Skip to main content
rulesSource-backed

Commercial Content Routing Rules

Source-backed rules for AI workflow directories that need to classify commercial, sponsored, affiliate, vendor-authored, and thin promotional submissions before they enter the ordinary editorial content queue.

by MkDev11·added 2026-06-04·
Review first review before installing

Open the source and read safety notes before installing.

Citation facts

Source-backed facts for citing this resource, derived directly from the registry — also available as plain text for AI assistants.

Source URLs
https://developers.google.com/search/docs/essentials/spam-policies, https://github.com/JSONbored/awesome-claude/blob/main/content/rules/commercial-content-routing-rules.mdx
Safety notes
Commercial routing is an editorial control, not a legal compliance guarantee; escalate uncertain sponsorship, endorsement, or advertising questions to the maintainer or counsel., Do not let generated copy invent rankings, endorsements, security claims, customer counts, pricing promises, or benchmark results., Treat paid placement, affiliate links, vendor claims, and product submissions as higher-review-risk even when the linked product is technically useful.
Privacy notes
Commercial submissions may include submitter identity, company relationship, pricing terms, sales contacts, invite links, private roadmap claims, or analytics parameters., Remove tracking parameters and do not expose private sponsorship negotiations, vendor emails, account IDs, coupon codes, or referral IDs in public review threads., Keep reviewer notes focused on observable source evidence and directory policy rather than private commercial discussions.
Author
MkDev11
Submitted by
MkDev11
Claim status
unclaimed
Last verified
2026-06-04

Decision playbook

Review trust signals before you adopt

Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.

Compare context
Selected

0

Current score

78

Baseline

Delta

No baseline selected

No major trust-signal divergence detected in the current selection.

Source and provenance checks

Complete

Confirm ownership and provenance before trusting install instructions.

  • Source link availableRequired

    Open the canonical repository and verify ownership.

    Done
  • Source provenance statusRequired

    Marked as source-backed.

    Done
  • Metadata reviewed

    Registry metadata indicates a reviewed listing.

    Done

Safety and privacy checks

Complete

Validate risk disclosures before installation or API wiring.

  • Safety notes presentRequired

    Review the listed safety guidance before running commands.

    Done
  • Privacy notes presentRequired

    Review data handling notes before connecting accounts or secrets.

    Done
  • Trust level risk gateRequired

    Trust level does not block evaluation.

    Done

Package and install checks

Needs review

Check package metadata and artifact integrity signals.

  • Install payload available

    Install or copy payload is available for review.

    Done
  • Package verification flag

    No package verification flag provided.

    Pending
  • Checksum metadata

    No checksum provided for downloaded artifact.

    Pending

Compare-driven decision checks

Needs review

Use compare context to validate trade-offs before adoption.

  • Compare tray has multiple entries

    Add at least one more entry to compare trust differences.

    Pending
  • Baseline comparison available

    No baseline peer selected yet.

    Pending
  • Diverging trust signals identified

    No major trust-signal divergence found.

    Pending

Setup at a glance

Copy & paste

Copy-ready — paste the snippet to get started.

10 minutes

Adoption plan

Balanced adoption plan

Current risk score 16/100. Use staged verification before broader rollout.

Risk 16

Pre-adoption checks

Validate source and review signals before any execution.

  • Confirm source provenanceRequired

    Source URL/provenance metadata is present.

    Done
  • Confirm metadata review state

    Listing has review metadata.

    Done
  • Verify install payload

    Install/config payload exists and can be inspected.

    Done

Security checks

Confirm safety, privacy, and package integrity signals.

  • Review safety notesRequired

    Safety notes are present.

    Done
  • Review privacy notesRequired

    Privacy notes are present.

    Done
  • Verify package integrity metadata

    No package verification/checksum metadata.

    Pending

Rollout

Adopt in controlled steps based on the selected plan.

  • Run in isolated sandbox firstRequired

    Use a constrained sandbox and observe behavior across multiple tasks.

    Pending
  • Roll out graduallyRequired

    Roll out to a small cohort before wider usage.

    Pending
  • Set monitoring and fallback

    Define rollback path and monitor errors after adoption.

    Pending

Evidence readiness

Evidence readiness matrix · balanced

Required evidence gates are covered (5/6 signals complete).

