This delivery-verification skill mostly matches its stated purpose, but it asks for broad execution and sensitive integration access while also making an unscoped outbound link request and including under-disclosed chat inspection logic.
Review this skill before installing in a trusted environment. It should only be used if you are comfortable granting it Python execution, access to Xianyu chat/order verification services, and outbound access to submitted delivery links. Prefer tightening it to documented MCP calls, removing unused required secrets, documenting or removing the AI-declaration check, and restricting link validation to approved cloud-drive domains.