Marketplace Publisher Guidelines

Effective date: August 7, 2026

Phase 2 Scope and Acceptance

These guidelines apply when a creator submits a Skill, Agent, remote MCP Connector, or Bundle for the Anystart Marketplace. They supplement the Terms of Service, Privacy Policy, and Creator Profile Guidelines. Submitting a release with the current Marketplace Publisher agreement is a separate acceptance action from activating a creator profile.

Phase 2 does not include paid listings, invocation earnings, revenue sharing, royalties, payouts, or any other compensation. Publishing creates no right to ranking, promotion, continued distribution, review within a particular time, or approval of later releases.

Rights, Accuracy, and Support

You must own or have all licenses and permissions needed for every submitted name, description, icon, archive, instruction, prompt, configuration, dependency, trademark, and other material. Your listing and declared capabilities must be accurate and must not conceal behavior, external services, data flows, costs, authentication requirements, or material limitations. You remain responsible for licensing, support, maintenance, security notices, and lawful operation of your plugin and its third-party services.

Do not submit malware, credential theft, phishing, spam, evasion or persistence mechanisms, destructive or deceptive behavior, unlawful or infringing material, undisclosed surveillance, sexual exploitation, hate or harassment, threats, promotion of self-harm or terrorism, or content designed to defeat Anystart safeguards. Do not include secrets, private keys, access tokens, passwords, personal data that you lack permission to distribute, or instructions to obtain such material.

Package and Connector Safety

Packages must use the supported Marketplace format and limits. Marketplace MCP Connectors must use declared remote HTTPS HTTP or SSE endpoints only. Local stdio, commands, arguments, working directories, private-network targets, embedded credentials, and literal secret values are prohibited.

Required credential variable names may be disclosed, but customer credentials remain on the customer's device and are not included in Marketplace cloud records. Clearly disclose the connector provider, origin, transport, authentication method, data categories sent, whether data leaves the device, and links to applicable support, privacy, and terms information.

Review and Publication

Anystart may automatically inspect, unpack, scan, and manually review a private plugin archive, listing claims, connector declarations, and related evidence. Review applies only to the exact release and archive hash submitted. Approval means only that the reviewed release may be published under the then-current Marketplace rules; it is not certification, verification, endorsement, or a warranty of safety, quality, legality, or fitness.

We may request changes, reject a submission, preserve the last approved public release while another release is reviewed, or require re-review when executable behavior, permissions, connectors, data handling, or other material claims change. Do not bypass review by changing remote behavior or using a listing that misrepresents the approved release.

Distribution License and Installed Copies

For each submitted release, you grant Anystart a worldwide, non-exclusive, royalty-free license to store, copy, unpack, inspect, scan, technically modify, display, promote, transmit, distribute, and make that release available for installation, restoration, security review, moderation, dispute handling, and service continuity. You also authorize end users to download, install, locally execute, and use the release through Anystart for its intended Marketplace purpose. These licenses continue for existing installations and necessary archive, audit, security, dispute, and legal records after normal unpublishing or account deletion to the extent described in the Terms and Privacy Policy.

You may unpublish a listing to stop discovery and new installs. Unpublishing does not remotely erase installed copies or automatically switch existing users to another release. Anystart requires an explicit user action to install a newer approved creator release. The platform may suspend or remove a listing separately from revoking a release. A revoked release may be blocked when a device next reconciles with Anystart; a device that remains offline may not receive that status immediately.

Reports, Enforcement, and Appeals

Users may report a plugin. Anystart may investigate, restrict discovery, suspend or remove a listing, revoke a release, roll back to another previously approved release when safe, suspend the creator profile or account, or take other proportionate action. Serious security, legal, fraud, or safety concerns may require immediate action without advance notice. Reports and review do not guarantee a particular result or response time.

To appeal a decision or submit an intellectual-property, privacy, or other rights complaint, email [email protected] with the listing slug and enough information to evaluate the request. Do not include unnecessary sensitive information. If you stop supporting a plugin or become aware of a vulnerability or misleading disclosure, notify Anystart and affected users promptly and cooperate on a safe wind-down.

Privacy and Records

Draft listings and archives are private to the creator and authorized reviewers until publication. Approved public listing metadata and reviewed capability disclosures become public; private archive contents, review notes, reports, internal identifiers, and credentials are not intentionally published. Anystart may retain immutable releases, terms acknowledgements, review and moderation history, reports, reserved slugs, and security evidence as described in the Privacy Policy.