The inference shell marketplace lists apps, agents, flows, skills, knowledge, MCP servers and other software ("Software") that buyers run through inference shell and through the tools that connect to it. We review Software before it is listed and keep reviewing it afterwards: automated checks on every version, periodic rescans, and human review. Listed Software must keep meeting this policy, including future changes to it.
Unlike some directories, the marketplace allows media generation (image, video, audio, 3D). It is a core use of inference shell. Media Software must still follow rule S8.
S. safety and security
ID
Rule
Checked by
S1
Software must comply with the Terms of Service, including its acceptable use rules, and must not facilitate anyone else violating them.
AI review, human
S2
Software must not circumvent inference shell's sandbox, metering, billing, rate limits, spend limits or safety controls, or help a buyer do so.
scan (INF-SEC-008, 015, 020), dynamic
S3
Software must protect the privacy of buyers and third parties, handle personal and sensitive data responsibly, and comply with applicable privacy law.
attestation, AI review
S4
Software must collect only the data needed to perform its function. It must not collect extra conversation, agent context, or buyer data, even for logging.
AI review, dynamic (egress)
S5
Software must not read or extract a buyer's other data (knowledge, memory, chats, files, secrets, integrations, or other runs) beyond what the buyer passes in or explicitly grants.
scan, AI review
S6
Credentials must come only through declared secrets, integrations or OAuth. Software must never exfiltrate, log or hard-code them, and never read them from a buyer's machine.
No malware, reverse shells, persistence, destructive commands, obfuscated or encoded payloads, or code that downloads and runs unreviewed code at run time.
Software that generates or edits media depicting real people (face swap, voice clone, lip sync, likeness) must require the buyer to confirm consent or rights, and must not target sexual content involving real people or minors.
AI review, human
S9
Software must not infringe others' intellectual property, and must be permitted by the terms of every upstream API, model or dataset it uses.
attestation, human
I. instructions and descriptions
These rules apply to anything that gives an AI model tools or behaviour through natural language: skills, knowledge, agent prompts, MCP tool descriptions, and app descriptions shown to agents (agent_description).
ID
Rule
Checked by
I1
Each tool, function or capability is described narrowly and unambiguously: what it does and when to use it.
AI review, TOOL_DESC_VAGUE
I2
Descriptions match actual behaviour, with no undisclosed functionality and no promised features that don't exist.
dynamic, AI review
I3
Names and descriptions must not be confusable with other listings.
NAME_CONFUSABLE
I4
Software must not steer the model into calling other tools, listings or resources the user didn't ask for, and descriptions must not be written to attract extra calls.
TOOL_DESC_STEERS, AI review
I5
Software must not interfere with the model's use of other tools.
AI review
I6
Software must not instruct the model to fetch and follow behavioural instructions from external sources at run time.
scan, AI review
I7
No hidden, obfuscated, encoded or invisible instructions. All behavioural guidance must be human-readable.
scan (INF-SEC-007, 009, 019)
I8
Skills pre-approve only the tools they need, with paths scoped where the harness supports it.
ALLOWED_TOOLS_UNSCOPED_WRITE
P. publisher requirements
ID
Rule
Checked by
P1
Software that collects personal data or sends data to a service other than inference shell links a clear privacy policy covering collection, use and retention.
PRIVACY_POLICY_MISSING
P2
Publishers keep a verified contact email and a public support channel.
publisher profile
P3
Software is documented: what it does, its intended use, and how to troubleshoot it.
DOCS_MISSING
P4
Software that needs sign-in, secrets or seeded data gives reviewers working test access with sample data, through the submission's test-access fields.
REQUIRES_AUTH + test access present
P5
Submissions include working use cases that show core functionality: three for apps, agents, flows and MCP servers, and one for skills and knowledge. Use cases must pass when the reviewer runs them.
dynamic
P6
Publishers own or are authorized to use every endpoint, domain, API and external resource the Software connects to or renders. Proxying a partner's API with permission is allowed. Unauthorized scraping or reselling is not.
attestation, dynamic (egress), human
P7
Publishers maintain the Software, keep its dependencies available, and fix reported issues within the timeframes in the Publisher Terms.
