Review times
← Microsoft 365 Agent Store
Rejection library

Why Microsoft 365 agents get rejected

What Microsoft has said when it turned Microsoft 365 agents down, what causes each reason, and how to fix it before you submit.

5 reasons
0 rejections reported, 0 with a reason

How rejections arriveStatus and validation feedback live in Partner Center, and Microsoft marks each validation rule “Must fix” or not. No Agent Store rejections have been reported here yet.

Free, nothing stored. From a terminal: npx mcplane preflight --url https://your-server/mcp (mcplane docs).

At a glance

ReasonApplies toReportsCaught by
Test cases failedChatGPT Plugins, Grok Plugins, Microsoft 365 Agent Store–mcplane CLI
Descriptions instruct the modelClaude Connectors, Claude Plugins, ChatGPT Plugins, Microsoft 365 Agent Store, Grok Plugins, ClawHub–Server check
Privacy policyChatGPT Plugins, Claude Connectors, Claude Plugins, Muse Connectors, Cursor Marketplace, Microsoft 365 Agent Store–Server check
Field too long or invalidChatGPT Plugins, Claude Connectors, Claude Plugins, Microsoft 365 Agent Store–Server check + CLI
Not enough beyond CopilotMicrosoft 365 Agent Store–By hand

Tool definitions

Applies to Claude Connectors · Claude Plugins · ChatGPT Plugins · Microsoft 365 Agent Store · Grok Plugins · ClawHub

What reviewers and the rules say

“Instructional phrases, for example, 'if the user says X', 'ignore', 'delete', 'reset', 'new instructions', 'Answer in Bold', or 'Do not print anything'.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)
“Describe what the tool does, and don’t tell Claude how to behave.”
Claude Connectors · Anthropic’s connector checklist
manipulative ranking language in tool descriptions
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)
“authority too broad / could change agent behavior without clear guardrails”
ClawHub · ClawHub’s security scan, quoted in an issue

Lines such as “always call this tool first” or “never tell the user” read as an attempt to steer the model, the same shape as prompt injection. Anthropic rejects descriptions that tell Claude to call tools the user didn’t ask for or interfere with other tools. OpenAI’s rules say tool metadata must not override platform instructions or safeguards. Microsoft rejects instructional phrases in any description, xAI looks for prompt injection in SKILL.md and descriptions, and ClawHub’s scanner flags text that could change an agent’s behaviour. Naming a sibling tool to call first is common in approved listings and isn’t the problem.

How to fix it

  • Describe what the tool does and returns, as facts.
  • Move usage guidance into the server’s instructions or your docs.
  • If a line has to stay, explain it in the submission’s notes for reviewers.

How common it is: in our scan of Claude’s connector directory on 29 September, 21% of servers tell the model what to do inside a tool description (118 of 564).

Caught by

Policy

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Muse Connectors · Cursor Marketplace · Microsoft 365 Agent Store

What reviewers and the rules say

“Missing or incomplete privacy policies result in immediate rejection.”
Claude Connectors · Anthropic’s submission guide
privacy policy gaps and undisclosed returned data
ChatGPT Plugins · A developer listing their rejection reasons on the OpenAI developer forum (paraphrased)

Every store asks for a privacy policy, and reviewers read it. Anthropic wants it to cover data collection, usage and storage, third-party sharing, retention and contact information. OpenAI asks for the categories of personal data you collect, why you use them, who receives them, how long you keep them and what users can do about it. Data your tools return that the policy doesn’t mention counts as a gap.

How to fix it

  • Link a page that loads without signing in.
  • Cover collection, use, sharing, retention, user controls such as deletion, and how to contact you.
  • Mention the data your tools return and any free-form content users send, not only what they type into forms.

How common it is: in our scan of Claude’s connector directory on 29 September, 4% of servers link a privacy policy that doesn’t load (145 of 3,283).

