Review times
← All stores
Rejection library

Why submissions get rejected

What reviewers at ChatGPT, Claude, Muse, Grok, Cursor and the other stores have said when they turned a submission down, what causes each reason, and how to fix it before you submit.

27 reasons
12 rejections reported, 2 with a reason

Free, nothing stored. From a terminal: npx mcplane preflight --url https://your-server/mcp (mcplane docs).

At a glance

ReasonApplies toReportsCaught by
Couldn’t connect to the serverChatGPT Plugins, Claude Connectors, Muse Connectors, Cursor Marketplace, Vercel Connect1Server check + CLI
Reviewer couldn’t sign inChatGPT Plugins, Claude Connectors, Muse Connectors, Cursor Marketplace, Vercel Connect1Server check + CLI
Tool scan failedChatGPT Plugins, Claude Connectors–Server check
Tool hints missing or wrongChatGPT Plugins, Claude Connectors–Server check
Test cases failedChatGPT Plugins, Grok Plugins, Microsoft 365 Agent Store–mcplane CLI
Name too genericChatGPT Plugins, Grok Plugins–By hand
Developer name mismatchChatGPT Plugins–By hand
Descriptions instruct the modelClaude Connectors, Claude Plugins, ChatGPT Plugins, Microsoft 365 Agent Store, Grok Plugins, ClawHub–Server check
Description doesn’t matchChatGPT Plugins, Claude Connectors, Grok Plugins–mcplane CLI
Privacy policyChatGPT Plugins, Claude Connectors, Claude Plugins, Muse Connectors, Cursor Marketplace, Microsoft 365 Agent Store–Server check
Asks for sensitive dataChatGPT Plugins–Server check
Upsell or pricing copyChatGPT Plugins–Server check
Domain verificationChatGPT Plugins–Server check
Field too long or invalidChatGPT Plugins, Claude Connectors, Claude Plugins, Microsoft 365 Agent Store–Server check + CLI
Tools need titlesClaude Connectors, Claude Plugins–Server check
Catch-all request toolClaude Connectors, ChatGPT Plugins, Grok Plugins–Server check
Writes use a token in the chatClaude Connectors, ChatGPT Plugins–Server check
Support must be a web pageChatGPT Plugins–Server check
Icon or faviconChatGPT Plugins, Claude Connectors–Server check
Fails on mobileChatGPT Plugins–By hand
Secret in the packageClawHub, Claude Plugins, ChatGPT Plugins–By hand
Plugin repository problemClaude Plugins, Cursor Marketplace, Grok Plugins, Gemini CLI Extensions, Docker MCP Catalog–mcplane CLI
Personal account, not an organisationGrok Plugins–mcplane CLI
Duplicate submissionGrok Plugins, Docker MCP Catalog–By hand
Not enough beyond CopilotMicrosoft 365 Agent Store–By hand
Not accepting submissionsDocker MCP Catalog, Cursor Marketplace–By hand
No reason givenChatGPT Plugins, Claude Plugins, Grok Plugins, Docker MCP Catalog, Gemini CLI Extensions, Cursor Marketplace–By hand

Reaching your server

Applies to ChatGPT Plugins · Claude Connectors · Muse Connectors · Cursor Marketplace · Vercel Connect

What reviewers and the rules say

“Unable to connect to your MCP server to conduct further testing.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“We’re unable to connect to your MCP server using the MCP URL and/or test credentials we were given.”
ChatGPT Plugins · OpenAI’s help centre, quoted on the developer forum
“ERR_CONNECTION_RESET before connection established”
ChatGPT Plugins · First-hand: one of our own submissions; OpenAI’s answer to an appeal

The server works for you but not from the reviewer’s network. Review traffic goes through TLS-inspecting proxies and automated clients, which fail on things a browser at home never hits: Encrypted ClientHello advertised in DNS (the proxy resets the handshake, so nothing reaches your logs), a firewall or bot rule that answers scripts with 403, a 403 instead of a 401 for calls without a token, or a URL pasted with a trailing slash that 404s. ECH alone cost one developer three ChatGPT rejections. OpenAI uses the same wording when the test credentials don’t work, so check sign-in too.

