marketplace policy

version 1.0, effective 4 october 2026

The inference shell marketplace lists apps, agents, flows, skills, knowledge, MCP servers and other software ("Software") that buyers run through inference shell and through the tools that connect to it. We review Software before it is listed and keep reviewing it afterwards: automated checks on every version, periodic rescans, and human review. Listed Software must keep meeting this policy, including future changes to it.

Unlike some directories, the marketplace allows media generation (image, video, audio, 3D). It is a core use of inference shell. Media Software must still follow rule S8.

S. safety and security

IDRuleChecked by
S1Software must comply with the Terms of Service, including its acceptable use rules, and must not facilitate anyone else violating them.AI review, human
S2Software must not circumvent inference shell's sandbox, metering, billing, rate limits, spend limits or safety controls, or help a buyer do so.scan (INF-SEC-008, 015, 020), dynamic
S3Software must protect the privacy of buyers and third parties, handle personal and sensitive data responsibly, and comply with applicable privacy law.attestation, AI review
S4Software must collect only the data needed to perform its function. It must not collect extra conversation, agent context, or buyer data, even for logging.AI review, dynamic (egress)
S5Software must not read or extract a buyer's other data (knowledge, memory, chats, files, secrets, integrations, or other runs) beyond what the buyer passes in or explicitly grants.scan, AI review
S6Credentials must come only through declared secrets, integrations or OAuth. Software must never exfiltrate, log or hard-code them, and never read them from a buyer's machine.scan (INF-SEC-001, 011, 012, 022), CREDENTIAL_FROM_MACHINE
S7No malware, reverse shells, persistence, destructive commands, obfuscated or encoded payloads, or code that downloads and runs unreviewed code at run time.scan (INF-SEC-002–010, 013, 014, 021), RUNTIME_FETCH_EXEC
S8Software that generates or edits media depicting real people (face swap, voice clone, lip sync, likeness) must require the buyer to confirm consent or rights, and must not target sexual content involving real people or minors.AI review, human
S9Software must not infringe others' intellectual property, and must be permitted by the terms of every upstream API, model or dataset it uses.attestation, human

I. instructions and descriptions

These rules apply to anything that gives an AI model tools or behaviour through natural language: skills, knowledge, agent prompts, MCP tool descriptions, and app descriptions shown to agents (agent_description).

IDRuleChecked by
I1Each tool, function or capability is described narrowly and unambiguously: what it does and when to use it.AI review, TOOL_DESC_VAGUE
I2Descriptions match actual behaviour, with no undisclosed functionality and no promised features that don't exist.dynamic, AI review
I3Names and descriptions must not be confusable with other listings.NAME_CONFUSABLE
I4Software must not steer the model into calling other tools, listings or resources the user didn't ask for, and descriptions must not be written to attract extra calls.TOOL_DESC_STEERS, AI review
I5Software must not interfere with the model's use of other tools.AI review
I6Software must not instruct the model to fetch and follow behavioural instructions from external sources at run time.scan, AI review
I7No hidden, obfuscated, encoded or invisible instructions. All behavioural guidance must be human-readable.scan (INF-SEC-007, 009, 019)
I8Skills pre-approve only the tools they need, with paths scoped where the harness supports it.ALLOWED_TOOLS_UNSCOPED_WRITE

P. publisher requirements

IDRuleChecked by
P1Software that collects personal data or sends data to a service other than inference shell links a clear privacy policy covering collection, use and retention.PRIVACY_POLICY_MISSING
P2Publishers keep a verified contact email and a public support channel.publisher profile
P3Software is documented: what it does, its intended use, and how to troubleshoot it.DOCS_MISSING
P4Software that needs sign-in, secrets or seeded data gives reviewers working test access with sample data, through the submission's test-access fields.REQUIRES_AUTH + test access present
P5Submissions include working use cases that show core functionality: three for apps, agents, flows and MCP servers, and one for skills and knowledge. Use cases must pass when the reviewer runs them.dynamic
P6Publishers own or are authorized to use every endpoint, domain, API and external resource the Software connects to or renders. Proxying a partner's API with permission is allowed. Unauthorized scraping or reselling is not.attestation, dynamic (egress), human
P7Publishers maintain the Software, keep its dependencies available, and fix reported issues within the timeframes in the Publisher Terms.health monitoring
P8Publishers accept the current Publisher Terms.consent record

