Amazon Seller

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Amazon Seller skill appears well-aligned with its stated goal of automating seller operations using official Amazon SP-API and Ads API. Its footprint remains proportionate to its purpose with no evident credential harvesting, unauthorized data exfiltration, or untrusted third-party binaries. Key security improvements recommended: explicit credential handling/storage details, least-privilege scopes for API access, and per-action user consent prompts for high-impact operations (e.g., mass price changes, large shipment plans). Overall, the risk profile is Benign-to-Suspicious (leaning toward Benign) given the reliance on official APIs, provided credential management is properly secured in deployment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:21 AM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fskills%2Famazon-seller%2F@92d1f4d79d7641005a5794463a1b02670f994d0e