Risk 15

Source provenance

Present

Source repository/provenance is listed.

Required in this preset

Metadata review

Present

Review metadata is present.

Required in this preset

Safety notes

Present

Safety notes are present.

Required in this preset

Privacy notes

Present

Privacy notes are present.

Optional in this preset

Package integrity

Missing

Package integrity metadata is missing.

Optional in this preset

Install payload

Present

Install payload is available.

Required in this preset

Required evidence gates are covered for this preset.

Decision timeline

Decision timeline · balanced

5/6 steps complete with no blocking gaps for this preset.

Risk 14

triage

Confirm source provenanceRequired

Source/provenance metadata is available.

Done

triage

Check metadata review statusRequired

Review metadata is available.

Done

verify

Review safety notesRequired

Safety notes are available.

Done

verify

Review privacy notes

Privacy notes are available.

Done

verify

Validate package integrity metadata

Package integrity metadata is missing.

Pending

rollout

Verify install payload and commandsRequired

Install payload is available.

Done

No required blockers for this timeline preset.

Prerequisite readiness

Prerequisite readiness

4 prerequisites to line up before setup. Includes a review or approval gate.

0/4 ready
Permissions & scopes1Review & approval1General210 minutes

Safety & privacy surface

Safety & privacy surface

3 safety and 3 privacy notes across 4 risk areas. Review closely: third-party handling.

4 areas
  • SafetyGeneralCommercial routing is an editorial control, not a legal compliance guarantee; escalate uncertain sponsorship, endorsement, or advertising questions to the maintainer or counsel.
  • SafetyGeneralDo not let generated copy invent rankings, endorsements, security claims, customer counts, pricing promises, or benchmark results.
  • SafetyThird-party handlingTreat paid placement, affiliate links, vendor claims, and product submissions as higher-review-risk even when the linked product is technically useful.
  • PrivacyTelemetryCommercial submissions may include submitter identity, company relationship, pricing terms, sales contacts, invite links, private roadmap claims, or analytics parameters.
  • PrivacyThird-party handlingRemove tracking parameters and do not expose private sponsorship negotiations, vendor emails, account IDs, coupon codes, or referral IDs in public review threads.
  • PrivacyLocal filesKeep reviewer notes focused on observable source evidence and directory policy rather than private commercial discussions.

Safety notes

  • Commercial routing is an editorial control, not a legal compliance guarantee; escalate uncertain sponsorship, endorsement, or advertising questions to the maintainer or counsel.
  • Do not let generated copy invent rankings, endorsements, security claims, customer counts, pricing promises, or benchmark results.
  • Treat paid placement, affiliate links, vendor claims, and product submissions as higher-review-risk even when the linked product is technically useful.

Privacy notes

  • Commercial submissions may include submitter identity, company relationship, pricing terms, sales contacts, invite links, private roadmap claims, or analytics parameters.
  • Remove tracking parameters and do not expose private sponsorship negotiations, vendor emails, account IDs, coupon codes, or referral IDs in public review threads.
  • Keep reviewer notes focused on observable source evidence and directory policy rather than private commercial discussions.

Prerequisites

  • A directory submission policy that separates ordinary editorial content from sponsored, affiliate, claimed, or vendor-submitted listings.
  • Permission to block, reroute, or request edits when a submission includes commercial claims, tracking URLs, or unclear sponsorship.
  • Access to the submitted source URLs, repo/package metadata, pricing or plan pages, and any disclosed author or vendor relationship.
  • A maintainer-owned path for commercial review so contributors do not need to negotiate paid placement inside ordinary pull requests.

Schema details

Install type
copy
Reading time
6 min
Difficulty score
34
Troubleshooting
Yes
Breaking changes
No
Collection metadata
Estimated setup
10 minutes
Difficulty
beginner
Full copyable content
You are reviewing a commercial or promotional submission for an AI workflow
directory.

Rules:
1. Classify the submitter relationship before judging quality.
2. Route paid, sponsored, affiliate, claimed, or vendor-authored submissions to
   maintainer-owned commercial review instead of ordinary editorial review.
3. Reject affiliate or referral URLs in free contributor content.
4. Require clear disclosure when a listing is sponsored, affiliate-backed,
   vendor-authored, or commercially claimed.
5. Keep editorial listings source-backed, comparative, and non-promotional.
6. Do not merge thin product copy, unsupported superlatives, or tracking links.

