Agent skill

Appstore Review Checker

by luongnv89 in luongnv89/skills

Audit iOS/macOS apps against App Store Review Guidelines before submission, with evidence-backed verdicts and fixes.

MITAuto-check passedMobile

Install Appstore Review Checker

skills CLI
$ npx skills add luongnv89/skills --skill appstore-review-checker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install luongnv89/skills appstore-review-checker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/appstore-review-checker .claude/skills/appstore-review-checker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
appstore-review-checker
GitHub stars
131
Token cost
~2.7k tokens
SKILL.md length
1,197 words
Files
14 (incl. references)
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Audit iOS/macOS apps against App Store Review Guidelines before submission, with evidence-backed verdicts and fixes.

  • Works in 4 steps: Understand the App → Run the Audit → Generate the Report → …
  • General code review
  • SKILL.md covers Why This Matters, Prerequisites, Environment Check and Reference Index, plus 11 more sections
  • Calls git

What it does

Appstore Review Checker is an agent skill from luongnv89/skills. Audit iOS/macOS apps against App Store Review Guidelines before submission, with evidence-backed verdicts and fixes. Don't use for Google Play, general code review, or rejection appeals.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files (for example `agents/fixer.md`, `agents/guideline-auditor.md` and `agents/project-explorer.md`).

It sits in Mobile, covering App store release. It works with iOS and macOS. The repository describes itself as: Supercharge your AI agents/bots with reusable skills. The licence is MIT.

When your agent uses it

  • General code review
  • Rejection appeals

Example prompts

  • “/appstore-review-checker”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Understand the App
  2. Run the Audit
  3. Generate the Report
  4. Offer to Fix

What it can do on your machine

Read from SKILL.md and the folder at commit b5ef695. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Appstore Review Checker loads about 2.7k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 1,197 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from luongnv89/skills at commit b5ef695, republished under its MIT licence (© luongnv89). 1,197 words, ~2,664 tokens.

Download SKILL.mdSave it as .claude/skills/appstore-review-checker/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
appstore-review-checker
description
Audit iOS/macOS apps against App Store Review Guidelines before submission, with evidence-backed verdicts and fixes. Don't use for Google Play, general code review, or rejection appeals.
license
MIT
effort
high
metadata.version
1.4.0
metadata.author
Luong NGUYEN <luongnv89@gmail.com>

App Store Review Checker

You are an expert App Store compliance auditor. Your job is to analyze an iOS/macOS app project and produce a comprehensive audit report against Apple's App Store Review Guidelines, catching issues that would cause rejection before the developer submits.

Why This Matters

Apple rejects roughly 25% of all app submissions. Each rejection-resubmission cycle can cost a week or more. Most rejections are for predictable, detectable issues — privacy policy missing, metadata problems, IAP misconfiguration, missing account deletion. Catching these before submission saves significant time.

Prerequisites

Before running this skill, confirm:

  • Project access — Read access to the iOS/macOS Xcode project (or at minimum, App Store Connect metadata). If neither is available, stop and ask the user; do not proceed.
  • Tools available — Read, Glob, Grep for static analysis. The Agent tool is required for the recommended subagent flow; without it, fall back to single-conversation mode.
  • Write target confirmed — The audit writes APPSTORE_AUDIT.md to the project root. Confirm with the user before overwriting an existing report.
  • No secrets exposure — Never read or echo App Store Connect API keys, signing certificates, or *.p8/*.p12 files.
  • Scope confirmation — Static analysis only. Do not execute code, install dependencies, or run xcodebuild.

Environment Check

This skill has two modes:

  • With Subagent Architecture (Recommended): If the Agent tool is available, the audit runs via a 4-phase subagent workflow for maximum accuracy and depth. See references/subagent-architecture.md.
  • Without Subagent Tool (Fallback): If Agent is not available, run a complete audit in a single conversation. The end result (APPSTORE_AUDIT.md) is the same.

Reference Index

Load only the reference you need for the current step — keep the working context lean.

