xianyu-product

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from users or external files (e.g., Excel, product descriptions) and maps them directly to tool arguments for xianyu_publish_product and xianyu_batch_publish_products. If a user provides a malicious payload in a description, it could potentially influence the agent's behavior during the publication process, although the impact is limited to the scope of the publication tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:16 AM
Security Audit — agent-trust-hub — xianyu-product