Model or dataset
shaxiu/XianyuAutoAgent avatar
shaxiu/XianyuAutoAgent

XianyuAutoAgent: an LLM customer-service bot for Xianyu (Goofish) sellers

智能闲鱼客服机器人系统:专为闲鱼平台打造的AI值守解决方案,实现闲鱼平台7×24小时自动化值守,支持多专家协同决策、智能议价和上下文感知对话。

9,283 stars1,640 forksPythonGPL-3.0

At a glance

What is it?
XianyuAutoAgent is a Python agent that logs into Xianyu through a browser cookie, classifies buyer messages with an LLM, and routes them to price, tech or default reply prompts. It installs in a few commands, but the cookie dependency and the GPL-3.0 licence shape where it can be used.
Who is it for?
Adopt XianyuAutoAgent if you sell on Xianyu, already have an LLM API key, and accept that the bot authenticates with a browser cookie you must refresh yourself. Do not adopt it if you need a vendor to support the integration, if your workflow cannot tolerate a GPL-3.0 derivative, or if you sell on a platform other than Xianyu, since nothing in the repository abstracts the marketplace away.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 112 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What XianyuAutoAgent automates, and for whom

Xianyu is Alibaba's second-hand marketplace, known outside China as Goofish. Sellers there answer the same questions repeatedly: is it still available, will you ship today, can you go lower. The repository describes XianyuAutoAgent as an AI duty solution for that platform, offering 24/7 automated coverage, multi-expert decision routing, staged price negotiation and context-aware conversation. The intended user is a seller who already has an Xianyu listing and an LLM API key, not a developer building a general chatbot. The README's own framing is narrow: the project exists for one marketplace, and its authentication path is the web session of that marketplace rather than a documented public API. That narrowness is the point. A seller who wants replies handled while they sleep gets a single process that connects to Xianyu and answers, without writing an integration. The README also states plainly that the project is for learning and exchange, and that the team may stop updating or delete it at any time. Read that as a scope statement about support, not about code quality: the last push to the repository was on 2026-06-10, so the code has moved recently, but no release has been published and no support commitment is offered.

How the expert routing actually works

The mechanism is prompt routing, not a trained classifier. The README's feature table lists two engines: context awareness, implemented as stored session history that is passed to the LLM as input, and expert routing, described as intent recognition through prompt engineering followed by dynamic dispatch to an expert agent. In practice this means four prompt files under prompts/ do the work. classify_prompt.txt decides which expert a message belongs to. price_prompt.txt carries the negotiation behaviour, which the README calls a staged price-reduction strategy. tech_prompt.txt handles technical questions and, per the feature matrix, integrates web search. default_prompt.txt covers everything else. The data flow is therefore: a buyer message arrives, the stored conversation history plus the message goes to the model, the classification prompt picks a route, and the chosen expert prompt produces the reply. context_manager.py is the file that holds the history, and XianyuAgent.py and XianyuApis.py sit between the model and the marketplace connection. Two consequences follow. First, changing behaviour usually means editing a text file, not code, which is why the README documents the prompts directory as the customisation surface. Second, because routing is an LLM call on top of the reply call, every buyer message costs at least two model invocations, and a misclassification shows up as a wrong-tone reply rather than an error. The feature matrix marks sentiment analysis, market price comparison, RAG knowledge base enhancement, DingTalk integration and a web management interface as planned rather than implemented.

Install with pip and send your first automated reply

The README targets Python 3.8 or newer. Clone the repository, install the pinned dependencies, and create the environment file. The requirements file pins five packages: openai, websockets, loguru, python-dotenv and requests, each at a fixed version.

bash
git clone https://github.com/shaxiu/XianyuAutoAgent.git
cd XianyuAutoAgent
pip install -r requirements.txt

The environment file is the part that decides whether anything works. The README says to create a .env file or rename .env.example. The example file shows the keys and their defaults, including the Qwen endpoint and model name.

bash
API_KEY=apikey通过模型平台获取
COOKIES_STR=your_cookies_here
MODEL_BASE_URL=https://dashscope.aliyuncs.com/compatible-mode/v1
MODEL_NAME=qwen-max
TOGGLE_KEYWORDS=。
SIMULATE_HUMAN_TYPING=False

COOKIES_STR is the value that authenticates the bot to Xianyu. The README instructs you to obtain it from the Xianyu web client: open the browser console with F12, switch to Network, filter to Fetch/XHR, click a request, and read the cookies. API_KEY is described as coming from a model platform, and the README notes that the default model is Qwen and that other APIs require editing MODEL_BASE_URL and MODEL_NAME yourself. Before the first run, the prompt files must exist: the README says to create prompts/*_prompt.txt, or to remove the _example suffix from the template names, otherwise the four template files are read instead. Then start the process.

bash
python main.py

If you prefer containers, the repository ships a Dockerfile and a docker-compose.yml. The compose file references the image shaxiu/xianyuautoagent:latest, mounts ./data, ./prompts and ./.env into the container, sets TZ to Asia/Shanghai, and uses restart: always. The Dockerfile builds on python:3.10-alpine and copies the four _example prompt files into their non-example names at build time, so a container start does not need that manual rename. What you should see after python main.py is log output from loguru; the README's screenshots show a backend log, but the repository does not document the exact log lines, so do not expect a specific banner.

