Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add cruisediary/apple-app-review-skills --skill ai-data-disclosuregit clone --depth 1 https://github.com/cruisediary/apple-app-review-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cruisediary/apple-app-review-skills/ai-data-disclosure)<a href="https://agentmods.dev/skills/cruisediary/apple-app-review-skills/ai-data-disclosure"><img src="https://agentmods.dev/badge/skills/cruisediary/apple-app-review-skills/ai-data-disclosure/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/cruisediary/apple-app-review-skills/ai-data-disclosure"><img src="https://agentmods.dev/badge/skills/cruisediary/apple-app-review-skills/ai-data-disclosure.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00036 | $0.01832 |
| Opus 5 | $0.00018 | $0.00916 |
| Sonnet 5 | $0.00007 | $0.00366 |
| Haiku 4.5 | $0.00004 | $0.00183 |
Grade A, and why
ai-data-disclosure scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 131 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: AI Data Disclosure
Purpose
Detects apps that send user data to third-party AI systems (OpenAI, Google Gemini, Anthropic, etc.) without explicit in-app consent and disclosure, enforcing Guideline 5.1.2(i) which requires transparency before any user data is transmitted to external AI services.
Apple Guideline
- Primary: 5.1.2(i) — Privacy: Third-Party AI Data Sharing
- Related: 5.1.1(i) — Privacy Policy
- Reference:
references/guidelines/5-legal.md
Real-World Rejection Cases
-
Case: App sent user messages to OpenAI API without disclosing this in the app or privacy policy — rejected under 5.1.2(i) Source: Apple Developer Forums (multiple developer reports, 2023–2024) Root cause: Guideline 5.1.2(i) requires explicit disclosure and user consent before transmitting data to any third-party AI system — a generic "we may share data with service providers" clause in the privacy policy is insufficient; the app must present a clear in-app notice before AI processing occurs
-
Case: Health app transcribed user speech on-device and then sent transcripts to a third-party LLM for analysis — rejected for undisclosed AI data sharing Source: Apple Developer Forums (2024) Root cause: Any transmission of user-provided content to an external AI service requires explicit opt-in consent, regardless of whether the data was first processed on-device — the forwarding to an external AI is the disclosure trigger
Trigger
Invoke on any iOS/macOS project that integrates AI/ML APIs, chat features, or sends user-generated content to external services.
Inputs
| Name | Type | Default | Description |
|---|---|---|---|
project_root |
path | cwd | iOS/macOS project root |
shared_context |
object | nil | Pre-collected context from appstore-full-audit Phase 1 |
Actions
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 131 lines · 36 tokens per session scan A 426de0752792
ai-data-disclosure is a skill published in the GitHub repository cruisediary/apple-app-review-skills (16 stars, last pushed 4mo ago), licensed MIT. It adds 36 tokens to every session and 1,832 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
benchmark
Run performance + quality benchmarks. ASR reports WER, RTF, process memory, and throughput across engines/variants. Arguments include asr, tts, vad, diarize, asr-quick.
review-pr
Review a pull request for conceptual fit, architecture impact, adversarial failure modes, security risk, docs impact, regression risk, test coverage, and merge readiness. Use when asked to review a PR, check whether a PR is safe to merge, decide if more tests are needed, perform adversarial or security review, or…
boutique-best-practices
Best practices for using Boutique with Swift 6 concurrency, @Observable, @ObservationIgnored, Sendable conformance, testing with preview stores, and dependency injection. Use when troubleshooting Boutique issues, migrating to Swift 6, or setting up tests.
boutique-store
Create and use Boutique Store for Swift data persistence, including initialization, @Stored controllers, CRUD operations, operation chaining, and granular event monitoring. Use when persisting arrays of items, building data controllers, or working with Boutique's Store type.
boutique-stored-values
Persist individual values with Boutique's @StoredValue (UserDefaults) and @SecurelyStoredValue (Keychain), including set, reset, toggle, bindings, keypath setters, array and dictionary helpers, and async observation. Use when storing preferences, settings, feature flags, or sensitive data like auth tokens.
boutique-swiftui
Integrate Boutique with SwiftUI views using onChange, onStoreDidLoad, bindings, and preview stores. Use when building SwiftUI views that display or react to Boutique-persisted data.