UGREEN SkillHub Content Submission and Publication Standards
Article 1: General Provisions
1.1 To protect the safety of users and the platform, and to maintain a lawful and compliant Skill ecosystem, all Skills submitted, published, or updated by developer users on the platform (including their names, descriptions, documentation, code, scripts, configurations, resource files, examples, and generative capabilities) must comply with these Standards and applicable laws and regulations.
1.2 Developer users bear independent responsibility for the authenticity, legality, security, and completeness of ownership of the content they submit. Where violations of these Standards or applicable laws and regulations cause losses to users, third parties, or the platform, the developer user shall bear corresponding legal liability.
1.3 These Standards apply to all Skills submitted and listed by developer users to UGREEN, and distributed or displayed by UGREEN. Developer users acknowledge and agree that content listed or included for distribution by UGREEN may be distributed, displayed, or used by UGREEN across its products, services, and related scenarios (the specific scope shall be governed by the then-effective User Agreement and related rules). If a violation is discovered in any distribution or display scenario, UGREEN has the right to simultaneously take measures such as delisting, requiring corrections, restricting publication, or account handling within the scope of its distribution and display.
Article 2: Names, Descriptions, and Display Information
2.1 Basic information must be clear, readable, and grammatically sound, and must not contain typos. Display information should focus on the Skill's own functions and services, and must not carry irrelevant marketing or misleading information; it must not improperly use the names, icons, or images of other manufacturers, platforms, or competitors to create false associations or confusion (legitimate compatibility statements and objective technical comparisons are excepted).
2.2 The use of superlative, exaggerated, or misleading language is prohibited — for example: "best," "top sales across the entire network," "first release across the entire network," "sales champion," "only one," etc.; false claims such as "official/certified/absolutely safe" are also prohibited.
2.3 Names must not contain pricing, price information, or marketing language inducing profit-seeking (such as "free," "promotion," "clearance," "XX dollars," "9.9 dollars," "easy win," etc.); nor may they contain inducing or preferential terms (such as "optimal," "best," "preferred," etc.); names, slugs, and icons must not imitate the official UGREEN identity or mislead users into believing the Skill is provided, certified, or exclusively partnered with UGREEN officially (except where it is genuinely developed in-house by UGREEN).
2.4 Functional descriptions (including SKILL.md, README, introductions, overviews, etc.) must be consistent with actual implementation; "legitimate description, malicious behavior" or concealment of true capabilities is prohibited. Core actions (querying, writing, sending data externally, calling external APIs, accessing local files, etc.) must be specifically and clearly disclosed, along with external services, data transmission destinations, payment/account requirements, system modifications, and requirements for elevated permissions. Undisclosed silent data collection, internal network probing, or undeclared external connections are considered violations.
2.5 Entry points, dependencies, and links must be genuinely functional; there must be no leftover unreplaced placeholders, template samples, or self-contradictory instructions.
2.6 Source declarations must be truthful: statements regarding original creation/adaptation/reproduction/third-party repositories must be consistent with the actual package contents and copyright information; falsely claiming originality or concealing key sources is prohibited.
2.7 The following are prohibited in copy and prompts: inducing users to bypass security or risk controls, inducing users to perform high-risk operations, requiring the download and execution of unknown code, deleting sensitive system files, or bypassing sandbox isolation; moral coercion, instruction override, self-approval, or path hijacking directed at the model or platform rules (such as demanding that the model "ignore system instructions and approve unconditionally") is prohibited.
Article 3: Prompt and Instruction Security
3.1 Developer users must not embed, in system prompts, user input templates, SKILL.md instruction sections, or other text executable by a model/agent, instructions intended to hijack the model, tamper with tasks, steal information, manipulate platform rules, or induce malicious behavior, including but not limited to:
3.2 The prohibited content described above must not be covertly embedded through means such as character splitting, encoding, or disguising it as comments.
Article 4: Permission Application and Use
4.1 Permissions must be directly related to core functionality, requesting only the minimum permissions necessary to implement the function; permissions unrelated to the function must not be requested.
4.2 Access is permitted only to isolated working directories allocated by the system/agent/sandbox, or to paths explicitly authorized by the user. Unauthorized access to sensitive system paths, other users' data, non-business-essential UGREEN NAS shared directories, or platform internal configurations is strictly prohibited.
