검증된 AI Skills를 출처·설치 경로·검증 정보와 함께 탐색하는 카탈로그입니다.
GitHub, skills.sh, 국내 디렉터리에서 Agent Skills 표준 SKILL.md를 주기적으로
수집하고, 운영자 검토를 거친 항목만 공개합니다.
- Node.js
>=22.13.0
npm install
npm run dev
npm run build로컬 환경 변수 이름은 .env.example을 참고하세요. 운영 환경의 secret은
Sites runtime settings에서 관리합니다.
출시 전 검사는 다음 명령을 사용합니다.
npm run health:release1인 운영 절차와 중단 기준은 docs/one-person-runbook.md에
정리되어 있습니다.
- edit site code under
app/ .openai/hosting.jsondeclares Sites D1 and R2 bindingsvite.config.tssimulates declared bindings for local developmentdb/schema.tscontains catalog, approval, verification, quality, usage, backup, and workspace tablesworker/index.tsruns scheduled collection, summary generation, health monitoring, and retentionsandbox-adapter/verifies installation in an isolated Worker
Signed-in visitors receive both oai-authenticated-user-id and oai-authenticated-user-email. Private Sites require every visitor to sign in; public Sites may also have anonymous visitors, for whom neither header is present.
The user ID is stable for the same user on the same Site and different across Sites. Email and name are intended for display or contact purposes.
SIWC-authenticated workspace sites may also receive
oai-authenticated-user-full-name when the user's SIWC profile has a non-empty
name claim. The full-name value is percent-encoded UTF-8 and is accompanied by
oai-authenticated-user-full-name-encoding: percent-encoded-utf-8.
Treat the full name as optional and fall back to email when it is absent:
import { headers } from "next/headers";
export default async function Home() {
const requestHeaders = await headers();
const userId = requestHeaders.get("oai-authenticated-user-id");
const email = requestHeaders.get("oai-authenticated-user-email");
const encodedFullName = requestHeaders.get("oai-authenticated-user-full-name");
const fullName =
encodedFullName &&
requestHeaders.get("oai-authenticated-user-full-name-encoding") ===
"percent-encoded-utf-8"
? decodeURIComponent(encodedFullName)
: null;
const displayName = fullName ?? email;
// ...
}Import the ready-to-use helpers from app/chatgpt-auth.ts when the site needs
optional or required ChatGPT sign-in:
- Use
getChatGPTUser()for optional signed-in UI. - Use
requireChatGPTUser(returnTo)for server-rendered pages that should send anonymous visitors through Sign in with ChatGPT. - Use
chatGPTSignInPath(returnTo)andchatGPTSignOutPath(returnTo)for browser links or actions. - Pass a same-origin relative
returnTopath for the destination after sign-in or sign-out. The helper validates and safely encodes it. - Mark protected pages with
export const dynamic = "force-dynamic"because they depend on per-request identity headers.
Dispatch owns /signin-with-chatgpt, /signout-with-chatgpt, /callback, the
OAuth cookies, and identity header injection. Do not implement app routes for
those reserved paths. Routes that do not import and call the helper remain
anonymous-compatible.
SIWC establishes identity only; it does not prove workspace membership. Use the Sites hosting platform's access policy controls for workspace-wide restrictions, or enforce explicit server-side membership or allowlist checks.
Use SIWC for account pages, user-specific dashboards, saved records, and write actions tied to the current ChatGPT user. Leave public content anonymous.
npm run dev: start local developmentnpm run build: verify the vinext build outputnpm test: build the starter and verify its rendered loading skeletonnpm run db:generate: generate Drizzle migrations after schema changes