  • references/subagent-architecture.md — 4-phase agent design, responsibilities, data flow, output artifacts
  • references/audit-workflow.md — Phase-by-phase workflow detail (files to read, code patterns, app classification, report format, verdict criteria)
  • references/example-output.md — Example APPSTORE_AUDIT.md snippet showing FAIL/WARNING entries
  • references/edge-cases.md — Handling no-source, metadata-only, existing rejection, Kids Category, Catalyst, multi-target
  • references/quality-checks.md — Acceptance criteria, step completion report format, static-audit limits, common red-flag patterns
  • references/final-report.md — Final Report status rules, examples, fill rules and reader checks
  • references/guidelines.md — Full 150+ App Store guideline checklist plus Top 20 Rejection Triggers

Repo Sync Before Edits (mandatory)

When the audit target is a git worktree, Phase 3 writes APPSTORE_AUDIT.md at its root and Phase 4 edits project files — sync the branch before the first write (PROJECT_DIR is the audited project's root):

bash
branch="$(git -C "$PROJECT_DIR" rev-parse --abbrev-ref HEAD)"
git -C "$PROJECT_DIR" fetch origin && git -C "$PROJECT_DIR" pull --rebase origin "$branch"

If the tree is dirty: stash (-u), sync, pop. If origin is missing or the rebase conflicts, stop and ask the user. Not a git repo at all — or a metadata-only audit with no checkout? Skip this step; the report then writes to the working directory the user names.

Audit Workflow (Summary)

The audit always runs through four phases. Full detail is in references/audit-workflow.md.

Phase 1: Understand the App

Read project config (pbxproj, Info.plist, entitlements, Podfile/Package.swift), scan source for privacy/IAP/auth/UGC/push/web-view/background/network patterns, then classify the app (general/game/kids, IAP/subs, UGC, regulated, extensions, AR/streaming, etc.) so you know which guideline sections apply.

Phase 2: Run the Audit

Load references/guidelines.md. For each guideline, assign one of PASS / FAIL / WARNING / N/A. Start with the "Top 20 Rejection Triggers" at the bottom of that file. Always cite specific evidence — file path, line number, config key, or metadata field. Never use vague language like "might have issues."

Phase 3: Generate the Report

Write APPSTORE_AUDIT.md to the project root using the format in references/audit-workflow.md and the example in references/example-output.md. The report begins with one verdict — LIKELY PASS, AT RISK, or LIKELY REJECT — and ends with a numbered pre-submission checklist.

Phase 4: Offer to Fix

After presenting the report, offer to implement code-level fixes (privacy descriptions, restore-purchases, account-deletion flow, UIWebView → WKWebView). Confirm explicit user approval per FAIL ID before editing any file. Provide exact text/configuration for metadata changes. Never modify .entitlements or App Store Connect configuration.

Error Handling & Confirmation

  • Missing project files — If *.xcodeproj, Info.plist, or source code cannot be located, stop and ask the user for the correct path. Do not guess.
  • Ambiguous evidence — If a guideline cannot be verified from static analysis (e.g., runtime crashes, screenshot accuracy), mark the verdict as WARNING and list it under "requires manual verification" — never invent a PASS or FAIL.
  • Destructive actions — Before any Edit/Write in Phase 4, restate the FAIL ID and the change you plan to make, and wait for the user to confirm. If the user says no, skip that fix and continue.
  • Conflicting findings — If two guidelines yield contradictory verdicts on the same artifact, mark both as WARNING and surface the conflict in the report.
  • Existing report — If APPSTORE_AUDIT.md already exists, ask before overwriting; offer to write to APPSTORE_AUDIT_v2.md instead.
Show full SKILL.md (440 more words)Show less

Expected Output

The skill produces APPSTORE_AUDIT.md at the project root. Minimal expected shape:

markdown
# App Store Review Audit Report

**App:** NutriTrack – Meal Planner
**Date:** 2026-04-19
**Platform:** iOS 16+

## Verdict: LIKELY REJECT

- Total checks: 47 | Pass: 38 | Fail: 2 | Warning: 5 | N/A: 2

## Critical Issues (FAIL)

### 5.1.1-v-delete — Account Deletion
**Verdict:** FAIL
**Evidence:** `AccountViewController.swift:142` shows a "Delete Account" button calling `deleteAccountAPI()`, but `NetworkClient.swift:87` returns 501.
**Fix:** Implement two-step deletion flow (confirm → API → sign out → clear local data).

## Pre-Submission Checklist

1. [ ] Implement account deletion flow (5.1.1-v-delete)
2. [ ] Replace UIWebView with WKWebView (2.5.6)

Full example with warnings and metadata sections: references/example-output.md.

Verdict Criteria

Count the FAIL and WARNING verdicts, then apply the first row that matches. A Top 20 trigger is a guideline ID listed in Quick Reference: Top 20 Rejection Triggers in references/guidelines.md.

  1. LIKELY REJECT — At least one FAIL on a Top 20 trigger, or 3 or more FAILs.
  2. AT RISK — 1-2 FAILs, none on a Top 20 trigger; or 0 FAILs and 3 or more WARNINGs.
  3. LIKELY PASS — 0 FAILs and 0-2 WARNINGs.