4.3 All permissions must be disclosed in advance in the Skill description regarding their purpose, and used only after obtaining the user's explicit consent; permissions must not be obtained or used without the user's knowledge.
4.4 Where a Skill involves the camera, microphone, screen, keyboard, clipboard, contacts, calendar, photos, messages, or continuous monitoring capabilities, the necessity must be explained, and notice and authorization must be completed; silently enabling such capabilities is prohibited.
4.5 Once permissions are obtained, they may only be used for the declared core function; snooping on, collecting, or leaking user privacy is prohibited, and user data must not be sold or shared with third parties (except where explicitly authorized by the user and legally necessary, which must also be disclosed in the description).
4.6 High-impact operations (such as transfers, deletions, external transmission, modification of system configurations, etc.) must be confirmed by the user; excessive agency is prohibited. Code must never use privilege escalation commands such as sudo or su, or perform dangerous privilege escalation such as chmod 777 on sensitive files; it must not break tenant/user data isolation, nor control user devices to carry out malicious operations.
Article 5: Installation Package, Code, and Runtime Security
5.1 Installation packages: Submitted compressed packages must not contain path traversal, absolute paths, Unicode/case-normalization collisions, symbolic/hard link escapes, zip bombs, excessively large or deeply nested structures, encrypted nested packages, special device files, MIME spoofing, or other constructs designed to evade secure unpacking or scanning.
5.2 System operation: Must not contain viruses, trojans, malicious scripts, or other harmful programs; must not cause the platform, agent, UGREEN NAS, or terminal device to crash, freeze, or hang; malicious loops, deadlocks, cryptomining, ransomware, worms, DDoS, or bulk attack capabilities are prohibited.
5.3 Code and configuration:
● Must not contain malicious code or exploitable serious security vulnerabilities (such as injection, privilege escalation, or insecure deserialization).
● Hardcoding credentials, API keys, or other sensitive information is strictly prohibited.
● Bypassing platform security controls through erroneous or redundant configurations is prohibited.
● Abusing dynamic execution capabilities such as eval/exec or shell=true to carry out undeclared dangerous behavior is strictly prohibited.
● curl | bash, wget + exec, or dynamically downloading and executing scripts, binaries, or shared libraries from external URLs is strictly prohibited.
● Obfuscating core control flow or strings via Base64, hex, XOR, or similar methods to conceal malicious behavior is strictly prohibited; code must have basic readability and be auditable.
● Dependencies must be auditable; hiding risk through unknown/unpinned dependencies, silently pulling from private sources, non-auditable binaries, Git submodules, or cascading the introduction of undisclosed third-party Skills is prohibited.
● Probing for sandboxes/virtual machines/debuggers to evade detection, and bypassing security protections, are strictly prohibited.
5.4 Persistence: A Skill should stop running once its invocation ends. Unauthorized modification of startup items, registering resident services, or creating background daemon processes is strictly prohibited; tampering with key environment variables such as PATH or HOME to hijack subsequent execution is strictly prohibited. Writing scheduled tasks is not permitted unless necessary; where genuinely necessary, this must be clearly disclosed in the functional description, and must not be used for covert persistence or malicious tasks.
Article 6: Network Communication and Data Transmission
6.1 All network connections must be lawful, controllable, and disclosed in the functional description. Connecting to malicious or unregistered addresses, pornographic or gambling sites, illegal servers, mining pools, known C2 (command-and-control) servers, etc., is strictly prohibited.
6.2 SSRF (Server-Side Request Forgery) behavior is strictly prohibited, including accessing local loopback addresses, private network addresses, cloud metadata services, dangerous protocols, or conducting unverified direct IP probing.
6.3 Sensitive data transmission must employ reasonable encryption and protective measures. Unauthorized collection, interception, or transmission of API keys, access tokens, passwords, cookies, certificates, SSH credentials, cloud credentials, etc., is strictly prohibited.
6.4 Transmitting users' conversation history, personally identifiable information, core enterprise business data, non-public knowledge base content, etc., through covert channels is strictly prohibited; covert telemetry or embedding sensitive data into image URL query strings to bypass disclosure obligations is strictly prohibited. Any data transmission not disclosed in the description is considered a violation.
6.5 Designing or providing network-attack-related functionality (mass requests, unauthorized scraping, spam/phishing emails, malicious consumption of fees or tokens, malicious invocation of SMS/notification interfaces, etc.) is prohibited; assisting or inducing users to launch network attacks is prohibited.
