khadinakbarlabs/mobile-app-builder
v1.3.9MIT
A mobile app agency for iOS and Android
1.2.1 — Anthropic review preparation (local candidate, 2026-10-03)
- Add Anthropic directory metadata, regenerated phone/M/UI-tile logo, brand guide and owner review brief.
- Add a standalone Anthropic preparation workflow and structural preflight (185 workflows total).
- Pin downloadable tools and use project-local no-download execution for installed app tools; correct the Expo doctor command.
- Add native folder file/size/name/path gates, regression checks and exact-package validation.
- User verification and subsequent source publication, portal checks and submission remain pending.
1.2.0 — Mobile App Agency (local candidate, 2026-10-03)
- Preserve the existing 179 workflows; add agency coordination, engineering ownership guard, Apify CLI research, design references and store asset production (184 total).
- Classify every workflow across eight departments and 31 subcategories; add twelve native specialist roles and portable role cards.
- Add evidence-based stage gates, file ownership, reusable handoffs, configurable Actor research and actual screenshot capture manifests.
- Polish the entry-point README while preserving the detailed workflow guide.
- Correct inherited review guidance to use neutral milestones and independent feedback; minimize analytics properties.
- Add tested catalog tools, synchronized native manifests and isolated release bundles. Hosted MCP source and deployment are unchanged.
- Local candidate only; public source integration, directory submission and availability remain separate actions.
Changelog
1.3.9 — 2026-10-04
- Package Claude without the 189 OpenAI-only per-skill UI metadata files, reducing its native payload from 501 to 312 files.
- Preserve all 189 workflows, 16 native specialists, resources, four readable helpers and selected branding; retain OpenAI metadata in canonical source and the other distributions.
- Use the same host-specific file selection for native branch staging and the Claude ZIP; add regression checks for selective exclusion, resource retention and symlink rejection.
- Clarify distribution-specific discovery in installed guides and update versioned installation links.
- The exact published commit needs a new Anthropic scan; local packaging and host discovery do not establish reviewer clearance or live directory availability.
1.3.8 — 2026-10-04
- Fix Claude inline component discovery: use the standard agents directory so the pinned host lists all 16 specialists alongside all 189 skills.
- Add a host inventory release gate and CI check; fail on omitted, unexpected or inconsistent component counts.
- Move publisher-only command instructions into canonical source guides and remove them from installed bundles; preserve all user workflows, resources and branding.
- Add static file/reference receipts and rejection of unresolved installed helper commands, local imports, resources and skill routes.
- A new exact-commit Anthropic scan is required to confirm whether the inventory policy hold clears; local discovery is separate from directory approval.
1.3.7 — 2026-10-04
- Keep the general Anthropic filesystem preflight and catalog generation in publisher source; preserve both as release gates and retain the installed preparation checklist/templates.
- Make the installed agency browser read only prepared catalog metadata, with file-size, symlink, schema, route and classification checks. It no longer scans skill files or taxonomy at runtime.
- Reject zero, negative, coerced or unsafe production App Store app IDs before constructing the signature verifier; use explicit consuming-app public identity configuration.
- Preserve all 189 workflows, 16 specialists, intelligence resources, selected artwork and valid directory metadata.
- Add installed CLI and malformed/symlinked catalog regression checks plus bundle exclusions across all four formats.
- Anthropic review holds and live availability require a new scan of the exact published source; a local pass does not establish approval.
1.3.6 — 2026-10-04
- Replace the remaining Supabase environment-key example with explicit owner-supplied public app configuration; reject secret/service-role keys in the mobile client.
- Fix magic-link session establishment with validated PKCE code exchange, cold/warm link handling, duplicate delivery protection and generic errors. Update session lifecycle and SDK 54 protected-route guidance.
- Keep the publisher HTML artwork preview in development source only; retain Markdown brand guidance, the selected icon and README banner in every bundle.
- Add behavioral regression tests for valid/invalid callbacks, provider failures, retries, duplicate deliveries and preview exclusion.
- The latest observed Anthropic 1.3.5 scan passed security but retains reviewer holds; no cleared-hold or publication claim is made for a new commit before its scan.
1.3.5 — 2026-10-04
- Replace the AI streaming example's ambient secret read with an explicit consuming-app provider adapter, retaining authentication, atomic quotas and bounded provider requirements.
- Keep installed Anthropic preparation tooling structural; move artwork byte inspection to a mandatory source-only release gate excluded from every bundle.
