app-rejection-recovery

app-rejection-recovery is a skill for Claude Code from Eronred/aso-skills. It costs 168 tokens per session (2,235 once invoked), scanned A, original, MIT.

A guide for handling rejected mobile apps, including rejections from Apple's App Store or Google's Play Store.

In plain words
What is it for?
Collecting rejection details, classifying the violation, fixing app or listing issues, and preparing an appeal or resubmission.
Why use it?
It structures the diagnosis of policy problems, the required fixes, and the response needed for resubmission.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the aso-skills plugin — 40 skills shipped together

Good fit Collecting rejection details, classifying the violation, fixing app or listing issues, and preparing an appeal or resubmission.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/eronred/aso-skills/app-rejection-recovery
About the project

ASO & App Marketing Skills is a collection of AI-agent skills for improving mobile-app discoverability and marketing through keyword research, metadata optimization, competitor analysis, and market data. It is for indie developers, app marketers, and growth teams using compatible coding agents, and the catalogue contains the skills and instructions they use.

Eronred/aso-skills · 1,851 stars · on GitHub · appeeky.com

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add Eronred/aso-skills --skill app-rejection-recovery
Clone the repo
git clone --depth 1 https://github.com/Eronred/aso-skills

Made for: Claude Code.

Or install aso-skills, the plugin that ships this one along with the rest of its 40 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for app-rejection-recovery

README.md
[![agentmods](https://agentmods.dev/badge/skills/eronred/aso-skills/app-rejection-recovery/github.svg)](https://agentmods.dev/skills/eronred/aso-skills/app-rejection-recovery)
Your own site
<a href="https://agentmods.dev/skills/eronred/aso-skills/app-rejection-recovery"><img src="https://agentmods.dev/badge/skills/eronred/aso-skills/app-rejection-recovery/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for app-rejection-recovery

Your own site · 80×15
<a href="https://agentmods.dev/skills/eronred/aso-skills/app-rejection-recovery"><img src="https://agentmods.dev/badge/skills/eronred/aso-skills/app-rejection-recovery.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 168 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,235 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • Socket pass 8 May 2026
  • Snyk fail 8 May 2026
  • NVIDIA SkillSpector warn 7 Sept 2026
SkillSpector: 2 findings, up to medium

These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →

  • medium Rogue Agent · line 83
    Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
    Fix: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.
  • medium Rogue Agent · line 175
    Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
    Fix: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00168 $0.02235
Opus 5 $0.00084 $0.01118
Sonnet 5 $0.00034 $0.00447
Haiku 4.5 $0.00017 $0.00224

Measured 13d ago against content hash 19c64c811410, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

app-rejection-recovery scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/app-rejection-recovery/SKILL.md · 212 lines

How it starts

The opening of the file, as written. The whole thing — 212 lines — stays where its author put it; the contents beside it link to each section on GitHub.

App Rejection Recovery

You are an App Review specialist. Your goal is to diagnose the rejection, write a clean response (or appeal), fix the underlying issue, and get the user resubmitted within 24–72 hours.

Initial Assessment

  1. Ask the user to paste the full rejection message verbatim — including the guideline number(s)
  2. Ask: App Store, Play Store, or both?
  3. Ask: First submission or update? (First submissions are scrutinized harder)
  4. Ask: App ID and app category
  5. Ask: What was changed in this version vs the last approved version (for updates)
  6. Ask: Is this time-sensitive (launch date, marketing tied)?

Do not start writing the fix until you've classified the rejection type below.

Apple Rejection Taxonomy

Map the guideline number to the bucket:

Guideline Bucket Typical fix
2.1 Performance / completeness Test on physical device, fix crashes, add missing demo content
2.3.x Accurate metadata Match screenshots to actual app, remove unsupported devices, fix description
2.5.x Software requirements Use approved APIs only, fix private API use, fix HealthKit/SiriKit misuse
3.1.1 In-app purchase Use IAP for digital goods, no external payment links
3.1.2 Subscriptions Auto-renewal disclosure, restore purchases, terms link
3.2.2 Unacceptable business model Multi-level marketing, scams, etc.
4.0 Design Spam, copycat UI, broken layouts
4.2 Minimum functionality Web wrappers, "thin" apps, brochureware
4.3 Spam Duplicate of own/other app — most common rejection
4.5.x Apple sites and services Wrong logo use, push notification misuse
5.1.1 Privacy / data collection Privacy policy URL, data collection disclosure, ATT prompt copy
5.1.2 Data use & sharing Match privacy nutrition labels to actual collection
5.1.5 Location services Justify "Always" location, ATT-style strings
5.1.7 Health & medical Disclaimers, no diagnostic claims without FDA
5.2.x Intellectual property Trademark/IP holder permission required
5.3.x Gaming, gambling, lotteries License requirements
5.6.1 Developer code of conduct Spam, fake reviews, manipulation

Read the full file on GitHub · 212 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 13d ago First seen · 212 lines · 168 tokens per session scan A 19c64c811410

Subscribe to this mod's changes

app-rejection-recovery is a skill published in the GitHub repository Eronred/aso-skills (1,851 stars, last pushed 20d ago), licensed MIT. It adds 168 tokens to every session and 2,235 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

asc-app-create-ui

Create an App Store Connect app via iris API using web session from Blitz.

blitzdotdev/blitz-mac · 19 tokens

gingiris-aso-growth

A broad guide to growing mobile apps through App Store Optimization, launch planning, creator-made content, and marketing on platforms such as TikTok, Instagram, and YouTube Shorts.

Gingiris-1031/gingiris-skills · 320 tokens

site-to-ios-app

Use when converting any website, web app, PWA, SaaS dashboard, content site, or marketplace into an iOS app using the public Suede-originated site-to-iOS workflow. Covers URL audit, App Store 4.2 wrapper-risk checks, Capacitor or native-shell strategy, native value requirements, iOS build scaffolding, screenshots…

JasonColapietro/ios-app-dev-skills · 85 tokens

ios-screenshot-taker

Use when capturing deterministic iOS simulator screenshots for App Store, TestFlight, QA, launch pages, or marketing decks. Covers xcodebuild build, simulator boot/install/launch, seeded demo states, xcrun simctl screenshots, required App Store device classes, public-safe output handling, and slash commands such as…

JasonColapietro/ios-app-dev-skills · 78 tokens

google-play

A Google Play Store API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no Google Play Console access. Use when the user wants to search Android apps by keyword with price (free/paid) and country storefront filters, fetch an app's full details, reviews sorted by…

fetcher-sh/fetcher-skills · 131 tokens

ios-app-factory

Use when planning, creating, or orchestrating a complete iOS app-development workflow from idea or keyword to ship gate. Covers keyword-first product selection, native SwiftUI scaffolding, monetization, screenshots, ASO metadata, legal/compliance, grading, release handoff, and slash-command orchestration such as…

JasonColapietro/ios-app-dev-skills · 87 tokens