xianyu-product
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from users or external files (e.g., Excel, product descriptions) and maps them directly to tool arguments for
xianyu_publish_productandxianyu_batch_publish_products. If a user provides a malicious payload in a description, it could potentially influence the agent's behavior during the publication process, although the impact is limited to the scope of the publication tools.
Audit Metadata