Acceptance Criteria (Summary)

A successful run satisfies the full checklist in references/quality-checks.md. The non-negotiables:

  • APPSTORE_AUDIT.md exists at the project root.
  • Verdict line uses exactly LIKELY PASS, AT RISK, or LIKELY REJECT.
  • Every Top 20 rejection trigger has a verdict.
  • Every FAIL cites a specific file/line/config and gives a concrete actionable fix.
  • A numbered pre-submission checklist closes the report.
  • Static-analysis limits are explicitly declared (see references/quality-checks.md for the list of items requiring manual verification).
  • Phase 4 (Fixer) only runs after explicit user approval; no entitlements are modified.
  • The run ends with the four-line Final Report.

Review each Final Report against the reader checks in references/final-report.md as well as these correctness items.

Step Completion Reports

After each major phase, output a status report. Format and per-phase check names live in references/quality-checks.md (section "Step Completion Reports"). Use √ for pass, × for fail, — for context.

Final Report

End every run, stops included, with a four-line chat block after the last Step Completion Report. It summarizes the run; it never replaces APPSTORE_AUDIT.md.

text
Result: COMPLETE. Audited NutriTrack (iOS 16+); wrote APPSTORE_AUDIT.md; audit verdict LIKELY REJECT (2 FAIL, 5 WARNING).
Evidence: Read project.pbxproj, Info.plist, 1 entitlements file and 64 Swift files; 47 guidelines checked, each Top 20 trigger has a verdict; FAILs cite AccountViewController.swift:142 and LegacyBrowserViewController.swift:14.
Uncertainty: Static analysis only; runtime crashes, screenshot accuracy and backend deletion behavior are untested (listed under manual verification).
Decision: Approve fixes for FAIL IDs 5.1.1-v-delete and 2.5.6, or say none.
  • The first word after Result: is the run status: COMPLETE, PARTIAL or BLOCKED. The audit verdict (LIKELY PASS, AT RISK, LIKELY REJECT) is a separate value on the same line.
  • Use BLOCKED when no APPSTORE_AUDIT.md (or APPSTORE_AUDIT_v2.md) was written.
  • Use PARTIAL when the report exists but an applicable Acceptance Criteria item is unchecked.
  • Use COMPLETE when every applicable Acceptance Criteria item is checked.

Status rules, a PARTIAL and a BLOCKED example, fill rules and reader checks: references/final-report.md.

Edge Cases

See references/edge-cases.md for: no source code available, metadata-only audit, existing rejection notice, Kids Category app, StoreKit-without-IAP, multiple targets, macOS/Catalyst.

Common Red Flags

Quick-reference watch lists for privacy, IAP, metadata, and design red flags are in references/quality-checks.md (section "Common Patterns to Watch For"). Load it during Phase 2 to speed up triage.

Tone and Delivery

Be direct and helpful, like a senior iOS developer doing a pre-submission review for a colleague. Don't sugarcoat — a rejected app costs more time than honest feedback. Acknowledge what's done well, and prioritize fixes by impact: rejection-causing issues first, then warnings, then nice-to-haves.

© luongnv89, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (references) in skills/appstore-review-checker of luongnv89/skills.

  • SKILL.md
  • agents/fixer.md
  • agents/guideline-auditor.md
  • agents/project-explorer.md
  • agents/report-writer.md
  • docs/README.md
  • evals/evals.json
  • references/audit-workflow.md
  • references/edge-cases.md
  • references/example-output.md
  • references/final-report.md
  • references/guidelines.md
  • references/quality-checks.md
  • references/subagent-architecture.md

Open the folder on GitHubat commit b5ef695

Compare with similar skills

Appstore Review Checker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Appstore Review Checker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Appstore Review Checker this skillluongnv89/skills131—~2.7kAutomated safety check: PassMIT
Releasevaayne/mori303—~1.2kAutomated safety check: PassMIT
Appstore Releasekmworks/kmreader113—~2.5kAutomated safety check: PassMIT
Publish App Store VersionKeeForge/KeeForge117—~3.5kAutomated safety check: PassGPL-3.0
Prepare ReleaseKeeForge/KeeForge117—~572Automated safety check: PassGPL-3.0
App Store Screenshots GeneratorParthJadhav/app-store-screenshots7.2k—~16kAutomated safety check: PassMIT

Similar skills

  • Release

    vaayne/mori

    Release workflow for Mori macOS workspace terminal and MoriRemote iOS app.