How to fix it

  • Turn off Encrypted ClientHello for the MCP host. On Cloudflare it’s a zone setting, and only reachable through the API on the free plan.
  • Let automated clients through on the MCP path: no bot challenge, no user-agent or country rules.
  • Answer calls without a token with 401 and a WWW-Authenticate header, never 403.
  • Serve /mcp/ as well as /mcp.
  • Test from outside your own network, with a TLS 1.2 client as well as a browser.
  • Appeal by replying to the rejection email with your case ID, and ask what error the reviewer saw.

How common it is: in our scan of Claude’s connector directory on 29 September, 16% of servers advertise Encrypted ClientHello in DNS (505 of 3,185), and 39% of servers stop working when the URL has a trailing slash (221 of 562).

Caught by

Applies to ChatGPT Plugins · Claude Connectors

What reviewers and the rules say

“Tool scan failed: Internal service error”
ChatGPT Plugins · An error posted on the OpenAI developer forum
“Tool scan failed: method not implemented: server/discover”
ChatGPT Plugins · First-hand: one of our own submissions; ChatGPT’s submission portal
“If any tools are flagged for missing titles or annotations, fix them on your server before submitting.”
Claude Connectors · Anthropic’s submission guide

Before a person looks at it, the store scans your tools. ChatGPT’s scan calls methods beyond tools/list, such as server/discover, which isn’t in the MCP spec, and a server that answers an unknown method with HTTP 500 or error -32603 looks crashed. One developer’s scan only passed once tools/list was under about 32,000 tokens. A server behind OAuth that answers initialize without a token but refuses tools/list leaves the connector with no actions. Claude’s portal flags tools without titles or annotations at this step.

How to fix it

  • Answer methods you don’t implement with JSON-RPC error -32601 (method not found) at HTTP 200.
  • Keep tools/list compact: trim long descriptions and schemas.
  • Behind OAuth, pick one: 401 for everything until sign-in, or list tools without a token and require one to call them.
  • Give every tool a title and explicit hints before you submit to Claude.

How common it is: in our scan of Claude’s connector directory on 29 September, 16% of servers crash or return a non-standard error for a method they don’t implement (92 of 562).

Caught by

Signing in

Applies to ChatGPT Plugins · Claude Connectors · Muse Connectors · Cursor Marketplace · Vercel Connect

What reviewers and the rules say

“We’re unable to complete your sign-in or OAuth flow. Please ensure valid, working credentials are included and that they require no additional setup or verification to access your service.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“We were unable to proceed through the OAuth flow. The authorization URL loaded a blank page with no login or consent interface available to enter the submitted test credentials.”
ChatGPT Plugins · First-hand: one of our own submissions; a ChatGPT rejection email
“Plugins that require additional login steps, such as a new account sign-up or 2FA through an inaccessible account, will be rejected.”
ChatGPT Plugins · OpenAI’s plugin guidelines
“Test credentials: required, and they must be for a fully populated account”
Claude Connectors · Anthropic’s connector checklist

Reviewers sign in as strangers, on a network you don’t control, with the account you gave them. It breaks when the account needs an emailed code, a magic link, MFA or a Google login, when the sign-in page waits on JavaScript from another domain that is slow or blocked (they see a blank page), when that domain sits behind a bot challenge, or when OAuth discovery or client registration fails.

How to fix it

  • Give reviewers a dedicated account with a login and password that works immediately: no MFA, no email or SMS codes, no magic links, not your Google or SSO login, and seeded with data for every test case.
  • Sign in once as a brand-new user, in a fresh browser, from outside your network. Make the page show something before any JavaScript loads.
  • Keep bot challenges off your sign-in and auth domains, not just the MCP path.
  • Serve protected-resource metadata on the MCP host, authorisation-server metadata and PKCE (S256), and Dynamic Client Registration that accepts the store’s redirect URIs.
  • Accept private-use redirect schemes such as cursor:// in client registration, or desktop clients can’t sign in at all.