About this resource

Purpose

Use these rules when an AI workflow directory receives a submission that might be commercial, sponsored, affiliate-backed, vendor-authored, vendor-claimed, or promotional. The goal is to keep ordinary editorial content review separate from commercial placement and to make disclosure decisions before copy quality is debated.

These rules do not decide whether a product is good. They decide which review path a submission belongs in and what evidence must exist before it can appear in a public directory.

Classification Rules

Classify the submission before editing prose.

  1. Editorial. A contributor independently documents a tool, workflow, rule, guide, or directory entry without payment, affiliate benefit, vendor control, or claimed ownership.
  2. Vendor-authored. The author works for, owns, maintains, represents, or is formally connected to the listed product or service.
  3. Claimed. A vendor or maintainer asks to own or correct an existing entry.
  4. Sponsored. Placement, ordering, copy, links, or visibility are connected to payment, campaign value, or a commercial arrangement.
  5. Affiliate or referral. A URL, coupon, invite code, tracking parameter, or account-specific link can create attribution, compensation, credits, or lead tracking.
  6. Thin promotion. The submission mostly repeats sales copy, superlatives, launch language, pricing promises, or unsupported competitive claims.

When the classification is unclear, route the submission to maintainer review. Do not merge it as ordinary editorial content while the relationship is unknown.

Routing Rules

  • Route sponsored, affiliate, referral, claimed, and vendor-authored submissions out of the free contributor queue.
  • Keep commercial review maintainer-owned. Contributors can supply evidence, but they should not decide paid placement, sponsorship labels, or affiliate terms.
  • Reject affiliate and referral URLs in ordinary contributor PRs.
  • Replace tracking URLs with canonical documentation, repository, package, or product URLs before editorial review continues.
  • Require disclosure text when the submitter has a vendor, sponsor, affiliate, or ownership relationship.
  • Do not accept a commercial submission that lacks public source evidence for the claims it wants the directory to repeat.

Editorial Quality Rules

Ordinary editorial content should describe verifiable utility rather than sell.

Accept content that:

  • cites canonical docs, repos, packages, policies, or product pages;
  • explains concrete use cases, prerequisites, limits, safety notes, and privacy notes;
  • distinguishes open-source project code from hosted, paid, enterprise, or managed offerings;
  • states commercial status plainly without making the entry sound endorsed;
  • removes tracking parameters, marketing campaign fragments, and unverifiable rankings.

Request changes or reject content that:

  • says a product is best, leading, official, trusted, secure, fastest, or most popular without source-backed evidence;
  • imports landing-page copy without adding directory-specific context;
  • hides paid plans, hosted services, enterprise upsells, or vendor control when they affect user expectations;
  • uses affiliate links, invite links, coupon links, UTM-heavy links, or short links as source URLs;
  • asks the directory to publish private roadmap, sales, customer, or pricing claims that users cannot verify.

Disclosure Rules

Commercial status should be visible to reviewers and users.

  • Say when a listing is editorial and has no paid placement or affiliate link.
  • Say when a product has open-source code plus hosted, commercial, enterprise, marketplace, or paid support offerings.
  • Say when a submission is vendor-authored, vendor-claimed, sponsored, or affiliate-backed.
  • Use sponsored or affiliate link attributes when a published outbound link is commercial in that way.
  • Keep disclosure close to the listing rather than hiding it only in PR comments or internal notes.

Disclosure does not rescue thin content. A sponsored or vendor-authored entry still needs source evidence, safety notes, privacy notes, and directory-specific editorial value.

