Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Metadata Accuracy

ASecurity

Detects mismatches between features claimed in App Store metadata and features actually implemented in the codebase, enforcing Guideline 2.3.1 which prohibits misleading app descriptions.

18 stars
0 votes
0 copies
1 views
Added 9/20/2026
developmentgoswiftbashreactperformance

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add cruisediary/apple-app-review-skills --skill metadata-accuracy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Metadata Accuracy?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Metadata Accuracy
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cruisediary-metadata-accuracy/badge)](https://www.skillsdirectory.com/skills/cruisediary-metadata-accuracy)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: metadata-accuracy
description: >-
  Detects mismatches between features claimed in App Store metadata and features actually implemented in the codebase, enforcing Guideline 2.3.1 which prohibits misleading app descriptions.
---

# Skill: Metadata Accuracy
<!-- SEO: misleading description AR ARKit AI ML features not implemented Android coming soon Guideline 2.3.1 iOS App Store rejection -->

## Purpose
Detects mismatches between features claimed in App Store metadata descriptions and features actually implemented in the codebase, enforcing Guideline 2.3.1 which prohibits misleading app descriptions.

## Apple Guideline
- **Primary:** 2.3.1 — Performance: Accurate Metadata — App Descriptions
- **Related:** 2.3.10
- **Reference:** `references/guidelines/2-performance.md`

## Real-World Rejection Cases
- **Case:** App description mentioned "AR features" but app had no ARKit code — rejected for misleading metadata
  **Source:** Apple Developer Forums (Guideline 2.3.1 enforcement)
  **Root cause:** App description must accurately represent actual features in the submitted build — reviewers test claimed features and will reject if they cannot find them

- **Case:** App description referenced Android-only features — rejected under 2.3.10
  **Source:** mobiloud.com/blog/avoid-app-rejected-apple
  **Root cause:** Metadata must focus on Apple platform experience only — references to other platforms mislead App Store users and violate platform-specific metadata requirements

- **Case:** React Native cross-platform app displayed Android package name strings (e.g., `com.android.vending`, "Get it on Google Play") inside the onboarding flow — reviewer saw Android-specific UI text on an iOS device — rejected under 2.3.10
  **Source:** Apple Developer Forums (multiple cross-platform developer reports)
  **Root cause:** Cross-platform apps built with React Native, Flutter, or Capacitor sometimes include Android-specific strings, icons, or navigation patterns that surface in the iOS build — reviewers flag any visible Android platform references inside the running app, not just in the App Store description

## Trigger
Invoke on any iOS/macOS project before App Store submission to verify metadata accurately reflects the app's implemented features.

## Inputs
| Name | Type | Default | Description |
|------|------|---------|-------------|
| `project_root` | path | cwd | iOS/macOS project root |
| `shared_context` | object | nil | Pre-collected context from appstore-full-audit Phase 1 |

## Actions

### Phase 1: Context Collection
*Skip this phase if `shared_context` is provided.*

1. `Glob` `**/fastlane/metadata/**` or `**/metadata/**` — locate metadata/description files.
2. `Glob` `**/*.txt` in metadata directories — locate description text files.
3. `Glob` `**/*.swift` — collect Swift source files for feature cross-reference.

### Phase 2: Checks

1. **Android/cross-platform references**
   `Grep` pattern `"Android"|"Google Play"|"Play Store"|"on Android"|"Android version"` in metadata/description text files.
   Any match → 🟠 HIGH. App Store metadata must not reference competing platforms.

2. **Coming soon / planned features**
   `Grep` pattern `"coming soon"|"future update"|"planned feature"|"will be added"|"in a future release"|"soon available"` in metadata/description text files.
   Any match → 🟠 HIGH. Descriptions must only reflect features present in the submitted build — describing future features may cause rejection.

3. **AR feature claim vs ARKit presence**
   `Grep` pattern `"AR"|"augmented reality"|"ARKit"` in metadata/description text files.
   If found, `Grep` `ARKit|RealityKit|ARSCNView|ARSession` in `**/*.swift` — if absent → 🟠 HIGH. Claimed AR features must be implemented in the build being submitted.

4. **AI/ML feature claim vs CoreML presence**
   `Grep` pattern `"AI"|"artificial intelligence"|"machine learning"|"ML model"|"on-device AI"` in metadata/description text files.
   If found, `Grep` `CoreML|CreateML|MLModel|NaturalLanguage|Vision` in `**/*.swift` — if absent → 🟠 HIGH. Claimed AI/ML features must be implemented in the build being submitted.