Moving money, cryptocurrency or other financial assets, or executing financial transactions on a buyer's behalf.
U2
Advertising, sponsored content, paid placement, or Software whose main purpose is promotion.
U3
Bulk unsolicited messaging, fake engagement, review or ranking manipulation.
U4
Surveillance, stalking, people-search on private individuals, or covert tracking.
U5
Crypto mining, or cracking credentials or systems the buyer isn't authorized to test.
U6
Gambling or real-money games of chance.
U7
Anything the Terms of Service acceptable use rules prohibit (including weapons, CSAM, non-consensual intimate imagery, and deceptive deepfakes).
T. type-specific requirements
ID
Type
Rule
Checked by
T1
app
Outputs match the declared output schema. Failures return a clear error, not a generic one.
dynamic
T2
app
Pricing expressions are valid and match what the app actually consumes. A failed run carries no marketplace fee.
PRICING_INVALID, dynamic
T3
app
Required secrets and integrations are declared in inf.yml. Nothing else is read.
validation, dynamic
T4
agent, flow
Every referenced app, agent, skill, MCP server or knowledge entry is public, and listed where possible. The model and harness are declared.
DEP_NOT_PUBLIC, DEP_NOT_LISTED
T5
agent, flow
Cost per run is bounded by a step or spend limit.
validation
T6
skill, knowledge
Bundled scripts ship inside the listing. Nothing is downloaded and run at install or at run time.
RUNTIME_FETCH_EXEC
T7
mcp
Errors are handled with helpful messages.
dynamic
T8
mcp
Responses are token-frugal and proportionate to the task.
dynamic (response size)
T9
mcp
Tool names are at most 64 characters.
validation
T10
mcp
Servers that require sign-in use OAuth 2.0 over TLS with a certificate from a recognized authority.
connect probe
T11
mcp
Every tool has title, readOnlyHint and destructiveHint annotations, and the annotations are accurate.
TOOL_ANNOTATIONS_MISSING, WRITES_MISMATCH
T12
mcp
Servers support Streamable HTTP.
connect probe
M. marketplace integrity
ID
Rule
Checked by
M1
No artificial usage: calls from your own organizations, or scripted calls, earn nothing, and attempts to inflate usage lead to removal.
billing (self-org exclusion), anomaly review
M2
No bait-and-switch. A new version must keep the reviewed purpose. Material changes (purpose, new external hosts, new secrets, new write capability, broader tool grants) go back to human review.
version diff (MATERIAL_CHANGE)
M3
No name squatting, keyword stuffing, or impersonating other publishers or brands.
NAME_CONFUSABLE, human
M4
Listing text and media are accurate and not misleading.
AI review, human
enforcement
Outcome
When
Effect
Advisory
info or warning finding
Shown to the publisher and reviewer. Nothing is blocked
Hold
hold finding, or a first version
Goes to human review. The live version stays up
Block
block finding (for example a critical scan hit)
The version cannot be submitted or published. Fix it at the source
Changes requested
A reviewer cites a rule ID
The publisher resubmits the same version, or a new one
Rejection
A reviewer cites a rule ID
The version won't be listed. The publisher can appeal in the review thread
Suspension
Serious or repeated violation, security incident, or buyer harm
The listing is removed from discovery. Earnings may be withheld under the Publisher Terms
Publisher ban
Malicious Software, fraud, or repeated suspensions
All of the publisher's listings are removed
Existing listings are rescanned whenever the rule set changes. A new finding on a live version starts the same flow; for a block finding on a live version, the listing is suspended until it's fixed.
we use cookies
we use cookies to ensure you get the best experience on our website. for more information on how we use cookies, please see our cookie policy.
by clicking "accept", you agree to our use of cookies. learn more.