marketplaces-mcp

Warn

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install and run the marketplaces-mcp-ru package from a public registry using uvx. It also refers to standalone packages such as ozon-mcp-ru, wildberries-mcp-ru, yandex-market-mcp-ru, and avito-mcp-ru.\n- [REMOTE_CODE_EXECUTION]: By invoking uvx on unpinned packages, the skill triggers the execution of remote code that could be updated without the user's knowledge or verification.\n- [COMMAND_EXECUTION]: The skill setup requires the execution of shell commands to configure MCP servers within the agent's environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill acts as a gateway to multiple external marketplace APIs, which serves as a surface for processing untrusted data.\n
  • Ingestion points: Data retrieved from Seller APIs (Wildberries, Ozon, Yandex Market, Avito), including order details and product catalogs.\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the API output as untrusted or to ignore embedded instructions.\n
  • Capability inventory: The skill possesses network communication capabilities and file system write access for configuration storage (~/.marketplace-mcp/cabinets.json).\n
  • Sanitization: The instructions do not define any sanitization or validation logic for the content fetched from the marketplace endpoints.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 11, 2026, 02:17 PM
Security Audit — agent-trust-hub — marketplaces-mcp