Join our Newsletter — 33% off our NHI Course

OAuth app listings: are your marketplace controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Marketplace presence is not a security review, according to Offroad AI’s research: 677 apps asked for permissions beyond their stated function, 206 had dead publisher domains, and 49 AI-powered apps carried broad write access, based on its scan of major OAuth marketplaces. That pattern turns OAuth grants into persistent business risk rather than one-time consent.

Editorial analysis by NHI Mgmt Group, based on content published by Offroad AI: “Our OAuth agent found hidden risk in nearly one in three marketplace apps”.

By the numbers:

  • The agent found 677 apps that ask for at least one permission beyond their stated function, representing a combined 1.82 billion installs.
  • Offroad AI’s agent identified 206 apps with dead publisher domains and 89 apps whose publisher domain is currently available to buy.
  • The agent flagged 49 AI-powered apps with broad write access, representing an 81.6M install footprint.

Key questions

Q: What breaks when an OAuth app listing is mistaken for an approval decision?

A: The control breaks because marketplace listing status says nothing about scope fit, publisher continuity, or the app’s behaviour after installation.

Q: Why do broad OAuth scopes increase breach impact?

A: Broad scopes turn one consent decision into multiple reachable resources, which gives an attacker a much larger blast radius if the app is compromised.

Q: What signs indicate an OAuth app should be reviewed or revoked?

A: Look for dead or parked publisher domains, permissions that exceed the app’s stated function, broad write or delete scopes, and apps whose behaviour depends on AI-driven actions.

Practitioner guidance

  • Inventory all OAuth grants across marketplaces Map every approved third-party app to the scopes it holds, the publisher domain behind it, and the business systems it can reach.
  • Challenge over-broad scopes at approval time Compare requested permissions with the app’s stated purpose and reject grants where the scope set is materially wider than the use case.
  • Verify publisher domain continuity Check whether the domain behind the app is still active, owned, and supportable before leaving a grant in place.

Bottom line: Marketplace listings are not a trustworthy proxy for OAuth app safety because the real risk lives in the scopes, the publisher, and the post-consent behaviour.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Marketplace listing is not an identity assurance control: this article shows that publication in an official marketplace does not prove scope correctness, publisher continuity, or runtime trust. The listing only says the app exists in the catalog, while the actual risk lives in the durable OAuth grant behind it. Practitioners should stop treating marketplace status as evidence of safe access.

A few things that frame the scale:

A question worth separating out:

Q: How should organisations govern AI-powered OAuth apps?

A: Organisations should treat AI-powered OAuth apps as higher-uncertainty delegated actors because the model can decide when to act, not just what data to touch. That means stricter logging, narrower scopes, shorter review cycles, and explicit owner accountability for every high-risk action path such as sending mail or editing files.

👉 Read our full editorial: OAuth marketplace listings do not equal approval or safe access


This post was modified 5 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.