Caught by

  • auth.prm Protected-resource metadata resolves on the MCP hostServer check
  • auth.as-metadata Authorization-server metadata resolvesServer check
  • auth.pkce PKCE (S256) is supportedServer check
  • auth.dcr Dynamic Client Registration is offeredServer check
  • auth.dcr-native Registration accepts native redirect URIs (with --register)mcplane CLI
  • A reviewer account a stranger can use, and a sign-in page that renders without third-party scriptsBy hand

Tool definitions

Applies to ChatGPT Plugins · Claude Connectors

What reviewers and the rules say

“One or more of your tool’s annotations do not appear to match the tool’s behavior. Please confirm annotations are explicitly set to true or false (not null) for every tool.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“Use true for public or open-ended entities, including read-only web search and arbitrary destinations. A tool confined to a bounded private account, workspace, or catalog may use false, even when externally hosted.”
ChatGPT Plugins · OpenAI’s plugin guidelines, on openWorldHint
“Every tool must include a title and the applicable hint: readOnlyHint: true for read-only tools, and destructiveHint: true for tools that modify or delete data.”
Claude Connectors · Anthropic’s connector checklist

ChatGPT and Claude use readOnlyHint, destructiveHint and openWorldHint to decide when to ask the user before a tool runs, and both reviews check the hints against what each tool does. OpenAI wants all three set to true or false on every tool, and its definitions are stricter than many developers expect: a tool that posts, sends or uploads is not read-only; destructiveHint covers irreversible sends and transactions, and being able to undo something doesn’t make it non-destructive; openWorldHint depends on where the tool reaches, not on whether it calls an external API.

How to fix it

  • Set readOnlyHint, destructiveHint and openWorldHint to true or false on every tool, never null.
  • Mark tools that post, send or upload as readOnlyHint: false, and destructiveHint: true when the effect can’t be taken back.
  • Use openWorldHint: true for public or open-ended destinations, and false for a tool limited to the user’s own account, workspace or catalogue.
  • OpenAI no longer asks for a justification per hint. If its automated review flags a hint you believe is right, appeal with an explanation.

How common it is: in our scan of Claude’s connector directory on 29 September, 18% of servers leave at least one tool without explicit safety hints (102 of 564).

Caught by

Applies to Claude Connectors · Claude Plugins · ChatGPT Plugins · Microsoft 365 Agent Store · Grok Plugins · ClawHub

What reviewers and the rules say

“Describe what the tool does, and don’t tell Claude how to behave.”
Claude Connectors · Anthropic’s connector checklist
manipulative ranking language in tool descriptions
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)
“Instructional phrases, for example, 'if the user says X', 'ignore', 'delete', 'reset', 'new instructions', 'Answer in Bold', or 'Do not print anything'.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)
“authority too broad / could change agent behavior without clear guardrails”
ClawHub · ClawHub’s security scan, quoted in an issue

Lines such as “always call this tool first” or “never tell the user” read as an attempt to steer the model, the same shape as prompt injection. Anthropic rejects descriptions that tell Claude to call tools the user didn’t ask for or interfere with other tools. OpenAI’s rules say tool metadata must not override platform instructions or safeguards. Microsoft rejects instructional phrases in any description, xAI looks for prompt injection in SKILL.md and descriptions, and ClawHub’s scanner flags text that could change an agent’s behaviour. Naming a sibling tool to call first is common in approved listings and isn’t the problem.

How to fix it

  • Describe what the tool does and returns, as facts.
  • Move usage guidance into the server’s instructions or your docs.
  • If a line has to stay, explain it in the submission’s notes for reviewers.

How common it is: in our scan of Claude’s connector directory on 29 September, 21% of servers tell the model what to do inside a tool description (118 of 564).

