/app-store-review-skill
Evaluates code against Apple's App Store Review Guidelines. Use this skill when reviewing iOS, macOS, tvOS, watchOS, or visionOS app code (Swift, Objective-C, React Native, or Expo) to identify potential App Store rejection issues before submission. Triggers on tasks involving
$ npx -y skills add safaiyeh/app-store-review-skill --skill app-store-review-skill --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/app-store-review-skill
Context preview
The summary Claude sees to decide when to auto-load this skill.
Evaluates code against Apple's App Store Review Guidelines. Use this skill when reviewing iOS, macOS, tvOS, watchOS, or visionOS app code (Swift, Objective-C, React Native, or Expo) to identify potential App Store rejection issues before submission. Triggers on tasks involving
SKILL.md
app-store-review-skill.SKILL.mdname: app-store-review
description: Evaluates code against Apple's App Store Review Guidelines. Use this skill when reviewing iOS, macOS, tvOS, watchOS, or visionOS app code (Swift, Objective-C, React Native, or Expo) to identify potential App Store rejection issues before submission. Triggers on tasks involving app review preparation, compliance checking, or App Store submission readiness.
license: MIT
metadata:
author: safaiyeh
version: "1.3.2"
App Store Review Guidelines Checker
Comprehensive guide for evaluating iOS, macOS, tvOS, watchOS, and visionOS app code against Apple's App Store Review Guidelines. This skill covers EVERY guideline point to identify potential rejection issues before submission.
**Supports:** Swift, Objective-C, React Native, and Expo apps
**Guidelines current through:** Apple's June 8, 2026 App Review Guidelines update (verified still current as of August 29, 2026). Also incorporates post-June policy announcements: social media age-rating questions (mandatory September 2026), Republic of Korea age rating changes (August/October 2026), and Brazil/EU alternative payment and distribution terms.
When to Apply
Use this skill when:
- Preparing an app for App Store submission
- Reviewing code for compliance issues
- Implementing features that may trigger review concerns
- Auditing existing apps for guideline violations
- Building features involving payments, user data, or sensitive content
Guideline Sections
Read individual rule files for detailed explanations, checklists, and code examples:
| Section | File | Key Topics | |---------|------|------------| | **1. Safety** | [rules/1-safety.md](rules/1-safety.md) | Objectionable content, UGC moderation, Kids Category, physical harm, data security | | **2. Performance** | [rules/2-performance.md](rules/2-performance.md) | App completeness, metadata accuracy, hardware compatibility, software requirements | | **3. Business** | [rules/3-business.md](rules/3-business.md) | In-app purchase, subscriptions, cryptocurrencies, other business models | | **4. Design** | [rules/4-design.md](rules/4-design.md) | Copycats, minimum functionality, spam, extensions, Apple services, login | | **5. Legal** | [rules/5-legal.md](rules/5-legal.md) | Privacy, data collection, intellectual property, gambling, VPN, MDM, developer code of conduct |
Risk Levels by Category
| Risk Level | Category | Section | Common Rejection Reasons | |------------|----------|---------|--------------------------| | CRITICAL | Privacy & Data | 5.1 | Missing privacy policy, unauthorized data collection | | CRITICAL | Payments | 3.1 | Bypassing in-app purchase, unclear pricing | | HIGH | Safety | 1.x | Objectionable content, inadequate UGC moderation | | HIGH | Performance | 2.x | Crashes, incomplete features, deprecated APIs | | MEDIUM | Design | 4.x | Copycat apps, minimum functionality issues | | MEDIUM | Legal | 5.x | IP violations, gambling without license |
---
Quick Reference: High-Risk Rejection Patterns
For ATT findings, verify the SDK's configuration and actual data use. For account deletion, verify the destination and flow. For logging, inspect the data exposed and any redaction. If that evidence is unavailable, report what needs verification instead of declaring a rejection based on an API call, SDK import, or URL alone.
