Constants Publishing Guidelines

Last updated: August 31, 2026

How to read this

Publishing a Tool, MCP server, App, connector, skill, or template shared outside your own Workspace (“Community Item”) means other people will run your code against their data and their connected accounts. These Guidelines are the minimum bar for doing that responsibly. They are not a review — Constants does not audit Community Items, and listing does not mean approval.

Violating these Guidelines can result in a warning, unranking, removal of the Community Item, or suspension or termination of your account. Section 8 describes how enforcement works and how to appeal.

1. Safety and security

1.1 Community Items must not violate, or facilitate violation of, applicable law.

1.2 Community Items must not evade, disable, or enable users to circumvent Constants' safety systems, model guardrails, system instructions, sandbox boundaries, rate limits, or usage accounting.

1.3 Community Items must not contain or distribute malware, spyware, ransomware, cryptominers, corrupted files, or any code designed to disrupt, damage, or gain unauthorized access to any system, device, network, account, or data.

1.4 Community Items must not probe, scan, or test the vulnerability of any system without authorization, nor attempt to access non-public areas.

1.5 Community Items must not exfiltrate credentials, tokens, secrets, or session data, and must not transmit user data to any destination not disclosed in the Item's description and privacy policy (if applicable).

1.6 Community Items must not infringe or misappropriate anyone's intellectual property, and must not impersonate another person, company, product, or brand or use a name, icon, or description likely to be confused with one.

1.7 Community Items must respect the privacy of third parties. Do not publish or process other people's personal information without a lawful basis and any required consent.

2. Prohibited content and use cases

Community Items must not be, contain, generate, facilitate, promote, or provide access to:

2.1 Advertising vehicles. Constants does not support Community Items that serve advertisements, sponsored content, or paid product placements, or that exist primarily as an advertising, affiliate, lead-generation, or promotional vehicle. Every Community Item must deliver clear, legitimate, standalone functionality. Naming your own product inside a Community Item that genuinely integrates with it is fine; a Community Item whose actual purpose is to drive traffic or installs is not.

2.2 Abuse, harassment, and hateful content. Content or functionality that threatens, harasses, intimidates, degrades, doxxes, stalks, or humiliates any person or group, or that promotes or incites violence, hatred, or discrimination on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, age, or any other protected characteristic.

2.3 Sexual and adult content. Sexually explicit, pornographic, or sexually suggestive content, including generated imagery, video, audio, or text. Any sexual content involving minors, and any content that sexualizes minors, is strictly prohibited and will be reported to the appropriate authorities. Community Items must not be designed to bypass content filters in order to produce adult material.

2.4 Controlled substances. Content or functionality that facilitates the manufacture, synthesis, sourcing, sale, or unlawful acquisition of controlled substances, illegal drugs, drug precursors, or unapproved or counterfeit pharmaceuticals.

2.5 Weapons and violent harm. Content or functionality that provides meaningful assistance toward building, acquiring, or deploying weapons, explosives, or chemical, biological, radiological, or nuclear materials, or that facilitates terrorism or other violent extremism.

2.6 Fraud and deception. Phishing, credential harvesting, spoofed sites or login pages, scams, fake storefronts, payment fraud, fraudulent financial or investment schemes, academic dishonesty services, and disinformation.

2.7 Unlicensed professional practice. Community Items that hold themselves out as providing medical, legal, financial, or other licensed professional advice without appropriate qualification and disclosure.

2.8 Self-harm. Content that encourages, instructs in, or facilitates suicide, self-injury, or disordered eating.

2.9 Spam and platform manipulation. Bulk unsolicited messaging, engagement or metric manipulation, duplicate or near-duplicate listings, keyword-stuffed descriptions, or Community Items published primarily to occupy namespace.

2.10 Anything otherwise prohibited for legal, ethical, or policy reasons, including content that uses ambiguous language where surrounding context makes the intent clear.

Constants may deem a Community Item inappropriate and remove it even if it does not belong to any of the categories above.

3. Sensitive data — prohibited entirely

Community Items must not be designed to process, and must not accept, store, or transmit, any of the following:

  • financial account information, payment card data, or banking credentials
  • health information, including any protected health information subject to HIPAA or equivalent law
  • biometric information
  • government-issued identifiers
  • any other sensitive personal information or special category of personal data as defined under applicable law

This is an absolute bar, not a “handle it carefully” instruction. Constants is not designed to serve as a system of record for this data or to provide regulatory-grade safeguards for it, and no Community Item may hold itself out as suitable for it.

