Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add cruisediary/apple-app-review-skills --skill ugc-safety-featuresgit clone --depth 1 https://github.com/cruisediary/apple-app-review-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cruisediary/apple-app-review-skills/ugc-safety-features)<a href="https://agentmods.dev/skills/cruisediary/apple-app-review-skills/ugc-safety-features"><img src="https://agentmods.dev/badge/skills/cruisediary/apple-app-review-skills/ugc-safety-features/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/cruisediary/apple-app-review-skills/ugc-safety-features"><img src="https://agentmods.dev/badge/skills/cruisediary/apple-app-review-skills/ugc-safety-features.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00035 | $0.02067 |
| Opus 5 | $0.00017 | $0.01033 |
| Sonnet 5 | $0.00007 | $0.00413 |
| Haiku 4.5 | $0.00003 | $0.00207 |
Grade A, and why
ugc-safety-features scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 168 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: UGC Safety Features
Purpose
Detects missing mechanisms required for apps with user-generated content under Guideline 1.2. Apple explicitly requires all four of the following:
- Content filtering — objectionable content must be filterable before it surfaces to other users
- Report mechanism — users must be able to flag offensive posts, comments, and profiles
- Block mechanism — users must be able to block abusive users
- Published contact info — a developer contact method must be accessible within the app for users to report issues directly
Apple Guideline
- Primary: 1.2 — Safety: User Generated Content
- Related: 5.1.1(ii)
- Reference:
references/guidelines/1-safety.md
Real-World Rejection Cases
-
Case: App with user posts had no "Report" button — rejected under Guideline 1.2 Source: https://developer.apple.com/forums/thread/116703 Root cause: Apps with user-generated content must provide mechanism to report offensive content
-
Case: iOS app rejected 1.2 Safety — no ability to block abusive users Source: https://developer.apple.com/forums/thread/78288 Root cause: Guideline 1.2 requires block mechanism, not just report
-
Case: Community app rejected — no EULA requiring users to agree to content standards Source: https://buddyboss.com/docs/app-store-guideline-1-2-safety-user-generated-content/ Root cause: Users must agree to terms prohibiting objectionable content
Trigger
Invoke on any iOS/macOS project that includes user posts, comments, chat, or community features.
Inputs
| Name | Type | Default | Description |
|---|---|---|---|
project_root |
path | cwd | iOS/macOS project root |
shared_context |
object | nil | Pre-collected context from appstore-full-audit Phase 1 |
Actions
Phase 1: Context Collection
Skip this phase if shared_context is provided.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 168 lines · 35 tokens per session scan A 50617b1bc367
ugc-safety-features is a skill published in the GitHub repository cruisediary/apple-app-review-skills (16 stars, last pushed 4mo ago), licensed MIT. It adds 35 tokens to every session and 2,067 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
benchmark
Run performance + quality benchmarks. ASR reports WER, RTF, process memory, and throughput across engines/variants. Arguments include asr, tts, vad, diarize, asr-quick.
review-pr
Review a pull request for conceptual fit, architecture impact, adversarial failure modes, security risk, docs impact, regression risk, test coverage, and merge readiness. Use when asked to review a PR, check whether a PR is safe to merge, decide if more tests are needed, perform adversarial or security review, or…
boutique-best-practices
Best practices for using Boutique with Swift 6 concurrency, @Observable, @ObservationIgnored, Sendable conformance, testing with preview stores, and dependency injection. Use when troubleshooting Boutique issues, migrating to Swift 6, or setting up tests.
boutique-store
Create and use Boutique Store for Swift data persistence, including initialization, @Stored controllers, CRUD operations, operation chaining, and granular event monitoring. Use when persisting arrays of items, building data controllers, or working with Boutique's Store type.
boutique-stored-values
Persist individual values with Boutique's @StoredValue (UserDefaults) and @SecurelyStoredValue (Keychain), including set, reset, toggle, bindings, keypath setters, array and dictionary helpers, and async observation. Use when storing preferences, settings, feature flags, or sensitive data like auth tokens.
boutique-swiftui
Integrate Boutique with SwiftUI views using onChange, onStoreDidLoad, bindings, and preview stores. Use when building SwiftUI views that display or react to Boutique-persisted data.