goofish-cli-skills marketplace

A set of Claude skills for automating operations on Goofish, a Chinese online marketplace. It works with the goofish-cli MCP server.

In plain words
What is it for?
Use it to publish items, reply to buyers, run risk checks, recover from security challenges, and diagnose a shop.
Why use it?
It guides the agent through marketplace tasks and checks listings and messages for stated risk rules before action.

Plugin for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Claude Code
/plugin marketplace add fancyboi999/goofish-cli
agentmods
npx agentmods add plugins/fancyboi999/goofish-cli/marketplace
Clone the repo
git clone --depth 1 https://github.com/fancyboi999/goofish-cli

Made for: Claude Code.

Per session not measured What this adds to a session before it is invoked.
When invoked not measured Not applicable: nothing here is loaded into a session.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Security

Grade A, and why

goofish-cli-skills marketplace scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude-plugin/marketplace.json · 60 lines

What it actually says

{
  "$schema": "https://claude.ai/schemas/plugin-marketplace.json",
  "name": "goofish-cli-skills",
  "displayName": "goofish-cli Skills",
  "description": "闲鱼(goofish.com)自动化运营的 Claude Skills 套件。配合 goofish-cli MCP server 使用,让 Agent 在发布商品 / 回复买家 / 风控预检 / 店铺诊断这些场景里上手即会。",
  "version": "0.3.0",
  "author": {
    "name": "fancy",
    "url": "https://github.com/fancyboi999"
  },
  "homepage": "https://github.com/fancyboi999/goofish-cli",
  "repository": {
    "type": "git",
    "url": "https://github.com/fancyboi999/goofish-cli.git"
  },
  "license": "Apache-2.0",
  "requires": {
    "mcp": ["goofish"]
  },
  "plugins": [
    {
      "name": "goofish-overview",
      "source": "./skills/goofish-overview",
      "description": "闲鱼自动化总入口:介绍工具定位、账号模型、15 个 MCP 工具速查、风控底线,并指向其它专项 skill。"
    },
    {
      "name": "goofish-risk-guard",
      "source": "./skills/goofish-risk-guard",
      "description": "发布 / 发消息 / 风控恢复三道闸门。内置违禁词表、外联词表、x5sec 恢复指引。被其它 skill 频繁引用。"
    },
    {
      "name": "goofish-publish-item",
      "source": "./skills/goofish-publish-item",
      "description": "从描述 / 图片到商品发布的闭环:类目识别 → 标题 5 段式生成 → 风控扫描 → 批量传图 → 用户确认 → 调 item_publish。"
    },
    {
      "name": "goofish-reply-buyer",
      "source": "./skills/goofish-reply-buyer",
      "description": "买家消息闭环:拉未读 → 意图分类 → 议价阶梯策略 → 风控扫描 → 用户确认发送。不托管发送权。"
    },
    {
      "name": "goofish-shop-diagnosis",
      "source": "./skills/goofish-shop-diagnosis",
      "description": "限流 / 降权 / 曝光掉的归因诊断。search_items 买家视角搜 + item_view 历史对比 → 给嫌疑排序和修复清单。"
    }
  ],
  "install": {
    "preferredMethod": "cli",
    "cli": {
      "command": "uvx",
      "args": ["--from", "goofish-cli", "goofish", "skills", "install"],
      "description": "运行 `uvx --from goofish-cli goofish skills install` 把所有 skill 复制到 ~/.claude/skills/。"
    },
    "manual": {
      "description": "也可以直接 clone 仓库并把 skills/ 下的任一目录拷到 ~/.claude/skills/。"
    }
  },
  "tags": ["xianyu", "goofish", "ecommerce", "automation", "mcp", "chinese"]
}
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 60 lines scan A b0fdc0b05695

Subscribe to this mod's changes

goofish-cli-skills marketplace is a plugin published in the GitHub repository fancyboi999/goofish-cli (143 stars, last pushed 14d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other plugins, from other repositories

shopify-plugin

Shopify developer tools for Claude Code — search Shopify docs, generate and validate GraphQL, Liquid, and UI extension code. Skill scripts send usage telemetry (queries, code, model/client identifiers) to shopify.dev by default; set OPTOUTINSTRUMENTATION=true, or create an empty file at /.config/shopify-ai-toolkit/o.

Shopify/Shopify-AI-Toolkit · not measured

jpm-payments-skills

Conversational agent skills that walk a merchant from J.P. Morgan Payments onboarding through a working API integration. Supports Checkout and Online Payments in the initial release. Generates language-specific OAuth modules (Node/TypeScript, Python, Java idiomatic; other languages via canonical algorithm).

jpmorgan-payments/pdp-skills · not measured

tray-api

Plugin completo para integração com as APIs da Tray. Acelera o desenvolvimento de aplicativos e-commerce por parceiros e comunidade na plataforma Tray, fornecendo documentação detalhada de todos os endpoints, fluxos de autenticação OAuth, webhooks e boas práticas de integração.

tray-tecnologia/tray-api-ai-plugin · not measured

small-business-ru marketplace

Plugin marketplace listing 3 plugins: small-business-ru, humanizer-ru, marketplaces-mcp-ru.

ilyautov/small-business-ru · not measured

a1-yandex-kit-skills marketplace

Plugin marketplace listing 1 plugin: a1-yandex-kit-skills.

ztemerbekov/a1-yandex-kit-skills · not measured

lightspeed-x

Read-only Lightspeed X (Retail POS) access: sales reporting, inventory, products, and customers. Ask for top sellers, revenue by store, margin by brand, or what needs reordering.

genvjacobc/lightspeed-x-mcp · not measured