Back to skill

Security audit

Gumroad Launcher

Security checks across malware telemetry and agentic risk

Overview

This skill is for launching Gumroad products, but it can direct an agent toward live publishing with unclear account credentials and no required final approval step.

Install only if you intentionally want an agent to help prepare and publish Gumroad listings. Remove or ignore the named account references, use only your own limited-scope credentials, and require the agent to show the exact product file, sales copy, price, and target account before any live listing is created.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill explicitly references named third-party Gumroad accounts for operational use, which couples a general-purpose product-launch skill to specific real identities and stores. In an agentic context, that creates a real risk of unauthorized publication, account misuse, and accidental cross-account actions, especially because the skill is designed to proceed all the way to live listing.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough that the skill could activate for vague requests like creating something to sell or passive income product generation, even when the user did not intend end-to-end publishing. Because this skill includes external research, file creation, and live publishing, overbroad invocation materially increases the chance of unintended high-impact actions.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill instructs use of web_fetch or exec to publish through the Gumroad API using credentials, but does not require any warning, consent gate, or runtime confirmation before performing network actions on an external commercial platform. In an autonomous or semi-autonomous environment, that can lead to unauthorized account activity, accidental product publication, and credential misuse.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The example sales copy explicitly markets a skill to "clone any live website" and highlights extracting content from JS bundles and rebuilding sites pixel-perfect, but provides no legal, ethical, copyright, or privacy guardrails. In the context of a Gumroad product-launching skill, this materially increases the chance the agent will generate or promote products that facilitate unauthorized copying of third-party sites, which can enable IP infringement, deceptive impersonation, or misuse of scraped assets.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.