Review times
← Claude Plugins
Rejection library

Why Claude plugins get rejected

What Anthropic has said when it turned Claude plugins down, what causes each reason, and how to fix it before you submit.

7 reasons
0 rejections reported, 0 with a reason

How rejections arriveSince 25 September 2026 the submission portal validates the plugin on submit and shows feedback. Under the old Console form, some rejections showed no notes and some plugins vanished from the dashboard.

Free, nothing stored. From a terminal: npx mcplane preflight --url https://your-server/mcp (mcplane docs).

At a glance

ReasonApplies toReportsCaught by
Descriptions instruct the modelClaude Connectors, Claude Plugins, ChatGPT Plugins, Microsoft 365 Agent Store, Grok Plugins, ClawHub–Server check
Privacy policyChatGPT Plugins, Claude Connectors, Claude Plugins, Muse Connectors, Cursor Marketplace, Microsoft 365 Agent Store–Server check
Field too long or invalidChatGPT Plugins, Claude Connectors, Claude Plugins, Microsoft 365 Agent Store–Server check + CLI
Tools need titlesClaude Connectors, Claude Plugins–Server check
Secret in the packageClawHub, Claude Plugins, ChatGPT Plugins–By hand
Plugin repository problemClaude Plugins, Cursor Marketplace, Grok Plugins, Gemini CLI Extensions, Docker MCP Catalog–mcplane CLI
No reason givenChatGPT Plugins, Claude Plugins, Grok Plugins, Docker MCP Catalog, Gemini CLI Extensions, Cursor Marketplace–By hand

Tool definitions

Applies to Claude Connectors · Claude Plugins · ChatGPT Plugins · Microsoft 365 Agent Store · Grok Plugins · ClawHub

What reviewers and the rules say

“Describe what the tool does, and don’t tell Claude how to behave.”
Claude Connectors · Anthropic’s connector checklist
manipulative ranking language in tool descriptions
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)
“Instructional phrases, for example, 'if the user says X', 'ignore', 'delete', 'reset', 'new instructions', 'Answer in Bold', or 'Do not print anything'.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)
“authority too broad / could change agent behavior without clear guardrails”
ClawHub · ClawHub’s security scan, quoted in an issue

Lines such as “always call this tool first” or “never tell the user” read as an attempt to steer the model, the same shape as prompt injection. Anthropic rejects descriptions that tell Claude to call tools the user didn’t ask for or interfere with other tools. OpenAI’s rules say tool metadata must not override platform instructions or safeguards. Microsoft rejects instructional phrases in any description, xAI looks for prompt injection in SKILL.md and descriptions, and ClawHub’s scanner flags text that could change an agent’s behaviour. Naming a sibling tool to call first is common in approved listings and isn’t the problem.

How to fix it

  • Describe what the tool does and returns, as facts.
  • Move usage guidance into the server’s instructions or your docs.
  • If a line has to stay, explain it in the submission’s notes for reviewers.

How common it is: in our scan of Claude’s connector directory on 29 September, 21% of servers tell the model what to do inside a tool description (118 of 564).

Caught by

Applies to Claude Connectors · Claude Plugins

What reviewers and the rules say

“MCP servers must provide all applicable annotations for their tools, in particular readOnlyHint, destructiveHint, and title.”
Claude Connectors · Anthropic’s directory policy

Claude shows a tool’s title in permission prompts and in the directory, and its submission portal flags tools without one. Without a title, people see the raw name, such as search_docs_v2.

How to fix it

  • Add title to each tool, or annotations.title.
  • Keep titles short and plain: “Search documents”, not the function name.

How common it is: in our scan of Claude’s connector directory on 29 September, 9% of servers have tools without a human-readable title (52 of 564).

Caught by

  • tools.title Every tool has a human-readable titleServer check

Policy

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Muse Connectors · Cursor Marketplace · Microsoft 365 Agent Store

What reviewers and the rules say

“Missing or incomplete privacy policies result in immediate rejection.”
Claude Connectors · Anthropic’s submission guide
privacy policy gaps and undisclosed returned data
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)

Every store asks for a privacy policy, and reviewers read it. Anthropic wants it to cover data collection, usage and storage, third-party sharing, retention and contact information. OpenAI asks for the categories of personal data you collect, why you use them, who receives them, how long you keep them and what users can do about it. Data your tools return that the policy doesn’t mention counts as a gap.

How to fix it

  • Link a page that loads without signing in.
  • Cover collection, use, sharing, retention, user controls such as deletion, and how to contact you.
  • Mention the data your tools return and any free-form content users send, not only what they type into forms.

How common it is: in our scan of Claude’s connector directory on 29 September, 4% of servers link a privacy policy that doesn’t load (145 of 3,283).

Caught by

Listing details

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Microsoft 365 Agent Store

What reviewers and the rules say

“Up to three starter prompts, at most 128 characters each. Make them unique and omit app @mentions.”
ChatGPT Plugins · OpenAI’s submission docs
“server name up to 100 characters, one-liner up to 200 characters, description up to 2,000 characters”
Claude Connectors · Anthropic’s submission guide
“Tool names must be 64 characters or fewer.”
Claude Connectors · Anthropic’s connector checklist
“Each prompt mustn’t exceed 128 characters.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)

Each store enforces its own limits, some without telling you until review. ChatGPT’s display name and subtitle stop at 30 characters each, and it takes up to three starter prompts. Claude caps names at 100 characters, one-liners at 200, descriptions at 2,000 and tool names at 64. Microsoft wants three to five prompts per command, none over 128 characters.

How to fix it

  • Keep a shorter name for ChatGPT if yours runs past 30 characters.
  • Write up to three distinct starter prompts for ChatGPT, without @mentions.
  • Rename any tool over 64 characters.

How common it is: in our scan of Claude’s connector directory on 29 September, 3% of servers have a name longer than ChatGPT’s 30 characters (92 of 3,283).

Caught by

Plugin package

Applies to ClawHub · Claude Plugins · ChatGPT Plugins

What reviewers and the rules say

“File appears to expose a hardcoded API secret or token.”
ClawHub · ClawHub’s security scan, quoted in an issue
“Keep private credentials and secrets out of the ZIP.”
ChatGPT Plugins · OpenAI’s submission docs

Stores scan what you upload. A key in an MCP server’s headers or a token in a config file blocks the submission: Claude’s plugin validation reports “Secret in MCP headers”. ClawHub’s scanner also flags lines that only look like a secret, such as a command that reads a password from the user.

How to fix it

  • Ask for keys at install time. Claude plugins use a userConfig entry marked sensitive: true.
  • Keep credentials out of the ZIP, the repository and skill files.
  • Rewrite examples that look like real keys.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Applies to Claude Plugins · Cursor Marketplace · Grok Plugins · Gemini CLI Extensions · Docker MCP Catalog

What reviewers and the rules say

“Put a README of at least 40 words in the plugin folder”
Claude Plugins · Anthropic’s plugin checklist (blocks if missing)
“main, v1.2.3, and abbreviated SHAs are rejected by the validator.”
Grok Plugins · xAI’s contributing guide
“looks like there’s a failure in the CI job that ran, you’ll need to fix that first”
Docker MCP Catalog · A Docker maintainer on a pull request
“(MIT or Apache 2 are great, GPL is not).”
Docker MCP Catalog · Docker’s contributing guide

Stores that take plugins read them from a public GitHub repository at a pinned commit, and validate it before anyone reviews it. A private repository, a missing manifest, README or licence, a branch instead of a commit, or a failing CI run leaves nothing to review. Gemini CLI’s gallery skips a repository that fails validation without saying so.

How to fix it

  • Host the plugin in its own public GitHub repository. A private monorepo can’t be pinned.
  • Claude: add .claude-plugin/plugin.json, a README of at least 40 words and a LICENSE, then run claude plugin validate --strict.
  • Don’t leave a SKILL.md at the root beside a skills/ folder. Claude loads it as a single-skill plugin and hides the rest.
  • Grok: pin a full 40-character commit SHA, not main or a tag.
  • Docker: use a licence that lets people run the server, such as MIT or Apache 2.0, and get CI green before asking for review.
  • Gemini CLI: put gemini-extension.json at the root and add the gemini-cli-extension topic.

Caught by

The store itself

Applies to ChatGPT Plugins · Claude Plugins · Grok Plugins · Docker MCP Catalog · Gemini CLI Extensions · Cursor Marketplace

What reviewers and the rules say

The submission portal only shows “Rejected” with no notes.
Claude Plugins · A developer in Anthropic’s plugin issue tracker (paraphrased)
The rejection email said “Please see the details below:”, followed by nothing.
ChatGPT Plugins · A developer on the OpenAI developer forum (paraphrased)

Some reviews end without an explanation. ChatGPT rejection emails have arrived with an empty details section, Claude’s old plugin portal showed “Rejected” with no notes, Grok and Docker maintainers often close pull requests without a comment, Gemini CLI’s crawler skips repositories silently, and Cursor’s publish form sends no confirmation.

How to fix it

  • ChatGPT: reply to the rejection email with your case ID and ask for the specific finding.
  • On a pull request, ask what would make it acceptable.
  • Rule out the mechanical causes with a server check before you resubmit.

Of the 6 pull requests maintainers closed in the Grok and Docker queues we track, none had a comment saying why (checked 1 October).

Caught by

No script can see this one. A server check rules out the mechanical causes first.

How this is counted

Reports count rejected submissions where the developer picked the reason, or wrote a note that names it. Pull requests closed in the Grok and Docker queues count as rejections, but carry no reason.

The reasons themselves come from rejection emails developers have shared, public posts, the stores’ own docs and our own submissions. Each check is open source in mcplane, and the server check runs the ones marked “Server check”. Tool checks need tools that list without sign-in; for a server behind sign-in, run mcplane with --token.

Rejected?

Add it with the reason. The next developer sees it here, and the store’s review times include it.

Add your rejection

Already reported it as waiting? Open your private link and mark it rejected; the reason is on the same form.