- Add regression coverage for separation of media reads, corrupt artwork rejection and provider credential boundaries.
- Clarify safe research command guidance without runnable unsafe shell examples. Preserve all intelligence workflows, 16 agents, 189 skills and valid directory listing fields.
- Local/package results and the exact fetched directory scan remain separate from Anthropic reviewer approval and live availability.
1.3.4 — 2026-10-03
- Preserve native project changes during App Clip setup; require scoped regeneration authorization and validate invocation routes.
- Replace obsolete App Clip size assumptions with current target-specific constraints.
1.3.3 — 2026-10-03
- Address seven OpenAI workflow warnings with scoped dependency authorization, allowlisted shortcut routing, verified on-device AI/toolchain guidance and anonymized public research.
- Add a regression test for external shortcut destinations and unknown IDs.
- Preserve 189 skills, 16 roles and the selected minimal logo.
1.3.2 — 2026-10-03
- Ship only the selected minimal logo and README banner; retain older artwork in development source.
- Clarify that AI-streaming and account-deletion examples belong to the consuming app, with explicit server-secret and app-session boundaries.
- Record actual Anthropic validation findings and distinguish image inspection from execution.
1.3.1 — 2026-10-03
- Polished the public README with a compact brand header, plain-language use cases, intelligence desk routes and direct native installation guidance.
- Clarified user-directed research data/provider handling and the dedicated Claude source branch.
- Prepared the GitHub release and Anthropic submission source with the same verified 189 workflows and 16 roles.
1.3.0 — 2026-10-03
- Added four intelligence workflows and specialist roles for Apple/Google Play, TikTok/Instagram/YouTube creators, TikTok/Meta/Google ads, and website SEO.
- Included 15 public portfolio Actor routes with CLI-verified metadata and latest-build input-schema snapshots; execution remains disabled by default.
- Added new-app, existing-app and focused-task entry paths with plain-language guidance and preservation of current apps.
- Simplified the brand toward a sleek minimal phone/developer symbol. Retained owner verification before publication and submission.
Unreleased
1.1.3 — 2026-09-06
- Added the credential-free Cloudflare Workers MCP source, deployment guide, submission data, and a repeatable live-contract verifier for
https://app-builder.khadinakbar.dev/mcp. - Hardened metadata validation to flag nested credential-shaped field names without returning submitted values; added a 100 KB request-body guard and safe error handling.
- Updated Worker runtime compatibility, redacted-query observability, dependency audit remediation, CI validation, privacy disclosure, manifests, and public documentation to match the remote MCP service.
1.1.0 — 2026-08-09
Added 14 growth/conversion/virality/retention skills (165 → 179 total), filling the layer that makes apps successful rather than merely shippable. Researched across X/Twitter (Cal AI growth playbook), Reddit iOS/Android/RN communities, and the routed review-collection technique.
design-onboarding-funnel— the sales-funnel onboarding archetype (Cal AI / Jake Castillo pattern), the deliberate conversion-maximizing counterpart to the existing activation-firstdesign-onboarding-quiz. Both postures now offered; builder chooses.build-review-routing+command-build-review-prompt— routed/smart review collection: ask satisfaction in-app, route happy users to the native App Store / Google Play review prompt, route unhappy users to private feedback. The technique that raises the public rating by changing who reaches the review surface.design-shareable-result-card— viral share artifacts (Wordle / Cal AI / Spotify Wrapped pattern), 1080×1920 Story format, implemented withreact-native-view-shot+expo-sharing.build-creator-program— creator-led TikTok/Spark-Ads acquisition (the Cal AI model: seed organic creators, repurpose viral organic content as paid Spark Ads).design-viral-loop— K-factor (K = i × c), give-get referrals, invite-to-unlock mechanics.design-retention-loop— D1/D7/D30 benchmarks, the Hook Model, streaks, investments.build-win-back-flow— lapsed/expired-trial/inactive recovery with Apple StoreKit 2 win-back offers and RevenueCat web checkout.design-lifecycle-messaging— coordinated push + email + in-app cadence with frequency capping (55% higher 90-day retention when coordinated).build-cancellation-flow— cancel survey + reason-matched save offers (saves 10–35% of cancellations).instrument-growth-funnel— the canonical install→activate→trial→convert→retain→refer funnel, event vocabulary, cohort discipline, 2026 RevenueCat benchmarks.set-up-ab-testing— experimentation infrastructure (the #1 cited growth lever; Cal AI ran 5 real experiments/month across 46 trigger points).design-push-strategy— earning the one-shot permission (pre-prompt → contextual → 55–65% opt-in), re-engagement content.run-paid-acquisition— Apple Search Ads (intent capture), TikTok Spark Ads, Meta Advantage+; CAC:LTV discipline.