U. not allowed

Unless we agree otherwise in writing:

IDNot allowed
U1Moving money, cryptocurrency or other financial assets, or executing financial transactions on a buyer's behalf.
U2Advertising, sponsored content, paid placement, or Software whose main purpose is promotion.
U3Bulk unsolicited messaging, fake engagement, review or ranking manipulation.
U4Surveillance, stalking, people-search on private individuals, or covert tracking.
U5Crypto mining, or cracking credentials or systems the buyer isn't authorized to test.
U6Gambling or real-money games of chance.
U7Anything the Terms of Service acceptable use rules prohibit (including weapons, CSAM, non-consensual intimate imagery, and deceptive deepfakes).

T. type-specific requirements

IDTypeRuleChecked by
T1appOutputs match the declared output schema. Failures return a clear error, not a generic one.dynamic
T2appPricing expressions are valid and match what the app actually consumes. A failed run carries no marketplace fee.PRICING_INVALID, dynamic
T3appRequired secrets and integrations are declared in inf.yml. Nothing else is read.validation, dynamic
T4agent, flowEvery referenced app, agent, skill, MCP server or knowledge entry is public, and listed where possible. The model and harness are declared.DEP_NOT_PUBLIC, DEP_NOT_LISTED
T5agent, flowCost per run is bounded by a step or spend limit.validation
T6skill, knowledgeBundled scripts ship inside the listing. Nothing is downloaded and run at install or at run time.RUNTIME_FETCH_EXEC
T7mcpErrors are handled with helpful messages.dynamic
T8mcpResponses are token-frugal and proportionate to the task.dynamic (response size)
T9mcpTool names are at most 64 characters.validation
T10mcpServers that require sign-in use OAuth 2.0 over TLS with a certificate from a recognized authority.connect probe
T11mcpEvery tool has title, readOnlyHint and destructiveHint annotations, and the annotations are accurate.TOOL_ANNOTATIONS_MISSING, WRITES_MISMATCH
T12mcpServers support Streamable HTTP.connect probe

M. marketplace integrity

IDRuleChecked by
M1No artificial usage: calls from your own organizations, or scripted calls, earn nothing, and attempts to inflate usage lead to removal.billing (self-org exclusion), anomaly review
M2No bait-and-switch. A new version must keep the reviewed purpose. Material changes (purpose, new external hosts, new secrets, new write capability, broader tool grants) go back to human review.version diff (MATERIAL_CHANGE)
M3No name squatting, keyword stuffing, or impersonating other publishers or brands.NAME_CONFUSABLE, human
M4Listing text and media are accurate and not misleading.AI review, human

enforcement

OutcomeWhenEffect
Advisoryinfo or warning findingShown to the publisher and reviewer. Nothing is blocked
Holdhold finding, or a first versionGoes to human review. The live version stays up
Blockblock finding (for example a critical scan hit)The version cannot be submitted or published. Fix it at the source
Changes requestedA reviewer cites a rule IDThe publisher resubmits the same version, or a new one
RejectionA reviewer cites a rule IDThe version won't be listed. The publisher can appeal in the review thread
SuspensionSerious or repeated violation, security incident, or buyer harmThe listing is removed from discovery. Earnings may be withheld under the Publisher Terms
Publisher banMalicious Software, fraud, or repeated suspensionsAll of the publisher's listings are removed

Existing listings are rescanned whenever the rule set changes. A new finding on a live version starts the same flow; for a block finding on a live version, the listing is suspended until it's fixed.

we use cookies

we use cookies to ensure you get the best experience on our website. for more information on how we use cookies, please see our cookie policy.

by clicking "accept", you agree to our use of cookies.
learn more.