Caught by

Applies to Microsoft 365 Agent Store

What reviewers and the rules say

“Agents should be designed to complete enterprise workflows and must deliver differentiated value beyond what Copilot offers”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)

Microsoft rejects agents that do what Copilot already does. Its examples of differentiated value are workflows Copilot can’t do easily, such as creating tickets directly in a ticketing platform, and workflows the agent makes much faster.

How to fix it

  • Lead the description with the workflow your agent completes that Copilot can’t.
  • Make the sample prompts show that workflow.

Caught by

No script can see this one. A server check rules out the mechanical causes first.

Listing details

Applies to ChatGPT Plugins · Claude Connectors · Claude Plugins · Microsoft 365 Agent Store

What reviewers and the rules say

“Each prompt mustn’t exceed 128 characters.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines (must fix)
“Up to three starter prompts, at most 128 characters each. Make them unique and omit app @mentions.”
ChatGPT Plugins · OpenAI’s submission docs
“server name up to 100 characters, one-liner up to 200 characters, description up to 2,000 characters”
Claude Connectors · Anthropic’s submission guide
“Tool names must be 64 characters or fewer.”
Claude Connectors · Anthropic’s connector checklist

Each store enforces its own limits, some without telling you until review. ChatGPT’s display name and subtitle stop at 30 characters each, and it takes up to three starter prompts. Claude caps names at 100 characters, one-liners at 200, descriptions at 2,000 and tool names at 64. Microsoft wants three to five prompts per command, none over 128 characters.

How to fix it

  • Keep a shorter name for ChatGPT if yours runs past 30 characters.
  • Write up to three distinct starter prompts for ChatGPT, without @mentions.
  • Rename any tool over 64 characters.

How common it is: in our scan of Claude’s connector directory on 29 September, 3% of servers have a name longer than ChatGPT’s 30 characters (92 of 3,283).

Caught by

Testing

Applies to ChatGPT Plugins · Grok Plugins · Microsoft 365 Agent Store

What reviewers and the rules say

“All sample prompts must be functional and return responses.”
Microsoft 365 Agent Store · Microsoft’s agent validation guidelines
“One or more of your test cases did not produce correct results. Please re-run all submitted test cases and align tool behavior/output with the documented expected outcomes.”
ChatGPT Plugins · A rejection posted on the OpenAI developer forum
“could you share a short Grok Build demo covering sign-in, OAuth consent, and a harmless request”
Grok Plugins · An xAI reviewer on a pull request

Reviewers run what you give them, as the account you gave them, against your live server: ChatGPT’s five positive and three negative test cases, Microsoft’s sample prompts, or a demo for Grok. A test that names a tool you have since renamed, or expects data that has since changed, reads as a broken app. OpenAI also expects the same test cases to pass on ChatGPT web and mobile.

How to fix it

  • In each test case, name only tools the live server has.
  • Seed the demo account with the data every test case expects, and check it again right before you submit.
  • Record ChatGPT’s video walkthrough in developer mode, and again whenever tools change.
  • Give write tools a safe target, so reviewers don’t post to a real account.
  • For Grok, be ready to share a short demo of sign-in, OAuth consent and a harmless request.

Caught by

  • listing.test-tools Test cases use tools the server hasmcplane CLI
  • Demo data matches every test case, checked right before submittingBy hand

How this is counted

Reports count rejected submissions where the developer picked the reason, or wrote a note that names it. Pull requests closed in the Grok and Docker queues count as rejections, but carry no reason.

The reasons themselves come from rejection emails developers have shared, public posts, the stores’ own docs and our own submissions. Each check is open source in mcplane, and the server check runs the ones marked “Server check”. Tool checks need tools that list without sign-in; for a server behind sign-in, run mcplane with --token.

Rejected?

Add it with the reason. The next developer sees it here, and the store’s review times include it.

Add your rejection

Already reported it as waiting? Open your private link and mark it rejected; the reason is on the same form.