    303 GitHub stars~1.2k tokensUpdated 2 mo ago
    MobileAuto-check passed
  • Appstore Release

    kmworks/kmreader

    Coordinate the KMReader App Store release workflow. An agent skill from kmworks/kmreader.

    113 GitHub stars~2.5k tokensUpdated yesterday
    MobileAuto-check passed
  • Publish App Store Version

    KeeForge/KeeForge

    Prepare and publish an already-built KeeForge iOS or macOS version through the App Store Connect API using an API key.

    117 GitHub stars~3.5k tokensUpdated today
    MobileAuto-check passed
  • Prepare Release

    KeeForge/KeeForge

    Prepare the first KeeForge candidate for a new marketing version, including minor/major releases and patches or hotfixes to shipped versions.

    117 GitHub stars~572 tokensUpdated today
    MobileAuto-check passed
  • App Store Screenshots Generator

    ParthJadhav/app-store-screenshots

    Scaffolds a Next.js editor for designing App Store and Google Play screenshots as ads and exporting them at every required size, for iOS, Mac and Android.

    7.2k GitHub stars~16k tokensUpdated 2 days ago
    MobileAuto-check passed
  • App Store Preflight Skills

    truongduy2611/app-store-preflight-skills

    Scan an iOS/macOS Xcode project for common App Store rejection patterns before submission.

    1.4k GitHub stars~1.4k tokensUpdated 4 mo ago
    MobileAuto-check passed

More from luongnv89/skills

All 36 skills in this repo
  • Appstore Assets

    luongnv89/skills

    Generate App Store screenshots and header/search images for iPhone, iPad and Mac from a codebase or landing page, or re-render a set.

    131 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Dont Make Me Think

    luongnv89/skills

    Review UI usability using Steve Krug's principles and produce a scannable report.

    131 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Herdr Agent

    luongnv89/skills

    Manage AI agent fleets in Herdr: tile root + sub-agents in one tab, start/prompt/wait/read/monitor via the herdr agent CLI, steer any pane; help lists every operation.

    131 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Ollama Optimizer

    luongnv89/skills

    Optimize Ollama configuration for the current machine's hardware.

    131 GitHub stars~4.1k tokensUpdated today
    Auto-check: notes
  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • SEO AI Optimizer

    luongnv89/skills

    Audit and optimize websites for technical SEO, content SEO, and AI bot accessibility.

    131 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Works with

Questions about Appstore Review Checker

What does Appstore Review Checker do?

Audit iOS/macOS apps against App Store Review Guidelines before submission, with evidence-backed verdicts and fixes. Appstore Review Checker is an agent skill from luongnv89/skills. Audit iOS/macOS apps against App Store Review Guidelines before submission, with evidence-backed verdicts and fixes.

When should I use Appstore Review Checker?

Appstore Review Checker fits situations like: general code review; rejection appeals.

How do I install Appstore Review Checker in Claude Code?

Run `npx skills add luongnv89/skills --skill appstore-review-checker -a claude-code`. Or copy the skill folder (skills/appstore-review-checker in luongnv89/skills) into .claude/skills/appstore-review-checker in your project. Claude Code loads it when a task matches its description.

How do I install Appstore Review Checker in Codex?

Run `npx skills add luongnv89/skills --skill appstore-review-checker -a codex`. Or copy the skill folder (skills/appstore-review-checker in luongnv89/skills) into .agents/skills/appstore-review-checker in your project. Codex loads it when a task matches its description.

Can I use Appstore Review Checker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luongnv89/skills --skill appstore-review-checker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/appstore-review-checker, .gemini/skills/appstore-review-checker, .github/skills/appstore-review-checker and .opencode/skills/appstore-review-checker in your project.

What does Appstore Review Checker need to run?

Going by SKILL.md and its folder, Appstore Review Checker needs the command-line tools its instructions call (git).

Does Appstore Review Checker access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Appstore Review Checker safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Appstore Review Checker use?

Appstore Review Checker is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Appstore Review Checker use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Appstore Review Checker?

Skills that share tags, products or a category with Appstore Review Checker: Release (vaayne/mori, 303 stars), Appstore Release (kmworks/kmreader, 113 stars), Publish App Store Version (KeeForge/KeeForge, 117 stars) and Prepare Release (KeeForge/KeeForge, 117 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Appstore Review Checker?

luongnv89 (a GitHub user) maintains it in luongnv89/skills, which has 131 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 9, 2026.

Source: luongnv89/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.