App Store Preflight Skill
Scan an iOS/macOS Xcode project for common App Store rejection patterns before submission.
by truongduy2611·MIT license·★ 1,380 Stars on the repo·GitHub ↗
Files of App Store Preflight Skill
truongduy2611/
Show the full text128 lines
App Store Preflight Skill
Run pre-submission checks on your iOS/macOS project to catch common App Store rejection patterns.
Prerequisites
- asc CLI — Install via Homebrew:
brew install asc(App-Store-Connect-CLI) - ASC CLI Skills — app-store-connect-cli-skills for
ascusage patterns - jq — Optional, but used by some JSON-inspection examples in the rule docs
Step 1: Identify App Type → Load Checklist
Determine which guidelines apply by loading the relevant checklist from references/guidelines/by-app-type/. Always start with all_apps.md, then add the app-type-specific one:
| App Type | Checklist |
|---|---|
| Every app | references/guidelines/by-app-type/all_apps.md |
| Subscriptions / IAP | references/guidelines/by-app-type/subscription_iap.md |
| Social / UGC | references/guidelines/by-app-type/social_ugc.md |
| Kids Category | references/guidelines/by-app-type/kids.md |
| Health & Fitness | references/guidelines/by-app-type/health_fitness.md |
| Games | references/guidelines/by-app-type/games.md |
| macOS | references/guidelines/by-app-type/macos.md |
| AI / Generative AI | references/guidelines/by-app-type/ai_apps.md |
| Crypto & Finance | references/guidelines/by-app-type/crypto_finance.md |
| VPN | references/guidelines/by-app-type/vpn.md |
Full guideline index: references/guidelines/README.md
Step 2: Pull Metadata for Inspection
Pull the latest App Store metadata using the asc CLI:
# Pull canonical metadata JSON for the version you want to review
asc metadata pull --app "<APP_ID>" --version "<VERSION>" --dir ./metadata
asc metadata pull writes app info files to ./metadata/app-info/*.json and
version-localization files to ./metadata/version/<VERSION>/*.json.
Most rule examples below assume the canonical JSON layout written by
asc metadata pull.
If you already have metadata in another layout (for example fastlane
metadata/), either adapt the file-path examples to that structure or pull the
canonical asc layout first.
Step 3: Run Rejection Rule Checks
For each category, load the relevant rule files from references/rules/ and inspect. Each rule contains: What to Check, How to Detect, Resolution, and Example Rejection.
| Category | Rule Files |
|---|---|
| Metadata | references/rules/metadata/*.md |
| Subscription | references/rules/subscription/*.md |
| Privacy | references/rules/privacy/*.md |
| Design | references/rules/design/*.md |
| Entitlements | references/rules/entitlements/*.md |
Step 4: Report Findings
Produce a summary report using this template:
## Preflight Report
### ❌ Rejections Found (N)
- [GUIDELINE X.X.X] Description of issue
- File: path/to/offending/file
- Fix: What to do
### ⚠️ Warnings (N)
- [GUIDELINE X.X.X] Potential issue
### ✅ Passed (N)
- [Category] All checks passed
Order by severity: rejections first, then warnings, then passed.
Step 5: Autofix + Validate
Some issues can be auto-fixed:
- Competitor terms → Suggest replacement text with competitor names removed
- Metadata character limits → Show current vs. max length
- Missing links → Generate template ToS/PP URLs
After applying any auto-fix, re-run the affected checks to confirm the fix resolved the violation. Only mark as resolved once the re-scan passes.
For issues requiring manual intervention (screenshots, UI redesign), provide clear instructions but do not auto-fix.
Gotchas
- China storefront — Banned AI terms (ChatGPT, Gemini, etc.) are checked across ALL locales, not just
zh-Hans. Apple checks every locale visible in the China storefront. - Privacy manifests —
PrivacyInfo.xcprivacyis required even if your app doesn't call Required Reason APIs directly. Third-party SDKs (Firebase, Amplitude, etc.) that useUserDefaultsorNSFileManagertrigger this requirement transitively. - asc auth —
asc metadata pullrequires App Store Connect authentication. Runasc auth loginfirst, or setASC_KEY_ID,ASC_ISSUER_ID, and one ofASC_PRIVATE_KEY_PATH/ASC_PRIVATE_KEY/ASC_PRIVATE_KEY_B64. If you're unsure whatascis picking up, runasc auth doctor. - Subscription metadata — Apple requires ToS/PP links in BOTH the App Store description AND the in-app subscription purchase screen. Missing either one is a separate rejection.