5. **Android platform strings visible inside app**
   `Grep` pattern `"com\.android"|"google\.play"|"Get it on Google Play"|"Android"|"Play Store"` in `**/*.swift` and `**/*.strings`.
   Any match in a UI string, label, or localizable string → 🟠 HIGH. Android platform references visible inside the iOS app are flagged by reviewers under 2.3.10 — common in cross-platform codebases where Android strings leak into the shared bundle.

### Phase 3: Output
Collect all findings from Phase 2 and build the prioritised findings list below. Include file paths and line numbers. Omit tiers with no findings.

## Output Format

```
## Metadata Accuracy — Findings

### 🔴 CRITICAL — Guaranteed rejection
- [ ] TODO: <exact actionable step> — `file:line` — Guideline 2.3.1

### 🟠 HIGH — Very likely rejection
- [ ] TODO: Remove "Android" reference from App Store description — `fastlane/metadata/en-US/description.txt:8` — Guideline 2.3.10
- [ ] TODO: Remove Android platform string "Get it on Google Play" from in-app onboarding UI — visible to iOS reviewer — `OnboardingStrings.strings:14` — Guideline 2.3.10
- [ ] TODO: Remove "coming soon" feature claims from description — only describe features in the current build — `fastlane/metadata/en-US/description.txt:22` — Guideline 2.3.1
- [ ] TODO: Remove AR feature claim or implement ARKit — description mentions "AR experience" but no ARKit code found in codebase — Guideline 2.3.1
- [ ] TODO: Remove AI/ML claim or implement CoreML — description mentions "AI-powered" but no CoreML/CreateML usage found — Guideline 2.3.1

### 🟡 MEDIUM — Possible rejection
- [ ] TODO: Manually review all description bullet points against actual app features — verify each claimed capability is accessible to the reviewer

### 🟢 LOW — Best practice
- [ ] TODO: Keep a feature parity checklist — update description only after features ship; maintain a staging description for upcoming features outside of App Store Connect
```

## Tools Used
`Glob`, `Grep`, `Read`

## Constraints
- Read-only. No file edits.
- No network calls.
- Skip Phase 1 if `shared_context` is provided by orchestrating agent.
- Works on Swift, Objective-C, React Native, Flutter projects.

## Quick Commands

Run these in your project root to check manually:

```bash
# Check for Android references in metadata
!grep -rn "Android\|Google Play\|Play Store" . --include="*.swift" --include="*.strings" --include="*.md"

# Check for ARKit usage (if AR mentioned in description)
!grep -rn "ARKit\|RealityKit\|ARSCNView\|ARFrame" . --include="*.swift" | wc -l

# Check for CoreML usage (if AI/ML mentioned)
!grep -rn "CoreML\|MLModel\|VNCoreMLRequest\|CreateML" . --include="*.swift" | wc -l

# Check for "coming soon" in strings
!grep -rn "coming soon\|future update\|planned feature" . --include="*.swift" --include="*.strings" -i
```

## Swift Anti-Pattern Reference
`examples/swift/QualityPatterns.swift`

## Detection Steps

1. **Find target files**
   - Glob: `**/fastlane/metadata/`, `**/Info.plist`

2. **Search for rejection patterns**
   - Read `fastlane/metadata/en-US/description.txt` — extract feature claims
   - Cross-reference claimed features against actual Swift implementation (grep feature keywords)
   - Read `fastlane/metadata/en-US/keywords.txt` — check for competitor brand names
   - Check `fastlane/metadata/en-US/support_url.txt` — **runtime check**: verify URL resolves (HTTP 200); flag if file is missing

3. **Determine verdict**
   - Feature described in metadata but no matching Swift code found → 🟠 HIGH (Guideline 2.3.1 — accurate marketing, all advertised features must be present)
   - Competitor brand name in keywords → 🟠 HIGH (Guideline 2.3.7 — accurate keywords)
   - Support URL missing or unreachable → 🟠 HIGH (Guideline 1.5 — support contact / 2.1 — accurate metadata)
   - All described features implemented, support URL reachable → 🟢 pass

4. **Report**
   - Feature claims with no matching code
   - Keywords containing competitor names
   - Fix: Remove unimplemented feature claims from description; remove competitor names from keywords; ensure support URL returns HTTP 200

Attribution

cruisediarycruisediary
View sourceMore from cruisediary →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

284972 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2192 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10311 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →