Agent skill

App Store Review

by safaiyeh in safaiyeh/app-store-review-skill

Evaluates code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill.

MITAuto-check passedMobile

Install App Store Review

skills CLI
$ npx skills add safaiyeh/app-store-review-skill --skill app-store-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install safaiyeh/app-store-review-skill app-store-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
app-store-review
GitHub stars
368
Used in
1 other repo
Token cost
~3.4k tokens
SKILL.md length
1,260 words
Files
16
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Evaluates code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill.

  • Works in 5 steps: Ask first. Say something like: "This… → Show the full draft (exact title and… → Never include the user's code, app name,… → …
  • VisionOS app code (Swift
  • SKILL.md covers When to Apply, Guideline Sections, Risk Levels by Category and Quick Reference: High-Risk…, plus 3 more sections
  • Calls gh; reaches stripe.com; needs API_KEY

What it does

App Store Review is an agent skill from safaiyeh/app-store-review-skill. Evaluates code against Apple's App Store Review Guidelines. Use this skill when reviewing iOS, macOS, tvOS, watchOS, or visionOS app code (Swift, Objective-C, React Native, or Expo) to identify potential App Store rejection issues before submission. Triggers on tasks involving app review preparation, compliance checking, or App Store submission readiness.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files (for example `.agents/plugins/marketplace.json`, `.claude-plugin/marketplace.json` and `.claude-plugin/plugin.json`).

It sits in Mobile, covering App store release and Cross-platform mobile apps. It works with Expo, React Native, Objective-C and iOS. The repository describes itself as: Skill to validate your codebase against Apple App Review. The licence is MIT.

When your agent uses it

  • VisionOS app code (Swift
  • Expo) to identify potential App Store rejection issues before submission
  • Tasks involving app review preparation
  • Compliance checking

Example prompts

  • “Use the app-store-review skill to evaluate code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill”
  • “/app-store-review”

Requirements

  • A credential in API_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Ask first. Say something like: "This looks like a gap in the app-store-review skill itself. Want me to draft a GitHub issue so the…
  2. Show the full draft (exact title and body) before anything is sent.
  3. Never include the user's code, app name, bundle IDs, file paths, credentials, or proprietary details. The report is about this skill's…
  4. Send only after the user approves the exact text, using gh issue create --repo safaiyeh/app-store-review-skill --title "..." --body "..."…
  5. Never send feedback silently, automatically, or as a side effect of another task. A declined permission prompt means no — do not retry or…

What it can do on your machine

Read from SKILL.md and the folder at commit 7535ac5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • stripe.com

    Also links to:

    • developer.apple.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

App Store Review loads about 3.4k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 1,260 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from safaiyeh/app-store-review-skill at commit 7535ac5, republished under its MIT licence (© safaiyeh). 1,260 words, ~3,379 tokens.

Download SKILL.mdSave it as .claude/skills/app-store-review/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.
name
app-store-review
description
Evaluates code against Apple's App Store Review Guidelines. Use this skill when reviewing iOS, macOS, tvOS, watchOS, or visionOS app code (Swift, Objective-C, React Native, or Expo) to identify potential App Store rejection issues before submission. Triggers on tasks involving app review preparation, compliance checking, or App Store submission readiness.
license
MIT
metadata.author
safaiyeh
metadata.version
1.3.3

App Store Review Guidelines Checker

Comprehensive guide for evaluating iOS, macOS, tvOS, watchOS, and visionOS app code against Apple's App Store Review Guidelines. This skill covers EVERY guideline point to identify potential rejection issues before submission.

Supports: Swift, Objective-C, React Native, and Expo apps

Guidelines current through: Apple's June 8, 2026 App Review Guidelines update (verified still current as of August 29, 2026). Also incorporates post-June policy announcements: social media age-rating questions (mandatory September 2026), Republic of Korea age rating changes (August/October 2026), and Brazil/EU alternative payment and distribution terms.

When to Apply

Use this skill when:

  • Preparing an app for App Store submission
  • Reviewing code for compliance issues
  • Implementing features that may trigger review concerns
  • Auditing existing apps for guideline violations
  • Building features involving payments, user data, or sensitive content

Guideline Sections

Read individual rule files for detailed explanations, checklists, and code examples:

SectionFileKey Topics
1. Safetyrules/1-safety.mdObjectionable content, UGC moderation, Kids Category, physical harm, data security
2. Performancerules/2-performance.mdApp completeness, metadata accuracy, hardware compatibility, software requirements
3. Businessrules/3-business.mdIn-app purchase, subscriptions, cryptocurrencies, other business models
4. Designrules/4-design.mdCopycats, minimum functionality, spam, extensions, Apple services, login
5. Legalrules/5-legal.mdPrivacy, data collection, intellectual property, gambling, VPN, MDM, developer code of conduct

