition until the update passes. Keep existing input schemas working.
Steps to publish #
Things only the account owner can do are marked You.
- You: in the OpenAI Platform dashboard, complete individual or business verification. The listing name (
developerName, "Cookwala") should match the verified identity; editplugin.jsonif it differs. Submitting needs theapi.apps.writepermission (organization owners have it). Projects with EU data residency cannot submit; use a global-residency project. - Run
python tools/build_chatgpt_plugin.pyand take the ZIP frombuild/. - You: Plugins, Upload new or existing plugin, choose the developer identity, upload the ZIP. Fix validation errors by editing the package and uploading again. The category must be one of OpenAI's fixed titles (there is no food category, so the plugin uses
Other); the validator enforces the list. - You: MCPs, Connect. The server URL comes from
mcp.json; authentication is none. The portal then shows a domain-verification token. Publish it as plain text, and only the token, athttps://mcp.cookwala.ai/.well-known/openai-apps-challenge(or on the parenthttps://cookwala.ai/.well-known/openai-apps-challenge, which is a file insite/.well-known/served by GitHub Pages). Give the token to the agent or commit the file, wait for the site to publish, then Connect and let the tool scan run. Resolve any issue it lists, then Rescan. - You: record a short demo video that walks through the 5 positive and 3 negative cases (they are in
plugin.json), host it where reviewers can open it, put the URL inreview.demo_recording_url, run--final, rebuild the ZIP and upload it again ("Upload plugin to fix issues"). - You: run each positive case in ChatGPT yourself (after installing the draft) on desktop and mobile; output must match
expected_behaviorwith no errors. - You: Submit for review, accept the policy attestations, track the status and the emails. Only one review is active at a time. After approval choose Publish plugin.
Updating later #
- Server-only changes that keep the published contract go live with the daily scan, with no new ZIP. Redeploy the Worker, then Rescan to speed it up.
- Changes to listing text, icons or skills need a new version in
plugin.json, a new ZIP, review and Publish. - After editing a skill that names tools, deploy the server and rescan before submitting.
Known risks and decisions #
- Health content. The guidelines have no dedicated rule for allergy, diet or diabetes information, but results must be accurate and relevant and plugins may not collect protected health information. Cookwala collects none; the labels are screens, worded as "no allergen found" and "diabetic-friendly estimate", with advice to read labels and consult a clinician. The thresholds are not dietitian-reviewed.
- Age rating. Plugins must suit ages 13 to 17. Recipes with alcohol are filtered by
alcohol_freebut not removed; review if a reviewer objects. - Wording. No pricing, comparisons or unverifiable claims in the listing text. The long description avoids numbers it cannot back with the live catalog ("more than 2,000 recipes").
- Unverified details. Review times are not in the public documentation. The validator checks every limit that is documented, including the category list and the shape of the review test cases.