erxes Skill
PassAudited by VirusTotal on May 13, 2026.
Findings (1)
The erxes skill bundle is a legitimate integration for managing the erxes CRM/ERP platform via GraphQL. It includes a shell script (scripts/login.sh) that implements a standard OAuth Device Flow to authenticate users against a user-provided gateway URL. The instructions in SKILL.md and the various API reference files (block-api.md, operation-api.md, etc.) include explicit safety guardrails, such as requiring user confirmation for destructive actions (delete/remove) and instructing the agent to keep authentication tokens in memory rather than persisting them to disk. No evidence of malicious intent, data exfiltration, or unauthorized execution was found.