4. Truthful description and compatibility

These rules exist because Community Items describe themselves to an AI model in natural language, and a misleading description causes the model to call the wrong thing at the wrong time.

4.1 Every tool or capability must be described in narrow, unambiguous language stating what it does and when it should be invoked.

4.2 Descriptions must precisely match actual functionality. Do not describe capabilities the Item does not have, and do not include functionality the description does not disclose.

4.3 Descriptions must not be written so as to create confusion or conflict with other Community Items, or to cause other Items to be invoked extraneously.

4.4 Community Items must not induce a model to call other software, tools, databases, or resources that the user did not request, and must not interfere with a model's ability to call other software the user did want.

4.5 Community Items must not instruct a model to pull behavioral instructions dynamically from an external source for execution.

4.6 Community Items must not contain hidden, obfuscated, or encoded instructions. All behavioral guidance must be human-readable and plainly presented.

4.7 Any action that sends data outside Constants or that modifies, creates, or deletes data in an external system must be clearly labeled as such, and must be annotated so that the user is asked to confirm before it runs.

5. Publisher requirements

5.1 Data minimization. Collect only the data from the user's context needed for the Item's stated function. Do not collect conversation content, chat history, memory, uploaded files, or other context beyond that scope — including for logging or debugging purposes.

5.2 Authentication. Where authentication to a remote service is required, use OAuth 2.0 with certificates from a recognized certificate authority. Request the narrowest scopes your Item actually needs. Do not request write or destructive scopes for a read-only Item.

5.3 Secrets hygiene. Any authentication secret configured for your Community Item must be unique to that Item, hard to guess, and rotated at least every 90 days. Never hard-code secrets into published code.

5.4 Contact and support. Provide and keep current a verified contact address and a support channel where users can reach you about product and security concerns.

5.5 Incident notification. Notify Constants at safety@constants.io promptly if your Community Item suffers or may have suffered a security breach that affects users or that could threaten the platform.

5.6 Maintenance. Keep your Community Item working. Address breakage and reported issues within a reasonable timeframe. Unmaintained Items may be unranked or removed.

7. Attribution and provenance

7.1 Every Community Item page displays the publishing account, a notice that the Item is community-created and has not been reviewed by Constants, and a link to report it. This notice is part of the product and may not be removed, hidden, obscured, or misrepresented, on any plan.

7.2 Do not state or imply that your Community Item is created, verified, reviewed, endorsed, sponsored, or approved by Constants, or that you are a partner of Constants, without prior written approval.

7.3 Do not use Constants' name, logo, or trademarks in your Item's name, icon, or branding in a way likely to suggest official status.

8. Enforcement, removal, and appeals

8.1 How to report. Anyone can report a Community Item using the report link on its page or by emailing safety@constants.io.

8.2 How we review. Reports are reviewed by the Constants team, supported by automated detection. We review every report we receive, though we may not respond individually to each one. We prioritize reports involving minors, credible threats of offline harm, and unlawful content.

8.3 What can happen. Depending on severity, we may:

  • ask you to modify the Community Item
  • add a warning label
  • unrank or unlist the Item so it no longer appears in discovery
  • disable or remove the Item
  • restrict your ability to publish
  • suspend or terminate your account

Serious violations — including anything involving minors, malware, credential theft, or unlawful content — result in immediate removal without prior notice.

8.4 Notice to publishers. If we remove your Community Item we will notify you at the email associated with your account, and tell you which Guideline was implicated, except where notice is prohibited by law or would compromise an investigation.

8.5 Notice to installed users. When a Community Item that other users have added or connected is removed, we will use commercially reasonable efforts to notify those users that it is no longer available, and may revoke associated connections and authorizations. Neither Constants nor the publisher is obliged to preserve or migrate any associated data.

8.6 Appeals. If your Community Item was removed or your account restricted and you believe it was a mistake, email safety@constants.io with the Item name and your reasoning. A member of the team will review and respond.

8.7 Abuse of reporting. Submitting reports in bad faith, in bulk, or to harass another publisher may result in loss of reporting access and action against your account.