Amazon Seller
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe Amazon Seller skill appears well-aligned with its stated goal of automating seller operations using official Amazon SP-API and Ads API. Its footprint remains proportionate to its purpose with no evident credential harvesting, unauthorized data exfiltration, or untrusted third-party binaries. Key security improvements recommended: explicit credential handling/storage details, least-privilege scopes for API access, and per-action user consent prompts for high-impact operations (e.g., mass price changes, large shipment plans). Overall, the risk profile is Benign-to-Suspicious (leaning toward Benign) given the reliance on official APIs, provided credential management is properly secured in deployment.