Back to skill

Security audit

Etsy Digital Sales

Security checks across malware telemetry and agentic risk

Overview

This skill describes fully automated Etsy shop actions, including buyer follow-ups and credential use, without enough safety controls or guidance.

Review this carefully before installing. It is not showing hidden malware, and VirusTotal/static scans are clean, but it asks for Etsy credentials and describes automated shop and customer-message actions. Only use it with credentials stored in a secure secret store, verify Etsy policy compliance, require manual approval for buyer messages and listing changes, and prefer test or limited-scope credentials before using it on a real shop.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly promotes automated follow-up messages to collect reviews without warning about platform-policy, consent, or anti-spam risks. In this context, automation targeting customers can lead users to violate Etsy marketplace rules or send unwanted messages at scale, creating compliance and account-enforcement risk.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to store Etsy API and OAuth credentials in settings but provides no warning about treating them as sensitive secrets or limiting their exposure. Because these credentials can authorize marketplace actions and access account data, poor handling increases the risk of account takeover, unauthorized listing changes, or data exposure if the environment is shared or compromised.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.