Risk Levels by Category

Risk LevelCategorySectionCommon Rejection Reasons
CRITICALPrivacy & Data5.1Missing privacy policy, unauthorized data collection
CRITICALPayments3.1Bypassing in-app purchase, unclear pricing
HIGHSafety1.xObjectionable content, inadequate UGC moderation
HIGHPerformance2.xCrashes, incomplete features, deprecated APIs
MEDIUMDesign4.xCopycat apps, minimum functionality issues
MEDIUMLegal5.xIP violations, gambling without license

Quick Reference: High-Risk Rejection Patterns

For ATT findings, verify the SDK's configuration and actual data use. For account deletion, verify the destination and flow. For logging, inspect the data exposed and any redaction. If that evidence is unavailable, report what needs verification instead of declaring a rejection based on an API call, SDK import, or URL alone.

Critical Issues (Immediate Rejection)

Swift:

swift
// 🔴 Private API usage
let selector = NSSelectorFromString("_privateMethod")

// 🔴 Hardcoded secrets
let apiKey = "sk_live_xxxxx"

// 🔴 External payment for digital goods
func purchaseDigitalContent() {
    openStripeCheckout() // Use StoreKit instead
}

React Native / Expo:

typescript
// 🔴 Hardcoded secrets in JS bundle
const API_KEY = 'sk_live_xxxxx'; // REJECTION

// 🔴 External payment for digital goods
Linking.openURL('https://stripe.com/checkout'); // Use react-native-iap

// 🔴 Dynamic code execution
eval(downloadedCode); // REJECTION

// 🔴 Major feature changes via CodePush/expo-updates
// OTA updates for bug fixes only, not new features!
High-Risk Issues

Swift:

swift
// 🟡 Starting Apple-defined tracking without ATT authorization
// Illustrative helper: links user data across companies for ad targeting
enableCrossCompanyAdTracking() // Called before ATT authorization

// 🟡 Account creation without deletion
func createAccount() { } // But no way to initiate deletion in the app

React Native / Expo:

typescript
// 🟡 Starting Apple-defined tracking without ATT authorization
// Illustrative helper: SDK links user data across companies for ad targeting
initializeTrackingAdSDK(); // Called before ATT authorization

// ✅ First-party analytics alone does not require ATT
// Assumes no IDFA access, cross-company advertising use, or data broker sharing
import analytics from '@react-native-firebase/analytics';
analytics().logEvent('event');

// 🟡 Delete Account button opens instructions with no deletion flow
Linking.openURL('https://example.com/help'); // Verified instructions-only page
// ✅ An in-app button may link directly to a page that completes deletion
Linking.openURL('https://example.com/delete-account');

// 🟡 Sensitive data exposed in production logs (1.6 / 5.1)
console.log('Access token:', accessToken); // Remove the secret or redact it

// 🟡 Social login without a privacy-preserving alternative (4.8)
<GoogleSigninButton /> // Also offer a login meeting 4.8 criteria
                       // (Sign in with Apple is the simplest option)

// 🟡 Pre-permission button that asks for the grant (5.1.1(iv))
<Button title="Enable Location" onPress={requestLocation} /> // Use "Continue" or "Next"

// 🟡 Custom review prompts (5.6.1)
showCustomAlert('Rate us 5 stars!'); // Use StoreReview.requestReview()
Medium-Risk Issues
typescript
// 🟠 Vague purpose strings in Info.plist
"This app needs camera access" // Be specific!

// 🟠 WebView-only app (insufficient native functionality)
const App = () => <WebView source={{ uri: 'https://site.com' }} />;

// 🟠 References to Android in iOS app
const text = "Also available on Android"; // REJECTION