Caught by

Applies to ChatGPT Plugins · Claude Connectors · Grok Plugins

What reviewers and the rules say

“The description must match the tool’s actual behavior.”
Claude Connectors · Anthropic’s connector checklist
Second rejection: feedback on how our tools are described.
ChatGPT Plugins · A developer on the OpenAI developer forum (paraphrased)
A skill file still described the old API-key sign-in after the plugin had moved to browser OAuth.
Grok Plugins · An xAI reviewer on a pull request (paraphrased)

Reviewers compare what your listing, tool descriptions and skill files promise with what the tools do. They drift: a renamed tool, a removed feature or an old sign-in method still described in a skill file reads as misleading.

How to fix it

  • Describe each tool precisely: what it does, what it returns and when to use it.
  • Re-read the listing, tool descriptions and skill files after every change to the server.
  • Before resubmitting, compare what the store is reviewing with what the server does now.

Caught by

  • listing.test-tools Test cases use tools the server hasmcplane CLI
  • mcplane drift: what each store is reviewing against what the server does nowmcplane CLI

Applies to Claude Connectors · Claude Plugins

What reviewers and the rules say

“MCP servers must provide all applicable annotations for their tools, in particular readOnlyHint, destructiveHint, and title.”
Claude Connectors · Anthropic’s directory policy

Claude shows a tool’s title in permission prompts and in the directory, and its submission portal flags tools without one. Without a title, people see the raw name, such as search_docs_v2.

How to fix it

  • Add title to each tool, or annotations.title.
  • Keep titles short and plain: “Search documents”, not the function name.

How common it is: in our scan of Claude’s connector directory on 29 September, 9% of servers have tools without a human-readable title (52 of 564).

Caught by

  • tools.title Every tool has a human-readable titleServer check

Applies to Claude Connectors · ChatGPT Plugins · Grok Plugins

What reviewers and the rules say

“Don’t ship a catch-all api_request tool with a method parameter.”
Claude Connectors · Anthropic’s connector checklist
“Do not use discovery, operation selection, or schema fetching with a generic executor to enable operations not individually exposed for review.”
ChatGPT Plugins · OpenAI’s plugin guidelines
“a shell-exec MCP server when a scoped tool would do.”
Grok Plugins · xAI’s contributing guide, on over-broad scope

A tool such as api_request with a method and a path does reads and writes through one door, so its hints can’t be honest and nobody can review what it will do. Anthropic rejects a tool that accepts both safe and unsafe HTTP methods, OpenAI wants every operation the model can call exposed as its own tool, and xAI questions broad shell access where a narrow tool would do.

How to fix it

  • Split it into read tools and write tools, each with honest hints.
  • Expose each operation as its own tool, with its own description and input schema.
  • If a tool has to accept free-form paths or queries, name or link the API it calls in the description.

Caught by

Applies to Claude Connectors · ChatGPT Plugins

What reviewers and the rules say

“anyone who obtains or guesses a token can rewrite”
Claude Connectors · First-hand: one of our own submissions; Anthropic’s review of the Review Times connector
“Remote MCP servers that connect to a remote service and require authentication must use secure OAuth 2.0 with certificates from recognized authorities.”
Claude Connectors · Anthropic’s directory policy

A write tool that takes a secret as a parameter puts the secret in the conversation, where it can leak into logs, other tools or a shared chat. Anthropic treats that as a write nobody owns and requires OAuth for authenticated services. OpenAI counts access credentials and passwords as restricted data a plugin may not solicit.

How to fix it

  • Put writes behind OAuth, so each one is tied to a signed-in account.
  • Or move the write to your site and email the owner a private link. That is what Review Times did.
  • Never return edit tokens in tool results.

Caught by

Policy

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Muse Connectors · Cursor Marketplace · Microsoft 365 Agent Store

What reviewers and the rules say

“Missing or incomplete privacy policies result in immediate rejection.”
Claude Connectors · Anthropic’s submission guide
privacy policy gaps and undisclosed returned data
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)

Every store asks for a privacy policy, and reviewers read it. Anthropic wants it to cover data collection, usage and storage, third-party sharing, retention and contact information. OpenAI asks for the categories of personal data you collect, why you use them, who receives them, how long you keep them and what users can do about it. Data your tools return that the policy doesn’t mention counts as a gap.

