Back to skill

Security audit

Sellapp Autolist

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it can create public SellApp storefront products using the user's API key without a clear confirmation or draft-first safety step.

Review before installing if you do not want an agent to publish products on a live SellApp account. Use a test SellApp account or restricted API key first, verify the catalog and prices, and prefer adding a dry-run or explicit confirmation before any public listings are created.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill documentation states that it will create products and set them to PUBLIC, but it does not prominently warn users that running the automation will publish marketplace listings under their SellApp account. This can lead to unintended public storefront changes, reputational harm, and unwanted commercial activity if a user runs the skill without understanding the side effects.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.