Yeah, I've seen a lot of scams revolve around resources. Definitely add explicit rules stating what and what you cannot do with resources you purchase.
For plugins there is obfuscation and licensing. You could also just sell it privately and do each sale manually. More work, but you know who you're dealing with.
It never crossed my mind that there's no set rules (at least from what I can see) for resources. Thank you for suggestion this, when I get some time I'll go over it and try to get it implemented.