Pre-Submission Checklist

Privacy (Section 5.1)
  • Privacy policy link in App Store Connect
  • Privacy policy link accessible within app
  • All purpose strings are specific and accurate
  • App Privacy details completed in App Store Connect
  • ATT authorization obtained before Apple-defined tracking or IDFA access (see 5.1.2); first-party analytics alone does not require ATT
  • If app supports account creation, deletion can be initiated in-app; a direct link to complete deletion on the web is allowed
  • Data minimization - only requesting necessary permissions
  • Custom screens before a permission prompt have only one button, labeled neutrally (e.g. "Continue" or "Next"), that opens the system prompt; no "Allow"/"Enable" wording or Cancel/Close actions (see 5.1.1(iv))
  • User consent obtained before data collection
Payments (Section 3.1)
  • StoreKit used for all digital purchases
  • Restore purchases implemented
  • Subscription terms clearly displayed
  • Loot box odds disclosed if applicable
  • No external payment for digital goods (unless entitled)
  • Credits/currencies don't expire
Safety (Section 1.x)
  • No objectionable content
  • UGC moderation implemented (filter, report, block, contact)
  • UGC violations can be removed quickly and backed by a remediation plan
  • Kids and teens receive age-appropriate experiences inside the app
  • Parental gates for Kids Category apps
  • No false information or prank features
  • Medical disclaimers if applicable
  • No substance promotion
Performance (Section 2.x)
  • Age rating questionnaire's social media capability questions answered (mandatory for submissions starting September 2026; apps with a social feed get a "Social Media" descriptor and Time Allowances category)
  • No crashes or bugs
  • Tested on both iPhone and iPad — App Review currently reviews on iPad Air 11-inch (M3) and iPhone 17 Pro Max (as of August 2026)
  • All features complete and functional
  • No placeholder content
  • IPv6 tested and functional
  • Demo account provided if needed
  • Using only public APIs
  • No deprecated APIs
  • Proper background mode usage
Design (Section 4.x)
  • Sufficient native functionality (not just web wrapper)
  • No copycat concerns
  • Original app name and branding
  • No duplicate Bundle ID spam or low-effort saturated-category clones
  • Live Activities, push notifications, and Game Center are not used for spam, phishing, or unsolicited messages
  • Extensions comply with guidelines
  • Login alternatives if using social login
  • Not monetizing built-in capabilities
  • No unlicensed third-party content
  • Proper Apple trademark usage
  • Gambling license if applicable (with real location-based geo-restriction)
  • VPN uses NEVPNManager API
  • COPPA/GDPR compliance for kids
  • Review prompts use the system API only (no custom prompts)
  • No review, chart, search, or referral manipulation (5.6)

Show full SKILL.md (530 more words)Show less

Reporting Skill Issues (Feedback)

This skill improves through user reports. If during a session you observe that this skill failed the user, offer — once per session — to report it to the maintainer.

Offer feedback when you observe any of these. Classify with the category name — it goes in the issue title as [Feedback] <category>: <short description>.

Accuracy

  • False positive — the skill flagged code that is actually compliant (guidance too aggressive)
  • False negative — the user's app was rejected for something the skill reviewed but didn't flag
  • Wrong citation — a real issue, but attributed to the wrong guideline section or given the wrong risk level
  • Outdated — a rule here contradicts Apple's current published guidelines

Usefulness

  • Too noisy — a flood of low-value or duplicate findings drowned out the ones that mattered
  • Not actionable — a finding lacked the detail, code reference, or concrete fix needed to act on it
  • Bad fix — a suggested remediation was wrong, deprecated, didn't work, or would itself be rejected (including Swift vs React Native/Expo specifics)

Coverage

  • Missing rule — a review scenario, API, or storefront-specific requirement (EU, Brazil, Korea, US, ...) the skill doesn't cover
  • Contradiction — two parts of this skill disagree with each other

Behavior

  • Trigger/weight — the skill activated when irrelevant, failed to activate when it should have, or consumed excessive context
  • Unclear — the user found guidance confusing, ambiguous, or hard to apply

Softer signals count too: if the user repeatedly dismisses the same kind of finding, overrides the skill's advice and turns out to be right, or visibly works around a checklist item, that is feedback worth offering to file — micro-friction is as valuable as a wrong rule.

Consent rules — all mandatory, no exceptions:

  1. Ask first. Say something like: "This looks like a gap in the app-store-review skill itself. Want me to draft a GitHub issue so the maintainer can fix it?" If the user declines, drop it for the rest of the session.
  2. Show the full draft (exact title and body) before anything is sent.
  3. Never include the user's code, app name, bundle IDs, file paths, credentials, or proprietary details. The report is about this skill's rules, not the user's app. Only include such details if the user explicitly writes them into the draft themselves.
  4. Send only after the user approves the exact text, using gh issue create --repo safaiyeh/app-store-review-skill --title "..." --body "...". If gh is unavailable or unauthenticated, give the user this link to file it themselves: https://github.com/safaiyeh/app-store-review-skill/issues/new?template=skill-feedback.yml
  5. Never send feedback silently, automatically, or as a side effect of another task. A declined permission prompt means no — do not retry or find another route.

Issue content: skill version (from the frontmatter above), the feedback category, the rule section involved (e.g. "3.1.1"), what the skill said or did, what should have happened instead, and today's date. Nothing else unless the user adds it.


References

© safaiyeh, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 15 other files in the repository root of safaiyeh/app-store-review-skill.

  • SKILL.md
  • .agents/plugins/marketplace.json
  • .claude-plugin/marketplace.json
  • .claude-plugin/plugin.json
  • .codex-plugin/plugin.json
  • .github/ISSUE_TEMPLATE/skill-feedback.yml
  • .gitignore
  • LICENSE
  • README.md
  • agents/openai.yaml
  • metadata.json
  • rules/1-safety.md
  • rules/2-performance.md
  • … and 3 more

Open the folder on GitHubat commit 7535ac5

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in safaiyeh/app-store-review-skill, which our catalogue first saw on October 7, 2026.

