Creator package pilot

Package rules

A package is one reusable skill version for a named compatible AI tool. The ZIP carries the files; it does not make the skill safe, compatible with every client, or ready to run.

What to include

Current pilot limits

Submit one ZIP for one skill version. The ZIP may be at most 256 KiB, expand to at most 512 KiB, and contain at most 64 files, with each file at most 128 KiB.

SKILL.md format and a minimal example

Use UTF-8 text with flat, unique top-level frontmatter. Each value must be a one-line scalar. The required name is lower-kebab-case, nonempty and at most 64 characters; description is nonempty and at most 1,024 characters. Nested metadata is not supported.

---
name: meeting-notes
description: Turn meeting notes into a short action list.
---
Write the action list in Markdown.

Documentation and support links are optional, and a public GitHub repository is not required. Need help using an AI assistant? Read the client guide.

Source tier (when enabled): readable source, tests and setup files; 256 KiB compressed, 512 KiB expanded, 64 canonical files and 128 KiB per file. Include source-package.json. Checks and independent review never execute or install code, certify safety, or verify creator tests. Antivirus and dependency-vulnerability scanning are not performed. Policy: source-review-v1.

Source declaration example

This synthetic example is a format guide. Replace it with accurate declarations for your tool; do not copy unsupported safety claims.

{
  "schema_version": 1,
  "runtimes": [
    {
      "name": "cloudflare-workers",
      "versions": [
        "2026-09-13"
      ]
    }
  ],
  "dependencies": [],
  "operations": [
    {
      "kind": "read",
      "description": "Read a user-selected synthetic message.",
      "target_restrictions": [
        "Only the user-selected message identifier"
      ]
    }
  ],
  "authorization": {
    "mode": "none",
    "scopes": [],
    "credential_requirements": []
  },
  "network": {
    "domains": [],
    "destinations": []
  },
  "safety": {
    "read_only_by_default": true,
    "dry_run_supported": false,
    "consequential_writes_require_authorization": true,
    "validation_controls": [
      "Validate the message identifier"
    ],
    "target_restrictions": [
      "Only the selected message"
    ]
  },
  "tests": {
    "files": [
      "tests/tool.test.mjs"
    ],
    "fixtures": "synthetic_only",
    "provenance": "creator",
    "evidence": [
      "Creator-authored deterministic unit tests"
    ]
  }
}

The separate documentation tier retains its 64 KiB archive, 128 KiB expanded and 16 canonical-file limits. Source packages require readable Python or JavaScript plus the source declaration file. Binaries, vendored dependencies, installation hooks and private data are excluded.

Rights and review

You must have redistribution rights for every included file and provide the required license notices. Packages and their fields exclude secrets, private prompts, credentials, personal data and real customer data.

Each exact version is stored privately while its applicable checks and independent review are completed. A passing review records what was checked under one policy at that time; it is not a guarantee of safety, compatibility or performance. Changed bytes require a new version and fresh review.

Publish a new version

Each new upload must use a numeric major.minor.patch version greater than every earlier version of the listing, including withdrawn ones. Optional release notes are reviewed with the package and shown to buyers. Releasing a new version supersedes the previous release for new acquisitions; existing Library owners keep what they acquired.

Withdraw a version

Creators can permanently withdraw an exact submission from its Packages page. This stops review and new acquisitions. Existing Library owners retain access unless a moderator safety-blocks the version. Withdrawn versions move to History; their files and review records are retained. Corrected files need a new version number.