Marketplace safety policy

Skills we will not host.

Sealed is built for useful, lawful, enterprise-grade skills. A seller may not list or run a skill that helps someone steal secrets, export a user's local data, damage a computer, evade safety controls, defraud people, suppress voters, automate high-stakes regulated decisions, substitute for licensed professional advice, evade sanctions, launder funds, forge documents, traffic illegal goods, pirate protected works, bypass rights controls, harvest or surveil non-consenting people, manipulate or score people unlawfully, or abuse another person or system.

Policy version 2026-06-13.13. This page mirrors the server screening gate and public catalog rules.

01 Prohibited categories

Credential or payment theft

No skills that extract, capture, exfiltrate, or misuse passwords, API keys, session cookies, tokens, cards, private keys, or other secrets.

Local data exfiltration

No skills that secretly copy, package, upload, or export user files, browser data, source code, private documents, screenshots, messages, or other local data to external endpoints.

Malware or persistence

No keyloggers, reverse shells, backdoors, persistence, evasion, unauthorized implants, or instructions to bypass security tools.

Destructive computer actions

No skills that wipe disks; delete or corrupt credential stores, browser profiles, source trees, workspaces, backups, snapshots, or user files; encrypt data for coercion; sabotage systems; or otherwise harm a user's computer or data.

Resource abuse or system sabotage

No miners, fork bombs, resource exhaustion, or workflows that disable firewalls, backups, updates, logs, monitoring, or security services.

Unauthorized access

No account takeover, brute force, exploit chaining, vulnerability weaponization, or extraction from third-party systems without authorization.

Network abuse

No denial-of-service, botnet, spam, abusive traffic, scraping designed to bypass access controls, or infrastructure misuse.

Fraud or impersonation

No phishing, fake login capture, deceptive payment flows, identity theft, marketplace manipulation, or other transactional deception.

Election interference or voter suppression

No voter intimidation, election-worker harassment, false voting-process information, election-office impersonation, or deceptive AI campaign impersonations.

Manipulative or social-scoring AI abuse

No harmful manipulation, exploitation of vulnerabilities, social scoring, criminal-risk prediction, facial-recognition database scraping, protected-characteristic biometric categorization, or workplace/education emotion recognition.

High-stakes regulated decisioning

No generic marketplace skills that automate, rank, score, approve, deny, or recommend consequential outcomes for employment, housing, credit, insurance, education, public benefits, healthcare triage, immigration, or law enforcement.

Licensed professional substitution

No generic marketplace skills that act as a doctor, lawyer, investment adviser, or other licensed professional by giving personalized diagnoses, prescriptions, legal advice or representation, investment recommendations, or auto-trading directives.

Sanctions or export-control evasion

No skills that help evade OFAC, sanctions, export controls, embargoes, restricted-party screening, KYC, or AML checks.

Financial crime or laundering

No money laundering, terrorist financing, mule accounts, transaction structuring, crypto-mixer abuse, or concealment of illegal proceeds.

Counterfeit or document fraud

No forged IDs, passports, visas, licenses, bank statements, pay stubs, invoices, diplomas, prescriptions, or altered documents used to deceive.

Illegal goods or unlawful services

No trafficking, sale, procurement, shipping, or distribution of illegal drugs, weapons, stolen goods, counterfeit goods, or unlawful services.

Weapons, explosives, or CBRN abuse

No skills that help make, convert, procure, deploy, or use firearms, silencers, machine-gun conversion devices, destructive devices, explosives, select agents, toxins, or chemical, biological, or radiological weapons.

Copyright, piracy, or rights circumvention

No paywall, DRM, copy-protection, license-check, or copyright-management circumvention; no piracy, cracked software, or unauthorized copying or redistribution of protected works.

Sexual abuse or non-consensual intimate content

No child sexual abuse material, sexual exploitation, sextortion, non-consensual intimate imagery, AI nudification/digital forgeries, or related abuse workflows.

Privacy abuse or surveillance

No non-consensual personal-data harvesting, people-finder datasets, covert tracking, deanonymization, or surveillance of private individuals through contact, location, biometric, device, or identity data.

Privacy abuse or harassment

No doxxing, stalking, swatting, non-consensual personal-data collection, or instructions that target private individuals.

Safety bypass or physical harm

No skills built to bypass Sealed containment, evade moderation, or provide operational instructions for physical harm.

02 Listing review path

1
Seller attestation

The seller must certify the skill is lawful, authorized, non-harmful, and non-infringing before upload.

2
Deterministic screening

The server screens the sealed submission before it can list. Rejections return policy codes only; the skill body is never echoed in the response or audit trail.

3
Sealed approval in production

Seller-submitted skills stay out of the public catalog and cannot run until a reviewer completes the fixed safety/legal checklist and applies a current policy approval stamp.

4
Re-screening after policy changes

Durable rows without a current screening stamp fail closed. They must be re-screened and, when required, reviewed before traffic.

03 Enforcement

We may refuse publication, remove a listing, suspend access, hold payouts while investigating, or terminate an account when a skill violates this policy, the Terms, or the law. Severe or repeated abuse may be referred to the appropriate platform, payment, enterprise, or legal channel.

Sanctions, export-control, AML, KYC, and restricted-party controls apply across buyers, sellers, skills, and payouts. We may block account access, seller onboarding, skill publication, runs, wallet activity, or Connect cash-out when required for sanctions/export compliance, payment-network rules, Stripe requirements, law-enforcement/legal obligations, or marketplace safety.

Good-faith defensive, educational, compliance, and authorized internal security work can be allowed when it is scoped to lawful systems and does not provide operational abuse instructions.