Updated mobile-app-builder-ios-android (flagship router) to route growth/retention/virality work to the matching skill. Cross-referenced design-onboarding-quiz to the new sales-funnel alternative so both postures are discoverable. Default analytics recommendation is now PostHog (privacy-safe, no ATT trigger).
1.0.8 — 2026-08-07
- Renamed the cross-client plugin install identifier from
expo-mobile-app-buildertomobile-app-builderwhile keeping the public title Mobile App Builder and the existing GitHub repository URL. - Prepared a matching local Codex marketplace deployment so the plugin folder, manifests, marketplace selector, and installed identifier use the same normalized name.
1.0.7 — 2026-08-07
- Synchronized the portable Agent Plugins and OpenAI manifest keyword lists so the uploader does not need to override divergent Codex metadata during conversion.
- Rebuilt the OpenAI archive for the marketplace's Agent Plugins-to-Codex normalization path.
1.0.6 — 2026-08-07
- Added the vendor-neutral Agent Plugins 1.0 root
plugin.jsonwhile retaining OpenAI's required.codex-plugin/plugin.jsonentry point. - Repackaged the skills-only OpenAI upload as a dual-compatible root-layout archive with synchronized 1.0.6 metadata.
1.0.5 — 2026-08-07
- Rebuilt
design-onboarding-quizaround an activation contract, shortest path to value, question-utility ledger, visible answer-to-experience mapping, purposeful motion, truthful evidence, privacy-aware telemetry, accessibility, and a measurable iOS/Android test matrix. - Reworked
command-build-onboardinginto a test-first Expo workflow with versioned resume state, existing-user migration behavior, permission and monetization timing, reduced-motion support, and activation-path acceptance checks. - Updated the flagship mobile builder to treat onboarding-to-activation as part of the first complete vertical slice instead of assuming a fixed quiz or paywall sequence.
- Rebuilt the OpenAI skills-only upload package with the Developer Tools category, root-layout archive validation, extracted-package verification, 165 normalized skills, production branding, reviewer cases, and credential/private-path scans.
1.0.4 — 2026-08-05
- Renamed the public plugin title to Mobile App Builder and set its 26-character subtitle to Develop Android & iOS Apps across supported marketplace manifests.
1.0.3 — 2026-08-05
- Added
prepare-chatgpt-app-submission, a Codex-managed wrapper that delegates to OpenAI Developers' officialchatgpt-app-submissionskill for real MCP server repositories, enforces review checks, and blocks fabricated JSON for static plugins. - Expanded the public package inventory to 165 skills and documented the distinction between a static Agent Skills plugin and a ChatGPT Apps MCP server.
- Replaced the public composer icon with a modern cross-platform mobile-builder mark.
- Aligned the public package publisher with the verified business identity.
- Prepared a minimal single-root skills-only archive for Plugins Directory upload.
1.0.2 — 2026-08-05
- Renamed every supported marketplace-facing title to iOS/Android Mobile App Builder, exactly 30 characters, while preserving the stable
expo-mobile-app-builderinstall identifier. - Added SEO-focused iOS, Android, Expo, and React Native descriptions, keywords, and discovery tags.
- Added a standalone
mobile-app-builder-ios-androidflagship skill for skills.sh and Skills CLI discovery.
1.0.1 — 2026-08-05
- Made every referenced document travel with its skill during standalone Skills CLI installation.
- Bundled the credential-free scaffold planner inside
command-scaffold-appwhile retaining the repository helper. - Added release validation that rejects parent-relative paths and broken isolated-skill links.
1.0.0 — 2026-08-05
- Rebuilt the owner-authorized private mobile workflow bundle as a public, skills-only Expo package for iOS and Android.
- Added 163 cross-platform design, implementation, quality, platform, EAS, and release-readiness skills.
- Removed personal source references, private path examples, credential artifacts, and secret-shaped values.
- Added a public-safety audit, credential-free scaffold planner, Expo SDK 54 reference set, legal documents, and release controls.
- Added native manifests for Codex, Claude Code, and Cursor plus GitHub-backed Agent Skills distribution.
- Kept external directory submission and publication out of the package build process.