The cookie is the failure mode, and it is not documented as recoverable

XianyuAutoAgent does not authenticate through an API key issued by the marketplace. It reuses your browser session cookie, and the README's only guidance is how to copy that value out of the developer console. Session cookies expire, and they are invalidated when the account logs out or the platform rotates them. The README does not document what happens when COOKIES_STR goes stale: there is no described re-authentication flow, no refresh token, no health check, and no rollback procedure. The practical result is that the bot can stop answering without a clear signal, and the operator has to notice and paste a new cookie. That is a design trade-off rather than a bug, but it belongs in your decision: an unattended 24/7 duty bot whose credentials require periodic manual replacement is not fully unattended. A second boundary is the platform itself. The README's notice says the project is for learning and exchange, and the repository gives no statement about whether automated replies comply with Xianyu's terms. Anyone running this against live buyer traffic should treat that as an open question rather than assume the project has settled it. Finally, the bot is the wrong tool outside Xianyu. Nothing in the repository layout abstracts the marketplace: XianyuApis.py and XianyuAgent.py are named for the platform, and the cookie flow is specific to its web client.

How it differs from a general LLM chat wrapper or a marketplace API client

The closest thing to an alternative in the repository is XianYuApis, the project by cv-cat that the README credits under acknowledgements and thanks for technical support. That project is an API layer: it exposes the Xianyu platform's endpoints. XianyuAutoAgent sits above that layer and adds the decision logic, which is why the README describes it as an agent with expert routing rather than a client library. The difference matters when you choose. If you want to build your own reply logic, an API client gives you the transport and leaves the policy to you. If you want the policy already written as editable prompts, with classification, staged bargaining and a manual-takeover keyword, XianyuAutoAgent is the higher-level option and the one that makes assumptions about tone and negotiation on your behalf. The other comparison worth drawing is against a generic LLM chat wrapper. A wrapper sends text to a model and returns text. XianyuAutoAgent adds three things a wrapper does not have: a persistent conversation history fed back as context, a routing step that selects among four prompt roles, and a toggle keyword that hands the conversation to a human. The cost of those additions is that the behaviour is spread across prompt files, so debugging a bad reply means reading the classification prompt and the expert prompt together.

Licence and the cost of staying current

The repository is licensed GPL-3.0. That is a copyleft licence, and it is the single most consequential fact for anyone considering a commercial deployment. If you modify XianyuAutoAgent and distribute it, or run a modified version as a network service in a way the licence treats as distribution, the GPL-3.0 obligations attach to your version. The project does not offer a separate commercial licence or a contributor licence agreement in the repository. This is a description of the licence text and not legal advice; if you plan to build a paid service on top of it, have someone qualified read GPL-3.0 against your specific deployment. On maintenance, the repository is not archived, and the last push was on 2026-06-10, which is recent enough that the code is moving. But there are no published releases, so upgrading means tracking the main branch rather than pinning a version. The dependency set is small and fully pinned in requirements.txt, which limits surprise breakage from transitive updates, and the Docker path pins python:3.10-alpine. The heavier upgrade cost is not code: it is the prompt files. If you customise classify_prompt.txt, price_prompt.txt, tech_prompt.txt and default_prompt.txt, a future change to how routing works will require you to re-read your own edits against the new templates. The README's notice that the team may stop updating or delete the project at any time should be read alongside that.

Editorial conclusion

Adopt XianyuAutoAgent if you sell on Xianyu, already have an LLM API key, and accept that the bot authenticates with a browser cookie you must refresh yourself. Do not adopt it if you need a vendor to support the integration, if your workflow cannot tolerate a GPL-3.0 derivative, or if you sell on a platform other than Xianyu, since nothing in the repository abstracts the marketplace away. Before trusting it with real buyers, verify four things on your own account: that your cookie still produces a live session after a restart, that the toggle keyword in TOGGLE_KEYWORDS actually flips the bot out of AI mode, that your edited prompts under prompts/ are the ones being loaded, and what the staged price floor in price_prompt.txt does when a buyer pushes below it.

Frequently asked questions

How do I install XianyuAutoAgent?

Clone the repository, run pip install -r requirements.txt, create a .env file with API_KEY, COOKIES_STR, MODEL_BASE_URL and MODEL_NAME, make sure the prompt files under prompts/ exist, then run python main.py. A Dockerfile and docker-compose.yml are also provided if you prefer containers.

Where does XianyuAutoAgent get the cookie it needs?

The README says to copy it from the Xianyu web client: press F12, open the console, go to Network, filter to Fetch/XHR, click a request, and read the cookies value into COOKIES_STR. The repository does not document what happens when that cookie expires.

Can I use XianyuAutoAgent with a model other than Qwen?

Yes. The README states that the default model is Qwen and that using another API requires editing MODEL_BASE_URL and MODEL_NAME in the .env file yourself. The example file ships with the DashScope compatible-mode endpoint and qwen-max.

How do I switch XianyuAutoAgent between AI replies and a human?

The TOGGLE_KEYWORDS setting controls this, and the example file sets it to the full stop character. According to the README, sending that keyword switches the conversation to manual takeover, and sending it again switches back to AI.

Official sources

  1. Issues
  2. License: GPL-3.0
  3. README
  4. shaxiu/XianyuAutoAgent on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/shaxiu-xianyuautoagent.svg)](https://hysenlabs.com/projects/shaxiu-xianyuautoagent)