Pimp My IDE / garage dispatch
Back to garage
October 2, 2026 | chat interfaces / MCP

Do not squeeze a website into a chat bubble.

A public page, a model-readable resource, a controlled action, and a run receipt do different jobs. Split them before a chat host starts calling your service.

The page explains. The resource supplies context. The tool changes state. The receipt says what happened. One miniature homepage cannot carry all four.

A chat surface is not a smaller browser.

OpenAI now describes plugins as a package of reusable skills and connections to external services. Its current documentation tells builders to start with user goals, build tools before custom interface work, and make the workflow useful without a widget.[1]

That changes the design problem. A website can explain a product, support browsing, and provide a durable public address. A chat host may need one record, one action, or one result. Sending the whole homepage into that exchange adds presentation without defining authority.

Keep the public page. Build a separate contract for context and action.

Resources carry context, not permission.

The Model Context Protocol defines resources as application-driven context with unique URIs. A client can list, read, search, filter, or subscribe to resources. The protocol does not require one interface pattern.[2]

That makes a resource a good home for a document, schema, project summary, or other read target. Give each item a stable identifier and a useful media type. Do not turn every readable object into a callable action.

Tools need narrow verbs.

OpenAI's plugin guide recommends one tool for each distinct action. It calls for an action-oriented name, explicit input and output schemas, accurate safety annotations, and a handler that authorizes every request. It also says useful results should work without custom UI and should return stable identifiers for later calls.[1]

A tool named manage_project hides too much. Separate list_projects, get_project, and update_project. The first two can be read-only. The last one needs identity, scope, validation, confirmation when the change is costly, and a result that names the updated record.

The widget is still untrusted input.

OpenAI's security guide says plugin widgets run in an isolated iframe with a strict content security policy. It also tells servers to validate model-provided inputs, enforce scopes on every call, require confirmation for irreversible work, and keep secrets out of component properties and results.[3]

A polished card does not grant authority. Authorization belongs on the server. The visible control should tell the user what will happen, while the server checks whether it may happen.

Ship four tests, not one demo.

  1. Open the public page without chat and confirm that its explanation still works.
  2. List and read each resource by its stable URI.
  3. Call every tool with allowed, denied, stale, and malformed inputs.
  4. Check that each successful action returns a stable record ID, changed state, and correlation ID without secrets.

The transfer switch below drafts that contract. It does not create a plugin, connect an account, call a tool, or verify a deployment.

Interactive makeover / chat-surface transfer switch

Shift the representation.

This replaces one vague "make the site work in chat" task. Pick the surface under review, select the contract sections to request, and copy a handoff with every runtime field left open.

Surface controls

The shifter changes this teaching display. It does not connect to ChatGPT, an MCP client, or your server.

Representation
Contract sections to request
Representation rail

Public page

0 of 4 sections
What crosses

Explanatory copy, navigation, sources, and a durable public URL.

What must be tested

Readable HTML, keyboard use, narrow screens, and a useful no-script fallback.

Contract draft incomplete.

No contract section is selected. Start with identity.

A completed display means four request sections are present. It does not mean a plugin was built, reviewed, published, authorized, called, or observed.

Surface handoff

The completed state is template structure ready. Every bracketed endpoint, version, scope, fixture, result, and reviewer field still needs real evidence.

Sources read

Source log and evidence boundary
  1. OpenAI Developers, "Build an MCP server", read October 2, 2026. This supplies the current plugin workflow, tool-design requirements, safety annotations, server-side authorization, useful no-UI results, and stable-identifier guidance.
  2. Model Context Protocol specification, "Resources", version 2025-06-18 and read October 2, 2026. This supplies application-driven resource handling, unique URIs, list and read operations, templates, and optional change subscriptions.
  3. OpenAI Developers, "Security & Privacy", read October 2, 2026. This supplies the iframe, content security policy, least-privilege, consent, input validation, scope enforcement, logging, and irreversible-action guidance.
  4. Hacker News discussion item 49927747, "Sites in ChatGPT", read October 2, 2026. This was the discovery signal. The linked feature page was blocked by an automated browser check, so it supports none of the implementation claims above.

Evidence boundary. We read the current plugin guide, security guide, MCP resource specification, and discussion. We did not create or submit a plugin, connect an MCP server, authenticate an account, call a tool, or test the new Sites feature. The switch writes a review template only.