Planned scope
Harden and finish the ChatGPT in-chat Agent Bounties experience without weakening the paid-bounty protocol or representing policy-ineligible actions as review-safe. The shared app will gain host-mediated card download and external-link handling, accurate MCP action hints, bounded action-intent data handling and retention, and review-facing collectible-card language. The full post/fund/claim/submit/verify lifecycle remains available for explicit developer/private use and through first-party hosted wallet review. A distinct public-review configuration will expose only capabilities whose advertised tools and behavior genuinely match the current OpenAI plugin rules; MoonPay remains an authorized fiat-to-crypto on-ramp, not canonical bounty funding and not inherited approval for Agent Bounties.
Change class: R2 for durable action-intent validation/cleanup; R1/R0 for widget bridge, metadata, tests, and submission documentation. This notice authorizes no wallet action, funding, verification, settlement, deployment, or payment claim.
Affected contracts or workflows
Expected areas: crates/mcp-server/src/chatgpt_app.rs, site/chatgpt-bounty-feed-widget.html, focused MCP/widget tests, crates/api/src/main.rs action-intent validation/status/retention routes, privacy/submission documentation, and chatgpt-app-submission.json. No Solidity contract, canonical event rule, wallet authority, MoonPay/Coinbase custody boundary, or payout invariant will change. Widget navigation will use the MCP Apps bridge first; card image downloads will use the host-mediated download capability in ChatGPT and retain a standalone-browser fallback.
Open PR queue check
Inspected all open PRs before edits: #587 (owner, review required, conflicting; V4 monitoring/release evidence, with only a separate crates/api/src/main.rs area potentially sharing a file), #575/#568/#567/#565/#562 (owner, review required, conflicting/blocked; deployment and repair workflows, no expected product-surface overlap), and Dependabot #510/#509/#508/#507/#506/#505/#504/#503/#501 (blocked/review required; Cargo lockfiles or GitHub Actions only). No active external collaborator PR is waiting on these ChatGPT/MCP/widget contracts. #587 keeps its existing review requirement and exact V4 evidence boundary; this change will avoid its sections and resolve/rebase any textual conflict before review.
Contributor impact and repair path
No current PR should need semantic rework. If #587 is refreshed first and produces a textual conflict in crates/api/src/main.rs, rebase this branch and retain both the V4 readiness behavior and the isolated action-intent validation/cleanup routes. Contributors extending the ChatGPT widget should refresh the plugin metadata after resource/tool changes and run cargo test -p mcp-server chatgpt_app -- --nocapture, python scripts/check-site.py, focused API tests, and git diff --check. No collaboration branch is currently recommended; one can be created if useful non-main-ready overlap appears.
Collaboration branch expected?
No known collaboration branch needed.
Distribution feedback request
If you found Agent Bounties through a tool, agent, bounty, GitHub search, social link, or another contributor, please comment with how you found it and what made you consider participating. Did an AI agent, tool, prompt, link, label, scanner, or workflow route you here? What would make participation easier or more trustworthy? If the project is useful, starring the repo, reacting to useful bounties, and sharing it with other agent builders or bounty solvers helps attract more collaborators.
Planned scope
Harden and finish the ChatGPT in-chat Agent Bounties experience without weakening the paid-bounty protocol or representing policy-ineligible actions as review-safe. The shared app will gain host-mediated card download and external-link handling, accurate MCP action hints, bounded action-intent data handling and retention, and review-facing collectible-card language. The full post/fund/claim/submit/verify lifecycle remains available for explicit developer/private use and through first-party hosted wallet review. A distinct public-review configuration will expose only capabilities whose advertised tools and behavior genuinely match the current OpenAI plugin rules; MoonPay remains an authorized fiat-to-crypto on-ramp, not canonical bounty funding and not inherited approval for Agent Bounties.
Change class: R2 for durable action-intent validation/cleanup; R1/R0 for widget bridge, metadata, tests, and submission documentation. This notice authorizes no wallet action, funding, verification, settlement, deployment, or payment claim.
Affected contracts or workflows
Expected areas:
crates/mcp-server/src/chatgpt_app.rs,site/chatgpt-bounty-feed-widget.html, focused MCP/widget tests,crates/api/src/main.rsaction-intent validation/status/retention routes, privacy/submission documentation, andchatgpt-app-submission.json. No Solidity contract, canonical event rule, wallet authority, MoonPay/Coinbase custody boundary, or payout invariant will change. Widget navigation will use the MCP Apps bridge first; card image downloads will use the host-mediated download capability in ChatGPT and retain a standalone-browser fallback.Open PR queue check
Inspected all open PRs before edits: #587 (owner, review required, conflicting; V4 monitoring/release evidence, with only a separate
crates/api/src/main.rsarea potentially sharing a file), #575/#568/#567/#565/#562 (owner, review required, conflicting/blocked; deployment and repair workflows, no expected product-surface overlap), and Dependabot #510/#509/#508/#507/#506/#505/#504/#503/#501 (blocked/review required; Cargo lockfiles or GitHub Actions only). No active external collaborator PR is waiting on these ChatGPT/MCP/widget contracts. #587 keeps its existing review requirement and exact V4 evidence boundary; this change will avoid its sections and resolve/rebase any textual conflict before review.Contributor impact and repair path
No current PR should need semantic rework. If #587 is refreshed first and produces a textual conflict in
crates/api/src/main.rs, rebase this branch and retain both the V4 readiness behavior and the isolated action-intent validation/cleanup routes. Contributors extending the ChatGPT widget should refresh the plugin metadata after resource/tool changes and runcargo test -p mcp-server chatgpt_app -- --nocapture,python scripts/check-site.py, focused API tests, andgit diff --check. No collaboration branch is currently recommended; one can be created if useful non-main-ready overlap appears.Collaboration branch expected?
No known collaboration branch needed.
Distribution feedback request
If you found Agent Bounties through a tool, agent, bounty, GitHub search, social link, or another contributor, please comment with how you found it and what made you consider participating. Did an AI agent, tool, prompt, link, label, scanner, or workflow route you here? What would make participation easier or more trustworthy? If the project is useful, starring the repo, reacting to useful bounties, and sharing it with other agent builders or bounty solvers helps attract more collaborators.