Reviewer Checklist

  • {"task": "Relationship classified", "description": "The submitter relationship is editorial, vendor-authored, claimed, sponsored, affiliate, referral, or unknown"}
  • {"task": "Correct route", "description": "Commercial or unclear submissions are routed to maintainer-owned review, not merged through the ordinary contributor queue"}
  • {"task": "Canonical links", "description": "Source URLs are canonical and do not contain affiliate, referral, coupon, short-link, or campaign tracking parameters"}
  • {"task": "Disclosure present", "description": "Paid placement, sponsorship, affiliate status, vendor authorship, or commercial ownership is disclosed where relevant"}
  • {"task": "Claims verified", "description": "Feature, pricing, license, security, popularity, benchmark, and compatibility claims have public source evidence"}
  • {"task": "Editorial value", "description": "The entry explains use case, prerequisites, limits, safety, and privacy instead of repeating promotional copy"}

Do Not Merge When

  • the author relationship is unknown and may be commercial;
  • the PR contains affiliate, referral, coupon, invite, short-link, or tracking URLs in contributor content;
  • a vendor-authored entry is presented as independent editorial review;
  • sponsored placement is requested without maintainer-owned commercial review;
  • public claims depend on private emails, sales decks, or unverified launch language;
  • generated text turns source facts into endorsements, rankings, or unsupported comparative claims.

Troubleshooting

  • The tool is useful but the PR is promotional: reroute it first, then ask for source-backed, neutral copy.
  • The contributor says there is no sponsorship: ask them to remove tracking URLs and state whether they have a vendor, affiliate, or ownership relationship.
  • A vendor submits corrections to an existing entry: separate factual fixes from placement, ordering, or promotional requests.
  • A link looks canonical but includes parameters: remove UTM, referral, coupon, invite, and partner parameters before using it as a source.
  • A claim is plausible but unsourced: keep the neutral fact that can be verified and drop the unsupported superlative.

Duplicate Check

Checked existing rules, guides, collections, tools, MCP entries, statuslines, submission validators, and recent PRs for commercial routing rules, sponsored directory submissions, affiliate link rejection, vendor-authored content, promotional copy review, and disclosure policy.

Existing entries often include per-listing disclosure text such as "no paid placement or affiliate link is used," and the submission pipeline rejects affiliate/referral URLs. This rules entry is distinct because it gives portable do/don't behavior for deciding whether a directory submission belongs in ordinary editorial review, maintainer-owned commercial review, or rejection.

Spam-Policy Mapping

Google Search Central documents the spam policies below. Each names a pattern that commercial and promotional directory submissions commonly trigger, which is why routing happens before quality review. Definitions are quoted from Google's spam policies page.

Google spam policy What Google says it covers (verbatim)
Thin affiliation "the practice of publishing content with product affiliate links where the product descriptions and reviews are copied directly from the original merchant without any original content or added value."
Link spam "the practice of creating links to or from a site primarily for the purpose of manipulating search rankings."
Scaled content abuse "when many pages are generated for the primary purpose of manipulating search rankings and not helping users."
Scraping "the practice of taking content from other sites, often through automated means, and hosting it with the purpose of manipulating search rankings."
Site reputation abuse "a tactic where third-party content is published on a host site mainly because of that host's already-established ranking signals."
User-generated spam "spammy content added to a site by users through a channel intended for user content."
Misleading functionality "intentionally creating sites that trick users into thinking they would be able to access some content or services but in reality can't."

References

Source citations

Add this badge to your README

Show that Commercial Content Routing Rules is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.

Listed on HeyClaude
[![Listed on HeyClaude](https://heyclau.de/badge/rules/commercial-content-routing-rules.svg)](https://heyclau.de/entry/rules/commercial-content-routing-rules)

How it compares

Commercial Content Routing Rules side by side with 2 alternatives on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.

1 trust signal differ across this comparison (Submitter).

Field

Source-backed rules for AI workflow directories that need to classify commercial, sponsored, affiliate, vendor-authored, and thin promotional submissions before they enter the ordinary editorial content queue.

Open dossier

Source-backed rules for reviewing AI-generated code that renders untrusted data into HTML, JavaScript, URLs, or CSS before merge for cross-site scripting risk, covering context-correct output encoding, dangerous DOM sinks, HTML sanitization, and Content-Security-Policy as defense in depth.

Open dossier

Source-backed rules for AI workflow directories that need consistent privacy metadata before accepting entries that touch prompts, files, local tools, hosted services, telemetry, generated artifacts, or personal data.

