# dxapp Desk > Before dx build, paste or drop the dxapp.json of a DNAnexus app or applet. A free in-browser > check runs the dnanexus-integration agent skill's own offline validator, validate_dxapp.py, with > the same report and exit status as the Python; two metered lanes add judgement: a readiness > review, or a corrected manifest that the page validates again. URL: https://dxapp-desk.skillsafe.ai/ API: https://dxapp-desk.skillsafe.ai/api.html Tokens: https://dxapp-desk.skillsafe.ai/tokens.html Model: gpt-terra (the balanced GPT tier alias on SkillSafe) Source skill: @k-dense-ai/dnanexus-integration (k-dense-ai/scientific-agent-skills, MIT) - building and operating reproducible genomics workloads on DNAnexus with dx, dxpy, apps and applets. Not affiliated with DNAnexus. ## What runs free, in the browser A JavaScript port of skills/dnanexus-integration/scripts/validate_dxapp.py, checked against CPython 3.12, 3.13 and 3.14 on 30,000 fuzzed manifests with identical stdout, stderr and exit status (see NOTICE.txt). Options: --kind auto|app|applet, --strict, and the Python version whose JSON error wording to use. It reports, by JSON path: - metadata: name syntax; for apps a semantic version, inputSpec and outputSpec; - parameters: names matching ^[A-Za-z_][A-Za-z0-9_]*$, no duplicates, a known class, boolean optional, no default/suggestions/choices in outputSpec; - runtime: a file or code entry, interpreter bash or python3, distribution Ubuntu, release 20.04 or 24.04 (20.04 warned), AEE version "0"; - placement: top-level resources and runSpec.systemRequirements are deprecated; - dependencies: execDepends entries without a version or tag; - retry and timeout: restartableEntryPoints, maxRestarts below 10, known restartOn reasons, non-negative counts, timeoutPolicy units and values; - regions: provider-qualified names, systemRequirements in every region or none, one resource selector per entry point, non-empty allowedInstanceTypes without duplicates; - access: network as a host list (warns on "*"), project and allProjects levels, ADMINISTER, cross-project and developer access; - httpsApp ports within 443, 8080, 8081; - credential-looking values under keys like token, password, secret or private_key. The page adds its own labelled checks quoted from the skill's configuration reference (no timeoutPolicy, restartOn without maxRestarts, retrying AppError or "*", AppInsufficientResourceError upgrade prerequisites, instanceTypeSelector licensing, file defaults that are local paths or defaults that do not match their class, pip execDepends on Ubuntu 24.04, project access an app rarely needs, an app without regionalOptions, httpsApp authorization), an inputs.json skeleton for dx run --input-json-file, and the commands to repeat the check and build. ## The paid lanes Input: {"task": "review"|"fix", "facts": "", "manifest": "", "context"?, "question"?, "review"? (fix only)}. Values under credential-looking keys are replaced by "[redacted by dxapp Desk]" before anything leaves the browser. - review -> status blocked | fix_before_build | ready_to_build, a stance on every flag (confirmed, explained, dismissed, needs_owner), findings (ref, area, severity, evidence, action), at most six build steps, open questions, assumptions. - fix -> status fixed | fixed_with_gaps | cannot_fix, flag stances, changes (ref, path, change, why), the whole corrected manifest as a JSON object, what to confirm, open questions, assumptions. Missing facts become "[to fill: ...]" strings, never invented regions, instance types, hosts or versions. Every reply is reconciled in the page: each flag answered once, no validator error argued away, a status no looser than the stances, every number traceable to what was sent, build commands in the right form (--create-app only for apps), and for a fix: the same validator re-run on the corrected manifest, new issues, parameter names kept, nothing invented, no redaction marker left. ## Limits The validator is offline. It never checks that an instance type exists in a region, that an asset or project exists, or that dx build will succeed; the page says so and so does the prompt. inspect_dxpy.py (which introspects an installed dxpy) is not ported. ## Citation Kassis, T., Agarwal, V., He, Y., Patel, D., & Brueckner, A. M. (2026). Scientific Agent Skills: A Library of Procedural Knowledge for Research Agents. arXiv:2609.00065.