Critical Issues (Immediate Rejection)
**Swift:**
// 🔴 Private API usage
let selector = NSSelectorFromString("_privateMethod")
// 🔴 Hardcoded secrets
let apiKey = "sk_live_xxxxx"
// 🔴 External payment for digital goods
func purchaseDigitalContent() {
openStripeCheckout() // Use StoreKit instead
}**React Native / Expo:**
// 🔴 Hardcoded secrets in JS bundle
const API_KEY = 'sk_live_xxxxx'; // REJECTION
// 🔴 External payment for digital goods
Linking.openURL('https://stripe.com/checkout'); // Use react-native-iap
// 🔴 Dynamic code execution
eval(downloadedCode); // REJECTION
// 🔴 Major feature changes via CodePush/expo-updates
// OTA updates for bug fixes only, not new features!High-Risk Issues
**Swift:**
// 🟡 Starting Apple-defined tracking without ATT authorization
// Illustrative helper: links user data across companies for ad targeting
enableCrossCompanyAdTracking() // Called before ATT authorization
// 🟡 Account creation without deletion
func createAccount() { } // But no way to initiate deletion in the app**React Native / Expo:**
// 🟡 Starting Apple-defined tracking without ATT authorization
// Illustrative helper: SDK links user data across companies for ad targeting
initializeTrackingAdSDK(); // Called before ATT authorization
// ✅ First-party analytics alone does not require ATT
// Assumes no IDFA access, cross-company advertising use, or data broker sharing
import analytics from '@react-native-firebase/analytics';
analytics().logEvent('event');
// 🟡 Delete Account button opens instructions with no deletion flow
Linking.openURL('https://example.com/help'); // Verified instructions-only page
// ✅ An in-app button may link directly to a page that completes deletion
Linking.openURL('https://example.com/delete-account');
// 🟡 Sensitive data exposed in production logs (1.6 / 5.1)
console.log('Access token:', accessToken); // Remove the secret or redact it
// 🟡 Social login without a privacy-preserving alternative (4.8)
<GoogleSigninButton /> // Also offer a login meeting 4.8 criteria
// (Sign in with Apple is the simplest option)
// 🟡 Custom review prompts (5.6.1)
showCustomAlert('Rate us 5 stars!'); // Use StoreReview.requestReview()Medium-Risk Issues
// 🟠 Vague purpose strings in Info.plist
"This app needs camera access" // Be specific!
// 🟠 WebView-only app (insufficient native functionality)
const App = () => <WebView source={{ uri: 'https://site.com' }} />;
// 🟠 References to Android in iOS app
const text = "Also available on Android"; // RERead more
name: app-store-review description: Evaluates code against Apple's App Store Review Guidelines. Use this skill when reviewing iOS, macOS, tvOS, watchOS, or visionOS app code (Swift, Objective-C, React Native, or Expo) to identify potential App Store rejection issues before submission. Triggers on tasks involving app review preparation, compliance checking, or App Store submission readiness. license: MIT metadata: author: safaiyeh version: "1.3.2"
App Store Review Guidelines Checker
Comprehensive guide for evaluating iOS, macOS, tvOS, watchOS, and visionOS app code against Apple's App Store Review Guidelines. This skill covers EVERY guideline point to identify potential rejection issues before submission.
**Supports:** Swift, Objective-C, React Native, and Expo apps
**Guidelines current through:** Apple's June 8, 2026 App Review Guidelines update (verified still current as of August 29, 2026). Also incorporates post-June policy announcements: social media age-rating questions (mandatory September 2026), Republic of Korea age rating changes (August/October 2026), and Brazil/EU alternative payment and distribution terms.