How to fix it

  • Link a page that loads without signing in.
  • Cover collection, use, sharing, retention, user controls such as deletion, and how to contact you.
  • Mention the data your tools return and any free-form content users send, not only what they type into forms.

How common it is: in our scan of Claude’s connector directory on 29 September, 4% of servers link a privacy policy that doesn’t load (145 of 3,283).

Caught by

Applies to ChatGPT Plugins

What reviewers and the rules say

“Do not collect, solicit, or process the following categories of Restricted Data”
ChatGPT Plugins · OpenAI’s plugin guidelines
The app solicits sensitive personal data (health, biometric, SSN, payment card).
ChatGPT Plugins · First-hand: one of our own submissions; a ChatGPT rejection email, summarised (paraphrased)

OpenAI’s restricted data covers payment card data, protected health information, government identifiers such as social security numbers, and access credentials such as API keys, one-time codes and passwords. It reads tool inputs and descriptions, so a parameter called password, or a description about detecting personal data, can trigger a rejection even when you store nothing.

How to fix it

  • Ask only for what the task needs. OpenAI also rules out “just in case” fields and broad profile data.
  • Remove inputs that ask for card data, health data, IDs or credentials.
  • Call things what they are: a viewer passcode the user makes up is not a password.
  • Say in your privacy policy what happens to free-form content users send, and any automatic screening.

Caught by

Applies to ChatGPT Plugins

What reviewers and the rules say

“Plugins must not display subscription plans, initiate new subscriptions, or promote upgrades.”
ChatGPT Plugins · OpenAI’s plugin guidelines
“Do not advertise pricing, subscriptions, free trials, discounts, or promotions.”
ChatGPT Plugins · OpenAI’s plugin guidelines, on listings
disallowed commerce
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)

OpenAI doesn’t let plugins sell digital products or services inside ChatGPT, freemium upsells included, and listings can’t advertise pricing, trials or promotions. Users can sign in to a paid account they already have and use what it includes. Reviewers read tool titles, descriptions and error messages, so a “limit reached, upgrade to Pro” error counts.

How to fix it

  • Keep plans and pricing on your website.
  • Make limit errors neutral: say the limit was reached and where the account can be managed.
  • Prices your tools return for physical goods are fine. Selling your own subscription, credits or tokens isn’t.

Caught by

Applies to Microsoft 365 Agent Store

What reviewers and the rules say

“Agents should be designed to complete enterprise workflows and must deliver differentiated value beyond what Copilot offers”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)

Microsoft rejects agents that do what Copilot already does. Its examples of differentiated value are workflows Copilot can’t do easily, such as creating tickets directly in a ticketing platform, and workflows the agent makes much faster.

How to fix it

  • Lead the description with the workflow your agent completes that Copilot can’t.
  • Make the sample prompts show that workflow.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Listing details

Applies to ChatGPT Plugins · Grok Plugins

What reviewers and the rules say

“Avoid overly generic names, especially single-word dictionary terms that aren’t explicitly tied to your brand.”
ChatGPT Plugins · OpenAI’s plugin guidelines
The auto rejection for app name being too generic is kind of crazy.
ChatGPT Plugins · A developer on the OpenAI developer forum (paraphrased)
“The keywords and domains fields power the plugin CTA feature in Grok Build. For this reason, we are pushing back on generic keywords.”
Grok Plugins · An xAI reviewer on a pull request

ChatGPT rejects names it judges too generic, sometimes automatically as soon as you submit, especially single dictionary words that aren’t tied to your brand. Its guidelines also rule out adding “MCP”, “MCP Server” or “Plugin” to a product name. Grok uses your keywords and domains to suggest your plugin in conversation, so its reviewers push back on generic ones.

How to fix it

  • Use your brand or product name, not a category word.
  • Don’t add “MCP”, “MCP Server” or “Plugin” to the name for ChatGPT.
  • For Grok, keep keywords and domains scoped to your brand.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Applies to ChatGPT Plugins

What reviewers and the rules say

“The developer name you entered does not match your verified individual or business name. Please update the developer name so it matches the verified name on your account.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum

ChatGPT shows a publisher name on every listing, and it has to match the individual or business name verified on your OpenAI account exactly. A trading name, a product name or a different spelling fails.