- macOS entitlements — Apple will ask you to justify every temporary exception entitlement (
com.apple.security.temporary-exception.*). Remove entitlements you don't actively use.
Adding New Rules
Create a .md file in the appropriate references/rules/ subdirectory:
# Rule: [Short Title]
- **Guideline**: [Apple Guideline Number]
- **Severity**: REJECTION | WARNING
- **Category**: metadata | subscription | privacy | design | entitlements
## What to Check
## How to Detect
## Resolution
## Example Rejection
| 1 | |
| 2 | name app-store-preflight-skills |
| 3 | description > |
| 4 | Scan an iOS/macOS Xcode project for common App Store rejection patterns before |
| 5 | submission. Use when preparing an app for App Store review, after receiving a |
| 6 | rejection from Apple, or when auditing metadata, subscriptions, privacy manifests, |
| 7 | entitlements, or design compliance. Integrates with the asc CLI for metadata inspection. |
| 8 | metadata |
| 9 | author truongduy2611 |
| 10 | version "1.0" |
| 11 | |
| 12 | |
| 13 | # App Store Preflight Skill |
| 14 | |
| 15 | Run pre-submission checks on your iOS/macOS project to catch common App Store rejection patterns. |
| 16 | |
| 17 | ## Prerequisites |
| 18 | |
| 19 | **asc CLI** — Install via Homebrew: `brew install asc` ([App-Store-Connect-CLI]) |
| 20 | **ASC CLI Skills** — [app-store-connect-cli-skills] for `asc` usage patterns |
| 21 | **jq** — Optional, but used by some JSON-inspection examples in the rule docs |
| 22 | |
| 23 | ## Step 1: Identify App Type → Load Checklist |
| 24 | |
| 25 | Determine which guidelines apply by loading the relevant checklist from `references/guidelines/by-app-type/`. Always start with `all_apps.md`, then add the app-type-specific one: |
| 26 | |
| 27 | | App Type | Checklist | |
| 28 | |----------|-----------| |
| 29 | | Every app | `references/guidelines/by-app-type/all_apps.md` | |
| 30 | | Subscriptions / IAP | `references/guidelines/by-app-type/subscription_iap.md` | |
| 31 | | Social / UGC | `references/guidelines/by-app-type/social_ugc.md` | |
| 32 | | Kids Category | `references/guidelines/by-app-type/kids.md` | |
| 33 | | Health & Fitness | `references/guidelines/by-app-type/health_fitness.md` | |
| 34 | | Games | `references/guidelines/by-app-type/games.md` | |
| 35 | | macOS | `references/guidelines/by-app-type/macos.md` | |
| 36 | | AI / Generative AI | `references/guidelines/by-app-type/ai_apps.md` | |
| 37 | | Crypto & Finance | `references/guidelines/by-app-type/crypto_finance.md` | |
| 38 | | VPN | `references/guidelines/by-app-type/vpn.md` | |
| 39 | |
| 40 | Full guideline index: `references/guidelines/README.md` |
| 41 | |
| 42 | ## Step 2: Pull Metadata for Inspection |
| 43 | |
| 44 | Pull the latest App Store metadata using the `asc` CLI: |
| 45 | |
| 46 | |
| 47 | # Pull canonical metadata JSON for the version you want to review |
| 48 | asc metadata pull --app "<APP_ID>" --version "<VERSION>" --dir ./metadata |
| 49 | |
| 50 | |
| 51 | `asc metadata pull` writes app info files to `./metadata/app-info/*.json` and |
| 52 | version-localization files to `./metadata/version/<VERSION>/*.json`. |
| 53 | |
| 54 | Most rule examples below assume the canonical JSON layout written by |
| 55 | `asc metadata pull`. |
| 56 | |
| 57 | If you already have metadata in another layout (for example fastlane |
| 58 | `metadata/`), either adapt the file-path examples to that structure or pull the |
| 59 | canonical `asc` layout first. |
| 60 | |