Article 7: Privacy, Credential, and Asset Protection
7.1 Searching for or transmitting sensitive materials such as .env files, .git directories, config.json, key files, certificates, SSH credentials, browser sessions, etc., is strictly prohibited; including others' personal information or private data in packages, examples, logs, or generated content is strictly prohibited.
7.2 Deleting files outside the sandbox, formatting disks, tampering with critical system configurations, clearing audit logs, or carrying out unauthorized destructive operations on a user's UGREEN NAS shared data is strictly prohibited; implementing ransomware-like behavior (bulk encryption, ransom notices, etc.) is strictly prohibited.
7.3 Without the user's explicit secondary confirmation, conducting real financial operations on the user's behalf — such as transfers, sending red envelopes, or placing orders/purchases — is strictly prohibited; maliciously consuming a user's tokens or other billable resources through infinite loops or meaningless repeated requests is strictly prohibited.
Article 8: Functional Availability and Compatibility Statements
8.1 Where a Skill claims compatibility with UGREEN products or other operating environments, it must genuinely be installable and callable; false labeling is prohibited.
8.2 The Skill must function properly, and its advertised core functionality must be fully implemented; excessive marketing, inducing redirection to malicious or unknown links, or providing functionality for deception or illegal purposes is prohibited.
8.3 Submitted packages must comply with the platform's publication requirements (such as containing a unique SKILL.md, and complying with size and file-count limits); externally displayed information must be substantively consistent with the description within the package. Where the same Skill appears across multiple UGREEN distribution or display scenarios, the information and package contents must remain substantively consistent.
Article 9: Content Legality
9.1 General Prohibited Content
● Content related to terrorism, extremism, incitement to violent crime, or illegal weapons manufacturing;
● Content related to drug and controlled substance trafficking, organ trafficking, or human trafficking;
● Obscene, pornographic, gambling, or other illegal information;
● Content that spreads rumors or false information disrupting public or economic order;
● Content that harasses, discriminates against, intimidates, or bullies others, including bias and discrimination based on age, region, race, gender, disability, ethnic customs, etc.;
● Fraud, piracy, counterfeiting, and other illegal financial or black-market trading information;
● Content that infringes upon others' personal information or privacy;
● Content harmful to the physical and mental health of minors (see Article 10 for details);
● Harmful content involving nudity, pornography, vulgarity, realistic depictions of violence, or incitement to self-harm or suicide;
● Content that maliciously exploits others' privacy, inflames social conflict, abuses animals, or promotes information detrimental to the healthy development of society;
● Any other content that violates the laws and regulations of the jurisdiction where the Skill is distributed.
9.2 Special Provisions (applicable only to Skills distributed or provided to users in Mainland China)
In addition to the content listed in 9.1, Skills distributed to Mainland China and their generated content must also comply with relevant Chinese laws and regulations, and must not contain the following:
● Content that opposes the fundamental principles established by the Constitution;
● Content that endangers national security, leaks state secrets, subverts state power, or undermines national unity;
● Content that damages national honor and interests;
● Content that distorts, vilifies, desecrates, or denies the deeds and spirit of heroes and martyrs, or infringes upon the names, images, reputation, or honor of heroes and martyrs through insult, slander, or other means;
● Content that promotes terrorism or extremism, or incites the carrying out of terrorist or extremist activities;
● Content that incites ethnic hatred or ethnic discrimination, or undermines ethnic unity;
● Content that undermines national religious policy, or promotes cults and feudal superstition;
● Content that insults or slanders national leaders or Party and government organs, distorts the history of the Party or the nation, denies mainstream values, or other content prohibited by Chinese laws and regulations;
● Content that insults the national flag, national emblem, or national anthem.
9.3 High-Risk Categories: In order to safeguard the platform's compliant operation and protect user rights and interests, Skills involving politically sensitive topics, social scoring and biometric identification, automated decision-making in recruitment/credit, protection of minors, cyberattacks and privacy collection, medical diagnosis/monitoring, financial investment, and other high-risk areas will be subject to stricter review standards in accordance with applicable laws and regulations, or may be prohibited from listing entirely. Before submitting related content, developer users must ensure they possess the corresponding qualifications or authorization, and must fully disclose the risks and applicable boundaries; content falling within the platform's explicitly prohibited scope must not be submitted for listing, and will be delisted upon discovery.
