legend-shop-supply-api
Query LegendShop Supply Products
Merchants need current supplier product data before choosing inventory. This skill queries LegendShop product, inventory, price, and balance data through the platform API.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "legend-shop-supply-api" from https://skillstore.io/skills/legendmall-legend-shop-supply-api.md and its manifest at https://skillstore.io/api/skills/legendmall-legend-shop-supply-api/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "legend-shop-supply-api". Show the first page of available products.
Expected outcome:
Returns a product list summary with product IDs, total count, page information, and next action suggestions.
Using "legend-shop-supply-api". Check details for product 1249846.
Expected outcome:
Returns the product name, price, SKU options, images, and parameters when the API permits access.
Using "legend-shop-supply-api". What is my developer account balance?
Expected outcome:
Returns the API status, success message, and current balance when the token has account permission.
Security Audit
CriticalThe skill legitimately performs network API calls to LegendShop and documents endpoint URLs. The most serious issue is embedded client credentials that can obtain tokens and query developer account balance. Many static Markdown, CSS, and entropy detections are false positives.
Confirmed security concerns (2)
Capability review items (19)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (23)
🔑 Env variables (4)
⚙️ External commands (29)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/legendmall-legend-shop-supply-api/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/legendmall-legend-shop-supply-api?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/legendmall-legend-shop-supply-api?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/legendmall-legend-shop-supply-api/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/legendmall-legend-shop-supply-api.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
legendmall. (2026). legend-shop-supply-api security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/legendmall-legend-shop-supply-api/audits/4BibTeX citation
@techreport{legendmall-legendmall-legend-shop-supply-api-2026,
author = {legendmall},
title = {legend-shop-supply-api security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/legendmall-legend-shop-supply-api/audits/4},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "legend-shop-supply-api security audit report (audit version 4)"
version: "unspecified"
type: report
authors:
- name: "legendmall"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/legendmall-legend-shop-supply-api/audits/4"
identifiers:
- type: other
value: "skillstore:legendmall-legend-shop-supply-api:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Source Products for a Store
Browse supplier product IDs and request details for items that may fit a sales channel.
Check Product Data Before Listing
Review price, SKU, image, and parameter data before preparing a product listing.
Verify Developer Account Readiness
Check account balance and API permission messages before running supply chain workflows.
Try These Prompts
Show me the first page of supply chain products with 12 items.
Get details for product ID 1249846 and summarize price, stock, SKU options, and images.
List products on page 2, then identify which items need detail checks before sourcing.
Check the developer account balance, then explain whether API permissions or funds block sourcing work.
Best Practices
- Confirm permissions and account ownership before running balance queries.
- Start with product list results, then request details for selected product IDs.
- Treat prices, stock, and balances as live API results that may change.
Avoid
- Do not publish shared client secrets in scripts or OpenAPI defaults.
- Do not disable proxy settings without explicit user approval.
- Do not present sample product data as live API data.
Frequently Asked Questions
Does this skill place orders?
Which tools can use it?
Does it need network access?
Are credentials included?
Can it query any product?
Is the balance query safe?
Developer Details
Author
legendmallLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
b8ca75d2c0a7e7102978993058777d82b8ab2610
Maintenance freshness
7/18/2026
Usage
2 downloads · 48 views