Compare with similar skills

App Store Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

App Store Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
App Store Review this skillsafaiyeh/app-store-review-skill3681 repos~3.4kAutomated safety check: PassMIT
Simfleetentropyconquers/simfleet118—~1.5kAutomated safety check: PassMIT
Iapkit E2E Martiehyodotdev/openiap155—~5.4kAutomated safety check: NotesMIT
Eas App Storesexpo/skills2.7k—~1.9kAutomated safety check: PassMIT
Limrun Xcodesuperset-sh/superset15k—~6.5kAutomated safety check: NotesCustom licence
Eas App Storessickn33/agentic-awesome-skills47k1 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Simfleet

    entropyconquers/simfleet

    Operate a simfleet device fleet: slimmed iOS simulators and Android emulators, parallel React Native worktree lanes with leased Metro ports, the native build cache, and per-agent device claims.

    118 GitHub stars~1.5k tokensUpdated 12 days ago
    MobileAuto-check passed
  • Iapkit E2E Martie

    hyodotdev/openiap

    Run IAPKit local receipt-validation E2E with the dev.hyo.martie React Native or Expo examples, the compiled packages/kit server, real Convex, and Apple or Google sandbox purchases.

    155 GitHub stars~5.4k tokensUpdated yesterday
    MobileAuto-check: notes
  • Eas App Stores

    expo/skills

    Official

    Build and submit iOS and Android apps with EAS to TestFlight, the App Store, or Google Play.

    2.7k GitHub stars~1.9k tokensUpdated 3 days ago
    MobileAuto-check passed
  • Limrun Xcode

    superset-sh/superset

    Build an iOS / Apple app on remote Xcode with lim xcode build instead of local xcodebuild, run project commands with lim xcode run, or run its XCTest suites with lim xcode test, from any environment…

    15k GitHub stars~6.5k tokensUpdated today
    MobileAuto-check: notes
  • Eas App Stores

    sickn33/agentic-awesome-skills

    Curated upstream guidance for Eas App Stores; use when the workflow matches the user goal.

    47k GitHub starsUsed in 1 repo~1.9k tokens
    MobileAuto-check passed
  • Mobile App Developer

    happycapy-ai/Happycapy-skills

    End-to-end mobile app development and publishing using Expo + EAS.

    137 GitHub stars~1.3k tokensUpdated 1 mo ago
    MobileAuto-check passed

Categories

Questions about App Store Review

What does App Store Review do?

Evaluates code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill. App Store Review is an agent skill from safaiyeh/app-store-review-skill. Evaluates code against Apple's App Store Review Guidelines.

When should I use App Store Review?

App Store Review fits situations like: visionOS app code (Swift; expo) to identify potential App Store rejection issues before submission; tasks involving app review preparation; compliance checking.

How do I install App Store Review in Claude Code?

Run `npx skills add safaiyeh/app-store-review-skill --skill app-store-review -a claude-code`. Or copy the skill folder (the safaiyeh/app-store-review-skill repository) into .claude/skills/app-store-review in your project. Claude Code loads it when a task matches its description.

How do I install App Store Review in Codex?

Run `npx skills add safaiyeh/app-store-review-skill --skill app-store-review -a codex`. Or copy the skill folder (the safaiyeh/app-store-review-skill repository) into .agents/skills/app-store-review in your project. Codex loads it when a task matches its description.

Can I use App Store Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add safaiyeh/app-store-review-skill --skill app-store-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/app-store-review, .gemini/skills/app-store-review, .github/skills/app-store-review and .opencode/skills/app-store-review in your project.

What does App Store Review need to run?

Going by SKILL.md and its folder, App Store Review needs the command-line tools its instructions call (gh) and credentials named API_KEY. Our summary lists: A credential in API_KEY.

Does App Store Review access the network?

SKILL.md names 2 domains. In commands or code: stripe.com; the agent is likely to contact it when it follows the instructions. As links in the text: developer.apple.com. This is read from the text; nothing was executed.

Is App Store Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does App Store Review use?

App Store Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does App Store Review use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to App Store Review?

Skills that share tags, products or a category with App Store Review: Simfleet (entropyconquers/simfleet, 118 stars), Iapkit E2E Martie (hyodotdev/openiap, 155 stars), Eas App Stores (expo/skills, 2.7k stars) and Limrun Xcode (superset-sh/superset, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains App Store Review?

safaiyeh (a GitHub user) maintains it in safaiyeh/app-store-review-skill, which has 368 GitHub stars. The repository was last updated on October 6, 2026.

Source: safaiyeh/app-store-review-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.