Open dossier
Next steps
Trust
Review statusReviewedMaintainer reviewedReviewedMaintainer reviewedReviewedMaintainer reviewed
Package trustPackage not verifiedPackage not verifiedPackage not verified
Source provenanceSource-backedSource-backedSource-backed
SubmitterDiffersMkDev11lourincedaging0-commitsMkDev11
Install riskReview firstReview firstReview first
Notes Safety ✓ Privacy ✓ Safety ✓ Privacy ✓ Safety ✓ Privacy ✓
Brand
Categoryrulesrulesrules
SourceSource-backedSource-backedSource-backed
AuthorMkDev11lourincedaging0-commitsMkDev11
Added2026-06-042026-07-152026-06-04
Platforms
Harness
Source repo
Safety notesCommercial routing is an editorial control, not a legal compliance guarantee; escalate uncertain sponsorship, endorsement, or advertising questions to the maintainer or counsel. Do not let generated copy invent rankings, endorsements, security claims, customer counts, pricing promises, or benchmark results. Treat paid placement, affiliate links, vendor claims, and product submissions as higher-review-risk even when the linked product is technically useful.A successful XSS injection runs attacker JavaScript in another user's browser session, enabling session/token theft, account takeover, keylogging, or unauthorized actions performed as that user. AI assistants frequently reach for innerHTML, dangerouslySetInnerHTML, or string-concatenated HTML because it is the shortest path to the desired rendering, without adding sanitization or switching to a safe sink. Relying only on a Content-Security-Policy header is not sufficient: CSP support and enforcement vary by browser, misconfiguration is common, and it does not address DOM-based XSS that never touches the network.Privacy metadata is a reviewer aid, not proof that a workflow is safe or compliant for every jurisdiction or organization. Escalate entries that touch regulated data, customer records, credentials, browser state, production systems, or private repositories. Do not let generated descriptions replace source-backed privacy notes; require the submitter to identify actual data paths.
Privacy notesCommercial submissions may include submitter identity, company relationship, pricing terms, sales contacts, invite links, private roadmap claims, or analytics parameters. Remove tracking parameters and do not expose private sponsorship negotiations, vendor emails, account IDs, coupon codes, or referral IDs in public review threads. Keep reviewer notes focused on observable source evidence and directory policy rather than private commercial discussions.XSS proof-of-concept payloads and captured DOM/session state can include real session tokens, cookies, or personal data; use synthetic accounts and redact captures before pasting them into a PR or issue. Sanitizer configuration (allowed tags/attributes) can itself leak intent about what user-generated content the product stores; avoid documenting real user content samples in public review threads. Third-party scripts and widgets execute with the same DOM access as first-party code; disclose any new third-party script include as part of the change under review.The review itself can expose private repo names, tool config, prompt examples, customer-like fixtures, logs, screenshots, or vendor account details. Avoid copying secrets, private prompts, personal data, or proprietary datasets into public metadata examples. Record unknowns honestly instead of filling gaps with guessed retention, sharing, or telemetry behavior.
Prerequisites
  • A directory submission policy that separates ordinary editorial content from sponsored, affiliate, claimed, or vendor-submitted listings.
  • Permission to block, reroute, or request edits when a submission includes commercial claims, tracking URLs, or unclear sponsorship.
  • Access to the submitted source URLs, repo/package metadata, pricing or plan pages, and any disclosed author or vendor relationship.
  • A maintainer-owned path for commercial review so contributors do not need to negotiate paid placement inside ordinary pull requests.
  • A pull request, diff, or snippet containing AI-generated or AI-edited code that renders variables into HTML, JavaScript, a URL, or CSS, or that calls DOM-manipulation APIs.
  • Knowledge of which values in the change are untrusted (user input, query params, third-party API responses, database content originally sourced from users).
  • Awareness of the framework's default auto-escaping behavior and which of its APIs bypass that escaping.
  • Permission to block merge when untrusted data reaches a dangerous sink without context-correct encoding or sanitization.
  • A directory entry or submission that describes an AI workflow, tool, MCP server, hook, skill, command, collection, guide, or hosted service.
  • Permission to request edits when privacy notes, source links, data categories, or execution surfaces are missing.
  • Access to source documentation for the tool or workflow, including where it runs and what data it reads or transmits.
  • A review place for recording privacy-relevant assumptions, unknowns, and last-checked dates.
Install
Config
Citations
ClaimUnclaimedUnclaimedUnclaimed
Open 3 picks in the interactive comparison tool

Signals

Loading live community signals…

More like this, weekly

A short, calm digest of reviewed Claude resources. Unsubscribe any time.