Acceptable Use Policy
Draft for review by a lawyer before launch.
You may not publish or do any of the following
- Malware or attacks. Rigs, hooks, scripts, MCP servers or instructions designed to steal credentials or data, damage systems, gain access without permission, mine cryptocurrency without clear disclosure, or run hidden network calls.
- Secrets. Real API keys, tokens, passwords, private keys or connection strings, yours or anyone else's. If you leak one by accident, revoke it first, then publish a new version.
- Instructions meant to make an AI tool act against its user. For example text that tells an agent to hide actions, disable its safety protections, read credentials, exfiltrate files or ignore the user's instructions.
- Impersonation. Presenting a rig as made by another person or company, or using a name to mislead people about who publishes it. Vendor and project names are reserved.
- Illegal content, and content that infringes someone else's rights.
- Personal information about other people.
- Abusing the service. Automated scraping that degrades the service, bypassing rate limits, probing for private rigs, or trying to get around the scan.
What happens if you break the rules
We may hide or remove the content, suspend the account, and where the law requires it, report to the authorities. See the takedown and abuse policy for the process and how to appeal.