Review times
← ClawHub
Rejection library

Why ClawHub skills get rejected

What OpenClaw has said when it turned ClawHub skills down, what causes each reason, and how to fix it before you submit.

2 reasons
0 rejections reported, 0 with a reason

How rejections arriveSkills are held while an automated security scan runs, and the scan can mark a skill suspicious with a short reason. No ClawHub rejections have been reported here yet.

Free, nothing stored. From a terminal: npx mcplane preflight --url https://your-server/mcp (mcplane docs).

At a glance

ReasonApplies toReportsCaught by
Descriptions instruct the modelClaude Connectors, Claude Plugins, ChatGPT Plugins, Microsoft 365 Agent Store, Grok Plugins, ClawHub–Server check
Secret in the packageClawHub, Claude Plugins, ChatGPT Plugins–By hand

Tool definitions

Applies to Claude Connectors · Claude Plugins · ChatGPT Plugins · Microsoft 365 Agent Store · Grok Plugins · ClawHub

What reviewers and the rules say

“authority too broad / could change agent behavior without clear guardrails”
ClawHub · ClawHub’s security scan, quoted in an issue
“Describe what the tool does, and don’t tell Claude how to behave.”
Claude Connectors · Anthropic’s connector checklist
manipulative ranking language in tool descriptions
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)
“Instructional phrases, for example, 'if the user says X', 'ignore', 'delete', 'reset', 'new instructions', 'Answer in Bold', or 'Do not print anything'.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)

Lines such as “always call this tool first” or “never tell the user” read as an attempt to steer the model, the same shape as prompt injection. Anthropic rejects descriptions that tell Claude to call tools the user didn’t ask for or interfere with other tools. OpenAI’s rules say tool metadata must not override platform instructions or safeguards. Microsoft rejects instructional phrases in any description, xAI looks for prompt injection in SKILL.md and descriptions, and ClawHub’s scanner flags text that could change an agent’s behaviour. Naming a sibling tool to call first is common in approved listings and isn’t the problem.

How to fix it

  • Describe what the tool does and returns, as facts.
  • Move usage guidance into the server’s instructions or your docs.
  • If a line has to stay, explain it in the submission’s notes for reviewers.

How common it is: in our scan of Claude’s connector directory on 29 September, 21% of servers tell the model what to do inside a tool description (118 of 564).

Caught by

Plugin package

Applies to ClawHub · Claude Plugins · ChatGPT Plugins

What reviewers and the rules say

“File appears to expose a hardcoded API secret or token.”
ClawHub · ClawHub’s security scan, quoted in an issue
“Keep private credentials and secrets out of the ZIP.”
ChatGPT Plugins · OpenAI’s submission docs

Stores scan what you upload. A key in an MCP server’s headers or a token in a config file blocks the submission: Claude’s plugin validation reports “Secret in MCP headers”. ClawHub’s scanner also flags lines that only look like a secret, such as a command that reads a password from the user.

How to fix it

  • Ask for keys at install time. Claude plugins use a userConfig entry marked sensitive: true.
  • Keep credentials out of the ZIP, the repository and skill files.
  • Rewrite examples that look like real keys.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

How this is counted

Reports count rejected submissions where the developer picked the reason, or wrote a note that names it. Pull requests closed in the Grok and Docker queues count as rejections, but carry no reason.

The reasons themselves come from rejection emails developers have shared, public posts, the stores’ own docs and our own submissions. Each check is open source in mcplane, and the server check runs the ones marked “Server check”. Tool checks need tools that list without sign-in; for a server behind sign-in, run mcplane with --token.

Rejected?

Add it with the reason. The next developer sees it here, and the store’s review times include it.

Add your rejection

Already reported it as waiting? Open your private link and mark it rejected; the reason is on the same form.