marketplaces-mcp
Warn
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install and run the
marketplaces-mcp-rupackage from a public registry usinguvx. It also refers to standalone packages such asozon-mcp-ru,wildberries-mcp-ru,yandex-market-mcp-ru, andavito-mcp-ru.\n- [REMOTE_CODE_EXECUTION]: By invokinguvxon unpinned packages, the skill triggers the execution of remote code that could be updated without the user's knowledge or verification.\n- [COMMAND_EXECUTION]: The skill setup requires the execution of shell commands to configure MCP servers within the agent's environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill acts as a gateway to multiple external marketplace APIs, which serves as a surface for processing untrusted data.\n - Ingestion points: Data retrieved from Seller APIs (Wildberries, Ozon, Yandex Market, Avito), including order details and product catalogs.\n
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the API output as untrusted or to ignore embedded instructions.\n
- Capability inventory: The skill possesses network communication capabilities and file system write access for configuration storage (~/.marketplace-mcp/cabinets.json).\n
- Sanitization: The instructions do not define any sanitization or validation logic for the content fetched from the marketplace endpoints.
Audit Metadata