All skills
rshankras avatar

/privacy-publish

@1361023

Turn drafted legal docs (privacy policy, terms) into hosted pages and set the App Store Connect Privacy Policy / Support / Marketing URLs via the ASC REST API. Use at Phase 6 / submission, after legal drafts exist. The App Privacy "nutrition label" stays manual (Apple exposes no API) β€” this prints the exact answers to click.

Use this Skill: https://skilld.dev/gh/rshankras/claude-code-apple-skills/privacy-publish

This session only. Nothing lands on disk.

SKILL.md

β‰ˆ86 tokens always: the name and description. β‰ˆ783 when used: this file.

Privacy Publish

Close the "hosted legal pages + ASC URLs" gap: render .planning/legal/{privacy,terms}.md β†’ host them β†’ PATCH the Privacy/Support URLs onto the App Store version. The one thing with no API β€” the App Privacy nutrition label β€” is handed off as a precise checklist.

Depends on the user's web infra, so ask once, remember. Hosting choice is theirs; the ASC URL-setting is the automatable part.

Prerequisites

  • Legal drafts exist: .planning/legal/privacy.md, .planning/legal/terms.md (from legal/privacy-policy).
  • _shared/asc-api/ set up (README).
  • Set ASC="python3 <path to asc.py>" β€” resolve asc.py relative to this SKILL.md file's location (../../_shared/asc-api/asc.py), never the project cwd. Known install locations:
    • SwiftShip symlink install: ~/.claude/swiftship-skills/_shared/asc-api/asc.py
    • Copied install: .claude/skills/_shared/asc-api/asc.py (project) or ~/.claude/skills/_shared/asc-api/asc.py (global)
    • Plugin install: resolve from this file's location β€” the _shared/ tree ships with the plugin.
  • The app has a current editable App Store version + an en-US appInfoLocalization and appStoreVersionLocalization (get their ids first).

Flow β€” dry-run β†’ confirm β†’ apply

  1. Render. Markdown β†’ minimal self-contained HTML (or keep .md if the host renders it).
  2. Publish (pick per the user's infra β€” AskUserQuestion once, then remember in .planning/):
    • git static site β€” commit + push to the pages repo/branch.
    • WordPress β€” POST /wp-json/wp/v2/pages with an application password.
    • Netlify / S3 / other β€” the host's CLI.
    • Browser fallback β€” drive the CMS with claude-in-chrome (detect β†’ preview β†’ confirm β†’ act β†’ fall back, per TOOL-HANDOFF.md).
    • Confirm both URLs resolve (HTTP 200) before touching ASC.
  3. Set the ASC URLs (REST β€” dry-run, confirm, then --apply):
    • Privacy Policy URL β†’ appInfoLocalizations (privacyPolicyUrl):
      $ASC PATCH /v1/appInfoLocalizations/<id> '{"data":{"type":"appInfoLocalizations","id":"<id>","attributes":{"privacyPolicyUrl":"https://…/privacy"}}}' --apply
    • Support / Marketing URL β†’ appStoreVersionLocalizations (supportUrl, marketingUrl) β€” PATCH the current version's en-US localization id.
  4. Nutrition label (manual β€” no API). Emit a checklist matching Sources/PrivacyInfo.xcprivacy (e.g. Data Not Collected, no tracking) for the user to click in ASC β–Έ App Privacy. Do not claim this step is automated.

Done

  • Legal pages live + resolving; Privacy/Support URLs set via API; nutrition-label checklist handed off.

Caveats

  • Verify each endpoint/field against the current ASC API reference before --apply (captured 2026-07).
  • Confirm URLs return 200 before setting them in ASC β€” a dead Privacy URL is a common rejection (Guideline 5.1.1).
  • The nutrition label and some age-rating specifics have no public API β€” those remain ASC-UI/manual by design.

Source: SKILL.md on GitHub

1 warning2mo3 checks Β· Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill automates the publishing of legal documents and updates App Store Connect configuration. It uses shell execution and browser automation to interact with external services. While these capabilities are necessary for the skill's function, they create a surface for indirect prompt injection if the source documents contain malicious instructions.

  • Socket2mo

    1 alert: gptSecurity

  • Snyk2mo

    Risk: LOW Β· No issues

Signed by skilld at 1361023. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 3 months ago
What it can do
Reads files Runs commands
MCP servers
claude-in-chrome
last_verified
2026-07-16
review_by
2027-06-22
All 6 allowed tools
ReadBashAskUserQuestionmcp__claude-in-chrome__navigatemcp__claude-in-chrome__computermcp__claude-in-chrome__read_page

README badge

README badge for rshankras/claude-code-apple-skills/privacy-publish