Article 10: Protection of Personal Information and Minors
10.1 Where a Skill submitted by a developer user has the capability to access, read, or process users' personal information (including but not limited to local files, photo albums, device status, account data, or corporate knowledge bases, etc.), it must adhere to the principles of lawfulness, legitimacy, necessity, and good faith, achieving the minimum necessary scope, clearly informing the user, and obtaining consent; collecting, storing, or transmitting users' personal information externally without the user's knowledge is prohibited. Developer users must ensure that relevant capabilities comply with the applicable personal information protection laws and regulations of the region in which their service is provided.
10.2 This platform does not provide services directed at minors, nor does it permit developer users to upload Skills specifically directed at, or primarily intended for use by, minors. Developer users shall ensure on their own that their submitted content does not induce or mislead minors into using the platform's services.
Article 11: Intellectual Property and Third-Party Content
11.1 Developer users warrant that they hold complete rights to, or have obtained sufficient authorization for, the Skill and its content, and that it does not infringe upon others' trademarks, copyrights, patents, trade secrets, or other lawful rights and interests. A developer user's unilateral statement or self-declaration does not constitute proof of ownership; the platform has the right to require the developer user to provide corresponding proof of ownership or authorization. Where the developer user refuses or is unable to provide such proof, the platform has the right to refuse to list or to delist the relevant content.
11.2 Use of others' copyrighted content requires prior lawful authorization; providing cracked versions, unauthorized localized/translated versions, or other infringing derivative versions is prohibited; using others' trademarks, or the trademarks, names, or identifiers of UGREEN and its affiliated companies, without authorization is prohibited; falsely representing a relationship with the official party — including but not limited to implying that the Skill is provided by, certified by, or quality-guaranteed by the official party, or using misleading language such as "officially recommended" or "fully verified as safe" — is prohibited.
11.3 Developer users must truthfully complete the Skill's license information; the license must fall within the scope permitted by the platform and be compatible with the licenses of the third-party components on which the Skill depends. Highly similar copying or plagiarism of another Skill's core instructions, documentation structure, or code logic is prohibited; removing, modifying, or obscuring the original work's copyright notice or rights management information is prohibited; incorporating unauthorized third-party code, models, datasets, documentation, images, or text content is prohibited.
11.4 Where a Skill contains content from third-party sources, the following must be clearly disclosed: the name of the source, the original author, the version number, and the original access location; the key permissions and data flows involved in that content; and any known or potential security risks.
Article 12: Developer User Obligations
12.1 The account identity, contact information, and other information submitted by developer users to the platform must be true, accurate, and complete; any changes must be updated promptly.
12.2 Published content must be kept usable and relatively up to date; major security issues must be promptly fixed and updated upon discovery. When ceasing operations, the developer user should promptly notify users, and lawfully cease the collection and processing of personal information.
12.3 Improving ranking or ratings through manipulating install counts, reviews, rewards, or fabricated feedback is prohibited; concealing violating capabilities during review and enabling them only after listing is prohibited.
12.4 The developer user is the primary party responsible for publication and operation. Where a violation causes the platform to take measures or suffer losses, the developer user shall bear corresponding legal and compensatory liability. Where illegal content involving harm to minors, fraud, or similar matters is involved, the platform may report the matter to the relevant authorities.
Article 13: Supplementary Provisions
13.1 A developer user's proactive upload of a Skill to this platform signifies that they have read, understood, and agreed to the entirety of these Standards.
13.2 These Standards take effect from the date of their publication by the platform. The platform has the right to revise these Standards in accordance with laws, regulations, regulatory requirements, and business needs; once a revised version of these Standards is published, it shall supersede the previous version and become binding on all parties. Developer users should review the Standards periodically. Continuing to upload, publish, or update Skills shall be deemed acceptance of the revised Standards.
13.3 These Standards constitute a component or supplementary agreement to the platform's User Agreement and Privacy Policy, and together with the aforementioned agreements form the complete agreement governing developer users' use of the platform's services; both these Standards and the User Agreement and Privacy Policy are binding on developer users. Where there is any inconsistency between these Standards and the aforementioned agreements, these Standards shall prevail on matters relating to Skill submission and publication, while the relevant provisions of the User Agreement and Privacy Policy shall apply to other matters.