How to fix it

  • Enter the developer name exactly as it appears on your verified account.
  • To publish under a business name, the business has to be the verified identity on the account.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Applies to ChatGPT Plugins

What reviewers and the rules say

“Domain verification failed: Challenge endpoint did not return 200 OK.”
ChatGPT Plugins · An error posted on the OpenAI developer forum
“Domain verification URL hostname must be the MCP hostname or a parent hostname”
ChatGPT Plugins · An error posted on the OpenAI developer forum
“we don’t support non-root .well-known locations when performing domain verification.”
ChatGPT Plugins · OpenAI staff on the developer forum

Before the MCP step, ChatGPT checks you control the server’s domain by fetching a token from /.well-known/openai-apps-challenge at the root of the MCP hostname or a parent hostname. A server mounted under a path, a firewall that blocks OpenAI’s verifier, a redirect or an HTML page all fail it.

How to fix it

  • Serve the token as plain text with a 200, at the root of the MCP hostname or a parent hostname, not under a path.
  • Let the OpenAI-Domain-Verification user agent through your firewall.

Caught by

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Microsoft 365 Agent Store

What reviewers and the rules say

“Up to three starter prompts, at most 128 characters each. Make them unique and omit app @mentions.”
ChatGPT Plugins · OpenAI’s submission docs
“server name up to 100 characters, one-liner up to 200 characters, description up to 2,000 characters”
Claude Connectors · Anthropic’s submission guide
“Tool names must be 64 characters or fewer.”
Claude Connectors · Anthropic’s connector checklist
“Each prompt mustn’t exceed 128 characters.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)

Each store enforces its own limits, some without telling you until review. ChatGPT’s display name and subtitle stop at 30 characters each, and it takes up to three starter prompts. Claude caps names at 100 characters, one-liners at 200, descriptions at 2,000 and tool names at 64. Microsoft wants three to five prompts per command, none over 128 characters.

How to fix it

  • Keep a shorter name for ChatGPT if yours runs past 30 characters.
  • Write up to three distinct starter prompts for ChatGPT, without @mentions.
  • Rename any tool over 64 characters.

How common it is: in our scan of Claude’s connector directory on 29 September, 3% of servers have a name longer than ChatGPT’s 30 characters (92 of 3,283).

Caught by

Applies to ChatGPT Plugins

What reviewers and the rules say

“all four listing URLs are required: websiteURL, supportURL, privacyPolicyURL, and termsOfServiceURL. Use HTTPS URLs without embedded credentials.”
ChatGPT Plugins · OpenAI’s submission docs

Claude accepts an email address for support. ChatGPT’s plugin package wants a support URL, plus website, privacy policy and terms URLs, all over https.

How to fix it

  • Put up a /support page with your email address on it.
  • Set website, support, privacy and terms to https URLs.

How common it is: in our scan of Claude’s connector directory on 29 September, 69% of servers give an email address, not a web page, for support (2,261 of 3,283).

Caught by

Applies to ChatGPT Plugins · Claude Connectors

What reviewers and the rules say

“the fallback favicon is not resolving”
Claude Connectors · First-hand: one of our own submissions; Anthropic’s review of the Review Times connector
“Icons and logos must be square and at least 48 by 48 pixels.”
ChatGPT Plugins · OpenAI’s submission docs

With no icon set, Claude’s directory falls back to /favicon.ico on your server’s domain, and reviewers flag it when that 404s. ChatGPT wants square icons of at least 48 by 48 pixels, and its developer-mode upload stops at 10 KB.

How to fix it

  • Serve /favicon.ico on the MCP server’s domain.
  • Keep a square 512×512 PNG behind a direct link ending in .png. It covers every store.
  • Export an 8-bit PNG under 10 KB for ChatGPT’s developer-mode dialog.

