Acceptable use policy
What you may not put into CoreSkill, what you may not do to it, how much of it you may use, and what happens when a rule is broken. This policy forms part of the Terms of service.
Effective 22/9/2026
No lawyer has reviewed this text
The rules below are written to be workable and to match how the system behaves. They have not been reviewed by a lawyer. Before Core Skill enforces them against a paying customer, above all the parts about suspension, a qualified person should read them.
This policy applies to everyone who uses CoreSkill: the organization that runs a business, every person invited into it, and every AI assistant connected with a key. It forms part of the Terms of service, so breaking it breaks the agreement.
The one rule behind all the others
Use CoreSkill to distribute your own working instructions to your own people. Everything forbidden below is a variation on using it for somebody else's data, somebody else's machine, or somebody else's harm. If a situation is not listed and you are unsure, write to [email protected] and ask before you do it.
Content you must not put into a skill or a file
- Anything unlawful under the law of Core Skill, or under the law of the place where your people will act on it.
- Content that infringes copyright, trademark, trade secret or any other right of a third party. Uploading a competitor's internal manual is the clearest example.
- Malware, exploit code, or instructions whose purpose is to break into a system that you are not authorized to test.
- Instructions designed to make an AI assistant deceive, defraud, or manipulate a person, including generating fake reviews, fake identities or fake official documents.
- Content that harasses, defames or incites violence or hatred against a person or a group.
- Sexual content involving minors, in any form and for any stated reason. There is no context in which this is acceptable, and it will be reported to the authorities.
- Sensitive personal data, meaning health, biometric, political, religious or financial data about identifiable people, unless you have a lawful basis and have accepted the Data processing addendum.
Things you must not do to the system
- Attempt to reach a business, a department, a server or a skill that you were not given access to, whether through the interface, through the API or by guessing identifiers.
- Attempt to use a key that is not yours, or to derive a valid key from one you have.
- Circumvent a rate limit, a quota or a suspension, including by rotating IP addresses or creating extra accounts for the purpose.
- Probe, scan or attack the service, its infrastructure, or another customer, except within the terms of the security research section below.
- Interfere with logging. The MCP log is how an organization sees who read which skill. Trying to suppress, forge or flood it is treated as a serious breach.
- Reverse engineer, decompile or copy the software, except to the extent the law expressly permits regardless of contract.
- Resell, sublicense or provide the service to third parties as if it were your own, without a written agreement with Core Skill.
- Use the service to build a competing product, or to benchmark it for publication, without written permission.
Keys, and what people do with them
- One key, one person, one machine. A shared key makes the log say something untrue about who did what, which destroys the main reason the log exists.
- Do not issue a key on somebody else's behalf and keep it. Every call it makes will carry that person's name. This is why the system refuses to let an Admin issue keys for an Owner or for another Admin.
- Do not publish a key, in a repository, in a ticket, in a chat channel, or in a screenshot. Treat a leaked key exactly as you would a leaked password: revoke first, investigate second.
- Revoke the keys of anyone who leaves. A key outlives an employment contract unless somebody ends it.
- Do not use a key after your access has been withdrawn, even if the key still technically works for a few seconds longer.
Fair use of resources
The system enforces the following limits. They are generous for normal work and exist to stop one customer degrading the service for everyone. If your legitimate use needs more, ask at [email protected] rather than working around them.
| Limit | Value | Why it exists |
|---|---|---|
| Skills per server | 50 | Keeps a skill list readable by an AI assistant in a single call. |
| Size of one uploaded file | 2 MB, and 20 MB in total per skill | A skill is an instruction, not a media library. Large files slow every call that reads them. |
| Active staff keys per person | 5 | One key per machine is enough. More than that usually means keys are being shared. |
| Service keys per server | 200, and 20 per bulk issue | Protects against scripted key creation that would flood the list. |
| MCP calls per IP address | 600 per minute | Blunts key guessing and stops one client saturating the endpoint for other customers. |
Automated access
Connecting an AI assistant is exactly what the service is for, and so is a script that reads skills to do your own work. What is not acceptable is systematically downloading the whole skill catalogue in order to store it elsewhere, to resell it, or to feed it into a product of your own. The boundary is purpose, not speed: read what your work needs, not everything you can reach.
Security research
- Testing is welcome against your own business, with your own accounts and your own keys.
- Do not test against another customer's data, and stop the moment you reach data that is not yours.
- No denial of service testing, no load testing, and no automated scanning that generates significant traffic.
- Do not exfiltrate, modify or delete data to prove a finding. A screenshot of the boundary you crossed is proof enough.
- Report first, publish later. Give Core Skill a reasonable window to fix the issue before making it public.
Reporting a vulnerability
Send findings to [email protected] with enough detail to reproduce the issue. Core Skill will acknowledge within a few working days, keep you informed, and will not pursue legal action against a researcher who follows the rules above in good faith.
What happens when a rule is broken
- A warning to the Owner, with what was found and what needs to change. Most cases end here, because most breaches are accidents.
- Removal of the offending content, or revocation of the keys involved, where the breach is ongoing.
- Suspension of the business or the account. This cuts off all three kinds of MCP key at once, so every connected AI assistant stops receiving skills immediately.
- Termination, and where the law requires it, a report to the competent authority. Core Skill will state the reason unless the law or an active investigation prevents it.
Core Skill will normally work through these steps in order. Where the breach involves an immediate risk to other customers, to the security of the service, or to a person's safety, it may go straight to suspension and explain afterwards.
Reporting abuse
If you believe someone is using CoreSkill in breach of this policy, write to [email protected] with as much detail as you can give: what you saw, where, and when. Reports about personal data go to [email protected] instead. Reports are treated confidentially, and you will be told the outcome where it is lawful to do so.
Changes and contact
This policy may change as new kinds of misuse appear. The current version is always the one on this page. Questions go to [email protected], or by post to Core Skill, coreskill.app. This policy is governed by the law of Core Skill and takes effect on 22/9/2026.
