Version: v1 · Effective: 2026-06-08 These terms apply to anyone who publishes an Ability to the apps.lloyal.ai distribution channel via lloyal publish or the underlying API. Registering a publisher handle and submitting a tarball constitutes acceptance.
Who this applies to
If you've run lloyal publishers register and claimed a handle, you are a publisher under these terms. Each subsequent submission is made under the handle you registered.
You retain ownership of the code in your Ability. These terms govern only the distribution relationship: what you grant Lloyal Labs to do with your tarball, what Lloyal Labs commits to do in return, and the rules your submissions must meet.
What you grant Lloyal Labs
By submitting a tarball through lloyal publish, you grant Lloyal Labs a non-exclusive, worldwide, royalty-free license to:
- Inspect the tarball during review — including extracting and reading
package.json, the bundled source, the manifest, and theability.jsonmetadata. - Sign the approved tarball bytes with the Lloyal platform Ed25519 key, producing a manifest carrying that signature.
- Distribute the signed tarball + manifest + catalog entry via the
apps.lloyal.aichannel and any successor channel under the same trust roots. - Cache and serve the signed tarball through Cloudflare R2 and any CDN layer in front of it.
- Display your handle and the catalog name publicly in the catalog and in any portal Lloyal Labs operates over the channel.
The signature is over the exact bytes you submitted; Lloyal Labs does not modify your tarball before signing. If a revision is needed, you submit a new version under a new semver.
What Lloyal Labs commits to
- Review every submission before it enters the catalog.
- Communicate review outcomes — approval includes the canonical tarball URL; rejection includes a written reason.
- Preserve rejected submission artifacts for 30 days so you can appeal or resubmit a corrected version.
- Not modify your tarball bytes. Approved bytes are exactly the submitted bytes.
- Maintain the catalog signature so consumers verifying against
CHANNEL_TRUST_ROOTScan rely on its integrity. - Honor reasonable rate limits (currently 10 publishes per 24h per publisher identity).
Your obligations
You agree that your submissions:
- Will not contain malicious code. This includes (non-exhaustively): credential-stealing logic, unauthorized network beacons, cryptocurrency miners, persistence mechanisms outside the harness's stated scope, or code that violates the Ability Protocol.
- Will not scrape or transmit personal data of harness end-users without their explicit informed consent.
- Will not impersonate another publisher, person, or organization.
- Will respect third-party rights. You are responsible for ensuring the tarball's contents — including transitive dependencies — comply with the licenses of any code you include.
- Will conform to the Ability Protocol for the protocol version declared in your
ability.json. - Will use a
package.jsonname that you control and that matches theimportNamefield declared in your manifest stub.
Rejection reasons
Lloyal Labs may reject a submission for any of:
- Failure to meet any obligation in the previous section.
- Tool surface overlap with existing approved abilities that creates significant consumer confusion.
- Manifest claims that don't match the tarball contents.
- Insufficient documentation for a reviewer to assess the Ability's behavior.
A rejection is per-submission; you may resubmit a corrected tarball under the same or a new version.
Revocation
Lloyal Labs may revoke a published Ability from the catalog for:
- A subsequent finding that the Ability violates these terms.
- A credible security report about the Ability's behavior.
- A legal order requiring removal.
- A request from the publisher to delist a version.
Revocation removes the catalog entry and the canonical R2 paths. Consumers who previously installed the Ability retain their local copy — the tarball bytes on their disk are not modified.
Suspension
Lloyal Labs may suspend a publisher account — preventing further submissions, without removing previously approved abilities — for:
- Repeated submission of abilities that violate these terms.
- Abuse of the review pipeline (e.g., spam submissions to exhaust reviewer capacity).
- Behavior that misrepresents Lloyal Labs or another publisher.
Suspended publishers may appeal by emailing [email protected].
Reserved handles
The handle lloyal is reserved for Lloyal Labs. All other handles are first-come-first-served, subject to good-faith use. Lloyal Labs reserves the right to reclaim a handle that is registered in bad faith (impersonation, squatting, abandoned squatting).
ToS revisions
This document is versioned (v1, v2, …). Each version is identified by the tosVersion field in your publisher record. When Lloyal Labs revises the ToS in a way that materially changes publisher obligations, the version increments and your existing registration's tosVersion becomes stale. The publish CLI will refuse to submit until you re-attest by running lloyal publishers register again.
Editorial or clarifying changes that don't change publisher obligations keep the same tosVersion.
Disclaimer
THE apps.lloyal.ai CHANNEL AND THE REVIEW PIPELINE ARE PROVIDED "AS IS". Lloyal Labs makes no warranty that any specific submission will be approved, that reviews will complete within a specific timeframe, or that the channel will be available continuously. To the extent permitted by law, Lloyal Labs disclaims all warranties — express, implied, statutory, or otherwise.
Nothing in these terms limits Lloyal Labs's review discretion. Approval is at Lloyal Labs's sole judgment based on the criteria documented here.
Liability
To the maximum extent permitted by law, Lloyal Labs's aggregate liability arising out of or relating to these terms or the channel is limited to the fees you paid Lloyal Labs in the 12 months preceding the claim. The channel is currently free; that limit is therefore zero.
Governing law
These terms are governed by the laws of New South Wales, Australia. Disputes will be resolved in the courts of New South Wales unless an alternative forum is required by applicable consumer-protection law in your jurisdiction.
Contact
For questions about these terms or to report a suspected violation by another publisher, email [email protected].