Caught by

Testing

Applies to ChatGPT Plugins · Grok Plugins · Microsoft 365 Agent Store

What reviewers and the rules say

“One or more of your test cases did not produce correct results. Please re-run all submitted test cases and align tool behavior/output with the documented expected outcomes.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“could you share a short Grok Build demo covering sign-in, OAuth consent, and a harmless request”
Grok Plugins · An xAI reviewer on a pull request
“All sample prompts must be functional and return responses.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines

Reviewers run what you give them, as the account you gave them, against your live server: ChatGPT’s five positive and three negative test cases, Microsoft’s sample prompts, or a demo for Grok. A test that names a tool you have since renamed, or expects data that has since changed, reads as a broken app. OpenAI also expects the same test cases to pass on ChatGPT web and mobile.

How to fix it

  • In each test case, name only tools the live server has.
  • Seed the demo account with the data every test case expects, and check it again right before you submit.
  • Record ChatGPT’s video walkthrough in developer mode, and again whenever tools change.
  • Give write tools a safe target, so reviewers don’t post to a real account.
  • For Grok, be ready to share a short demo of sign-in, OAuth consent and a harmless request.

Caught by

  • listing.test-tools Test cases use tools the server hasmcplane CLI
  • Demo data matches every test case, checked right before submittingBy hand

Applies to ChatGPT Plugins

What reviewers and the rules say

“Plugins must function reliably in ChatGPT on both desktop and mobile, including any UI components.”
ChatGPT Plugins · OpenAI’s plugin guidelines
we received a rejection notice stating that the issue was related to a mobile widget failure
ChatGPT Plugins · A developer on the OpenAI developer forum (paraphrased)

Reviewers test in ChatGPT’s mobile apps as well as on the web, and the same test cases have to pass on both. The mobile failures reported so far were in widgets.

How to fix it

  • Run every test case in the ChatGPT iOS and Android apps, not only on the web.
  • Check widgets at phone width, signed in as the demo account.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Plugin package

Applies to ClawHub · Claude Plugins · ChatGPT Plugins

What reviewers and the rules say

“File appears to expose a hardcoded API secret or token.”
ClawHub · ClawHub’s security scan, quoted in an issue
“Keep private credentials and secrets out of the ZIP.”
ChatGPT Plugins · OpenAI’s submission docs

Stores scan what you upload. A key in an MCP server’s headers or a token in a config file blocks the submission: Claude’s plugin validation reports “Secret in MCP headers”. ClawHub’s scanner also flags lines that only look like a secret, such as a command that reads a password from the user.

How to fix it

  • Ask for keys at install time. Claude plugins use a userConfig entry marked sensitive: true.
  • Keep credentials out of the ZIP, the repository and skill files.
  • Rewrite examples that look like real keys.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Applies to Claude Plugins · Cursor Marketplace · Grok Plugins · Gemini CLI Extensions · Docker MCP Catalog

What reviewers and the rules say

“Put a README of at least 40 words in the plugin folder”
Claude Plugins · Anthropic’s plugin checklist (blocks if missing)
“main, v1.2.3, and abbreviated SHAs are rejected by the validator.”
Grok Plugins · xAI’s contributing guide
“looks like there’s a failure in the CI job that ran, you’ll need to fix that first”
Docker MCP Catalog · A Docker maintainer on a pull request
“(MIT or Apache 2 are great, GPL is not).”
Docker MCP Catalog · Docker’s contributing guide

Stores that take plugins read them from a public GitHub repository at a pinned commit, and validate it before anyone reviews it. A private repository, a missing manifest, README or licence, a branch instead of a commit, or a failing CI run leaves nothing to review. Gemini CLI’s gallery skips a repository that fails validation without saying so.

How to fix it

  • Host the plugin in its own public GitHub repository. A private monorepo can’t be pinned.
  • Claude: add .claude-plugin/plugin.json, a README of at least 40 words and a LICENSE, then run claude plugin validate --strict.
  • Don’t leave a SKILL.md at the root beside a skills/ folder. Claude loads it as a single-skill plugin and hides the rest.
  • Grok: pin a full 40-character commit SHA, not main or a tag.
  • Docker: use a licence that lets people run the server, such as MIT or Apache 2.0, and get CI green before asking for review.
  • Gemini CLI: put gemini-extension.json at the root and add the gemini-cli-extension topic.