When to Apply
Use this skill when:
- Preparing an app for App Store submission
- Reviewing code for compliance issues
- Implementing features that may trigger review concerns
- Auditing existing apps for guideline violations
- Building features involving payments, user data, or sensitive content
Guideline Sections
Read individual rule files for detailed explanations, checklists, and code examples:
| Section | File | Key Topics | |---------|------|------------| | **1. Safety** | [rules/1-safety.md](rules/1-safety.md) | Objectionable content, UGC moderation, Kids Category, physical harm, data security | | **2. Performance** | [rules/2-performance.md](rules/2-performance.md) | App completeness, metadata accuracy, hardware compatibility, software requirements | | **3. Business** | [rules/3-business.md](rules/3-business.md) | In-app purchase, subscriptions, cryptocurrencies, other business models | | **4. Design** | [rules/4-design.md](rules/4-design.md) | Copycats, minimum functionality, spam, extensions, Apple services, login | | **5. Legal** | [rules/5-legal.md](rules/5-legal.md) | Privacy, data collection, intellectual property, gambling, VPN, MDM, developer code of conduct |
Risk Levels by Category
| Risk Level | Category | Section | Common Rejection Reasons | |------------|----------|---------|--------------------------| | CRITICAL | Privacy & Data | 5.1 | Missing privacy policy, unauthorized data collection | | CRITICAL | Payments | 3.1 | Bypassing in-app purchase, unclear pricing | | HIGH | Safety | 1.x | Objectionable content, inadequate UGC moderation | | HIGH | Performance | 2.x | Crashes, incomplete features, deprecated APIs | | MEDIUM | Design | 4.x | Copycat apps, minimum functionality issues | | MEDIUM | Legal | 5.x | IP violations, gambling without license |
---
Quick Reference: High-Risk Rejection Patterns
For ATT findings, verify the SDK's configuration and actual data use. For account deletion, verify the destination and flow. For logging, inspect the data exposed and any redaction. If that evidence is unavailable, report what needs verification instead of declaring a rejection based on an API call, SDK import, or URL alone.
Critical Issues (Immediate Rejection)
**Swift:**
// 🔴 Private API usage
let selector = NSSelectorFromString("_privateMethod")
// 🔴 Hardcoded secrets
let apiKey = "sk_live_xxxxx"
// 🔴 External payment for digital goods
func purchaseDigitalContent() {
openStripeCheckout() // Use StoreKit instead
}**React Native / Expo:**
// 🔴 Hardcoded secrets in JS bundle
const API_KEY = 'sk_live_xxxxx'; // REJECTION
// 🔴 External payment for digital goods
Linking.openURL('https://stripe.com/checkout'); // Use react-native-iap
// 🔴 Dynamic code execution
eval(downloadedCode); // REJECTION
// 🔴 Major feature changes via CodePush/expo-updates
// OTA updates for bug fixes only, not new features!High-Risk Issues
**Swift:**
// 🟡 Starting Apple-defined tracking without ATT authorization
// Illustrative helper: links user data across companies for ad targeting
enableCrossCompanyAdTracking() // Called before ATT authorization
// 🟡 Account creation without deletion
func createAccount() { } // But no way to initiate deletion in the app**React Native / Expo:**
// 🟡 Starting Apple-defined tracking without ATT authorization
// Illustrative helper: SDK links user data across companies for ad targeting
initializeTrackingAdSDK(); // Called before ATT authorization
// ✅ First-party analytics alone does not require ATT
// Assumes no IDFA access, cross-company advertising use, or data broker sharing
import analytics from '@react-native-firebase/analytics';
analytics().logEvent('event');
// 🟡 Delete Account button opens instructions with no deletion flow
Linking.openURL('https://example.com/help'); // Verified instructions-only page
// ✅ An in-app button may link directly to a page that completes deletion
Linking.openURL('https://example.com/delete-account');
// 🟡 Sensitive data exposed in production logs (1.6 / 5.1)
console.log('Access token:', accessToken); // Remove the secret or redact it
// 🟡 Social login without a privacy-preserving alternative (4.8)
<GoogleSigninButton /> // Also offer a login meeting 4.8 criteria
// (Sign in with Apple is the simplest option)
// 🟡 Custom review prompts (5.6.1)
showCustomAlert('Rate us 5 stars!'); // Use StoreReview.requestReview()Medium-Risk Issues
// 🟠 Vague purpose strings in Info.plist
"This app needs camera access" // Be specific!
// 🟠 WebView-only app (insufficient native functionality)
const App = () => <WebView source={{ uri: 'https://site.com' }} />;
// 🟠 References to Android in iOS app
const text = "Also available on Android"; // REAn AI agent skill that exhaustively evaluates iOS, macOS, tvOS, watchOS, and visionOS app code against every point in Apple's App Store Review Guidelines.
Repo: safaiyeh/app-store-review-skill

