Constraint: Public marketplace documentation must not identify private implementation sources or unpublished capabilities.
Rejected: Explaining omitted MCP servers in public README | the explanation itself exposes private context.
Confidence: high
Scope-risk: narrow
Directive: Public docs should describe only published plugins and generic marketplace rules.
Tested: python scripts/validate_marketplace.py; hidden content and filename scan for private identifiers.