Caught by

Applies to Grok Plugins

What reviewers and the rules say

“A branded plugin (acme) sourced from some-personal-account/acme-thing reads as a possible impersonation and will be questioned.”
Grok Plugins · xAI’s contributing guide
A developer closed their pull request to resubmit it from the company’s organisation.
Grok Plugins · A Grok marketplace pull request (paraphrased)

xAI wants a branded plugin to come from the organisation that owns the brand. A repository under a personal GitHub account reads as possible impersonation.

How to fix it

  • Transfer the repository to a GitHub organisation named after the product before you open the pull request.

Caught by

Applies to Grok Plugins · Docker MCP Catalog

What reviewers and the rules say

“Not already in the catalog; not a parallel entry for an existing plugin”
Grok Plugins · xAI’s contributing guide, review checklist

Stores that take pull requests close one that adds something already in the catalog, or a second one for the same plugin. Updates go through the existing entry.

How to fix it

  • Search the catalog and the open pull requests before you add an entry.
  • To update a listed Grok plugin, bump its pinned commit instead of adding a new entry.
  • Close your own older pull request when you open a replacement.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

The store itself

Applies to Docker MCP Catalog · Cursor Marketplace

What reviewers and the rules say

“We’re actually no longer accepting new mcp server entries”
Docker MCP Catalog · A Docker maintainer on a pull request, 8 August 2026
“We keep the marketplace curated. We work directly with plugin authors we trust, and every submission goes through our internal review process.”
Cursor Marketplace · Cursor’s marketplace security page

Some stores stop taking new entries without closing the door. A Docker maintainer said so on 8 August, quoted above; since then 639 more pull requests adding a server have been opened, and none has been merged (counted on 1 October). Cursor curates its marketplace and works directly with plugin authors it trusts.

How to fix it

  • Read the latest maintainer comments in the queue before you open a pull request.
  • Ask on your pull request whether it will be reviewed at all.
  • List the server where intake is open, such as the official MCP Registry, which takes entries through its own CLI.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Applies to ChatGPT Plugins · Claude Plugins · Grok Plugins · Docker MCP Catalog · Gemini CLI Extensions · Cursor Marketplace

What reviewers and the rules say

The rejection email said “Please see the details below:”, followed by nothing.
ChatGPT Plugins · A developer on the OpenAI developer forum (paraphrased)
The submission portal only shows “Rejected” with no notes.
Claude Plugins · A developer in Anthropic’s plugin issue tracker (paraphrased)

Some reviews end without an explanation. ChatGPT rejection emails have arrived with an empty details section, Claude’s old plugin portal showed “Rejected” with no notes, Grok and Docker maintainers often close pull requests without a comment, Gemini CLI’s crawler skips repositories silently, and Cursor’s publish form sends no confirmation.

How to fix it

  • ChatGPT: reply to the rejection email with your case ID and ask for the specific finding.
  • On a pull request, ask what would make it acceptable.
  • Rule out the mechanical causes with a server check before you resubmit.

Of the 6 pull requests maintainers closed in the Grok and Docker queues we track, none had a comment saying why (checked 1 October).

Caught by

No script can see this one. A server check rules out the mechanical causes first.

How this is counted

Reports count rejected submissions where the developer picked the reason, or wrote a note that names it. So far 12 rejections have been reported, and 2 say why. Pull requests closed in the Grok and Docker queues count as rejections, but carry no reason.

The reasons themselves come from rejection emails developers have shared, public posts, the stores’ own docs and our own submissions. Each check is open source in mcplane, and the server check runs the ones marked “Server check”. Tool checks need tools that list without sign-in; for a server behind sign-in, run mcplane with --token.

Rejected?

Add it with the reason. The next developer sees it here, and the store’s review times include it.

Add your rejection

Already reported it as waiting? Open your private link and mark it rejected; the reason is on the same form.