Skills we will not host.
Sealed is built for useful, lawful, enterprise-grade skills. A seller may not list or run a skill that helps someone steal secrets, export a user's local data, damage a computer, evade safety controls, defraud people, suppress voters, automate high-stakes regulated decisions, substitute for licensed professional advice, evade sanctions, launder funds, forge documents, traffic illegal goods, pirate protected works, bypass rights controls, harvest or surveil non-consenting people, manipulate or score people unlawfully, or abuse another person or system.
Prohibited categories
- Credential or payment theft
No skills that extract, capture, exfiltrate, or misuse passwords, API keys, session cookies, tokens, cards, private keys, or other secrets.
- Local data exfiltration
No skills that secretly copy, package, upload, or export user files, browser data, source code, private documents, screenshots, messages, or other local data to external endpoints.
- Malware or persistence
No keyloggers, reverse shells, backdoors, persistence, evasion, unauthorized implants, or instructions to bypass security tools.
- Destructive computer actions
No skills that wipe disks; delete or corrupt credential stores, browser profiles, source trees, workspaces, backups, snapshots, or user files; encrypt data for coercion; sabotage systems; or otherwise harm a user's computer or data.
- Resource abuse or system sabotage
No miners, fork bombs, resource exhaustion, or workflows that disable firewalls, backups, updates, logs, monitoring, or security services.
- Unauthorized access
No account takeover, brute force, exploit chaining, vulnerability weaponization, or extraction from third-party systems without authorization.
- Network abuse
No denial-of-service, botnet, spam, abusive traffic, scraping designed to bypass access controls, or infrastructure misuse.
- Fraud or impersonation
No phishing, fake login capture, deceptive payment flows, identity theft, marketplace manipulation, or other transactional deception.
- Election interference or voter suppression
No voter intimidation, election-worker harassment, false voting-process information, election-office impersonation, or deceptive AI campaign impersonations.
- Manipulative or social-scoring AI abuse
No harmful manipulation, exploitation of vulnerabilities, social scoring, criminal-risk prediction, facial-recognition database scraping, protected-characteristic biometric categorization, or workplace/education emotion recognition.
- High-stakes regulated decisioning
No generic marketplace skills that automate, rank, score, approve, deny, or recommend consequential outcomes for employment, housing, credit, insurance, education, public benefits, healthcare triage, immigration, or law enforcement.
- Licensed professional substitution
No generic marketplace skills that act as a doctor, lawyer, investment adviser, or other licensed professional by giving personalized diagnoses, prescriptions, legal advice or representation, investment recommendations, or auto-trading directives.
- Sanctions or export-control evasion
No skills that help evade OFAC, sanctions, export controls, embargoes, restricted-party screening, KYC, or AML checks.
- Financial crime or laundering
No money laundering, terrorist financing, mule accounts, transaction structuring, crypto-mixer abuse, or concealment of illegal proceeds.
- Counterfeit or document fraud
No forged IDs, passports, visas, licenses, bank statements, pay stubs, invoices, diplomas, prescriptions, or altered documents used to deceive.
- Illegal goods or unlawful services
No trafficking, sale, procurement, shipping, or distribution of illegal drugs, weapons, stolen goods, counterfeit goods, or unlawful services.
- Weapons, explosives, or CBRN abuse
No skills that help make, convert, procure, deploy, or use firearms, silencers, machine-gun conversion devices, destructive devices, explosives, select agents, toxins, or chemical, biological, or radiological weapons.
- Copyright, piracy, or rights circumvention
No paywall, DRM, copy-protection, license-check, or copyright-management circumvention; no piracy, cracked software, or unauthorized copying or redistribution of protected works.
- Sexual abuse or non-consensual intimate content
No child sexual abuse material, sexual exploitation, sextortion, non-consensual intimate imagery, AI nudification/digital forgeries, or related abuse workflows.
- Privacy abuse or surveillance
No non-consensual personal-data harvesting, people-finder datasets, covert tracking, deanonymization, or surveillance of private individuals through contact, location, biometric, device, or identity data.
- Privacy abuse or harassment
No doxxing, stalking, swatting, non-consensual personal-data collection, or instructions that target private individuals.
- Safety bypass or physical harm
No skills built to bypass Sealed containment, evade moderation, or provide operational instructions for physical harm.
Listing review path
- Seller attestation
The seller must certify the skill is lawful, authorized, non-harmful, and non-infringing before upload.
- Deterministic screening
The server screens the sealed submission before it can list. Rejections return policy codes only; the skill body is never echoed in the response or audit trail.
- Sealed approval in production
Seller-submitted skills stay out of the public catalog and cannot run until a reviewer completes the fixed safety/legal checklist and applies a current policy approval stamp.
- Re-screening after policy changes
Durable rows without a current screening stamp fail closed. They must be re-screened and, when required, reviewed before traffic.
Enforcement
We may refuse publication, remove a listing, suspend access, hold payouts while investigating, or terminate an account when a skill violates this policy, the Terms, or the law. Severe or repeated abuse may be referred to the appropriate platform, payment, enterprise, or legal channel.
Sanctions, export-control, AML, KYC, and restricted-party controls apply across buyers, sellers, skills, and payouts. We may block account access, seller onboarding, skill publication, runs, wallet activity, or Connect cash-out when required for sanctions/export compliance, payment-network rules, Stripe requirements, law-enforcement/legal obligations, or marketplace safety.
Good-faith defensive, educational, compliance, and authorized internal security work can be allowed when it is scoped to lawful systems and does not provide operational abuse instructions.