| 61 | ## Step 3: Run Rejection Rule Checks |
| 62 | |
| 63 | For each category, load the relevant rule files from `references/rules/` and inspect. Each rule contains: **What to Check**, **How to Detect**, **Resolution**, and **Example Rejection**. |
| 64 | |
| 65 | | Category | Rule Files | |
| 66 | |----------|------------| |
| 67 | | Metadata | `references/rules/metadata/*.md` | |
| 68 | | Subscription | `references/rules/subscription/*.md` | |
| 69 | | Privacy | `references/rules/privacy/*.md` | |
| 70 | | Design | `references/rules/design/*.md` | |
| 71 | | Entitlements | `references/rules/entitlements/*.md` | |
| 72 | |
| 73 | ## Step 4: Report Findings |
| 74 | |
| 75 | Produce a summary report using this template: |
| 76 | |
| 77 | |
| 78 | ## Preflight Report |
| 79 | |
| 80 | ### ❌ Rejections Found (N) |
| 81 | - [GUIDELINE X.X.X] Description of issue |
| 82 | - File: path/to/offending/file |
| 83 | - Fix: What to do |
| 84 | |
| 85 | ### ⚠️ Warnings (N) |
| 86 | - [GUIDELINE X.X.X] Potential issue |
| 87 | |
| 88 | ### ✅ Passed (N) |
| 89 | - [Category] All checks passed |
| 90 | |
| 91 | |
| 92 | Order by severity: rejections first, then warnings, then passed. |
| 93 | |
| 94 | ## Step 5: Autofix + Validate |
| 95 | |
| 96 | Some issues can be auto-fixed: |
| 97 | **Competitor terms** → Suggest replacement text with competitor names removed |
| 98 | **Metadata character limits** → Show current vs. max length |
| 99 | **Missing links** → Generate template ToS/PP URLs |
| 100 | |
| 101 | After applying any auto-fix, **re-run the affected checks** to confirm the fix resolved the violation. Only mark as resolved once the re-scan passes. |
| 102 | |
| 103 | For issues requiring manual intervention (screenshots, UI redesign), provide clear instructions but do not auto-fix. |
| 104 | |
| 105 | ## Gotchas |
| 106 | |
| 107 | **China storefront** — Banned AI terms (ChatGPT, Gemini, etc.) are checked across ALL locales, not just `zh-Hans`. Apple checks every locale visible in the China storefront. |
| 108 | **Privacy manifests** — `PrivacyInfo.xcprivacy` is required even if your app doesn't call Required Reason APIs directly. Third-party SDKs (Firebase, Amplitude, etc.) that use `UserDefaults` or `NSFileManager` trigger this requirement transitively. |
| 109 | **asc auth** — `asc metadata pull` requires App Store Connect authentication. Run `asc auth login` first, or set `ASC_KEY_ID`, `ASC_ISSUER_ID`, and one of `ASC_PRIVATE_KEY_PATH` / `ASC_PRIVATE_KEY` / `ASC_PRIVATE_KEY_B64`. If you're unsure what `asc` is picking up, run `asc auth doctor`. |
| 110 | **Subscription metadata** — Apple requires ToS/PP links in BOTH the App Store description AND the in-app subscription purchase screen. Missing either one is a separate rejection. |
| 111 | **macOS entitlements** — Apple will ask you to justify every temporary exception entitlement (`com.apple.security.temporary-exception.*`). Remove entitlements you don't actively use. |
| 112 | |
| 113 | ## Adding New Rules |
| 114 | |
| 115 | Create a `.md` file in the appropriate `references/rules/` subdirectory: |
| 116 | |
| 117 | |
| 118 | # Rule: [Short Title] |
| 119 | - **Guideline**: [Apple Guideline Number] |
| 120 | - **Severity**: REJECTION | WARNING |
| 121 | - **Category**: metadata | subscription | privacy | design | entitlements |
| 122 | |
| 123 | ## What to Check |
| 124 | ## How to Detect |
| 125 | ## Resolution |
| 126 | ## Example Rejection |
| 127 | |
| 128 |
Discussion
Browse more free Claude skills.