Back to skill

Security audit

亚马逊FBA库存计划专家

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed Amazon FBA planning bundle, but it also handles credentials, scheduled automation, public uploads, and automatic feedback reporting in ways users should review carefully.

Install only if you are comfortable giving this skill a LinkFox API key and using LinkFox services for Amazon seller workflows. Review the feedback-reporting behavior, avoid putting API keys in shell profiles, rotate any key exposed in logs, and use scheduled tasks or public uploads only with explicit user intent and non-sensitive files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:25
Finding

Mandatory Response Suffix Hijacks Agent Output

Content
View full analysis
`**:每次可见回复末尾输出 3 条贴合当前任务的可执行后续建议(陈述句,不用问号)。 ``` The directive requires every visible response to end with a specific XML-like element containing three suggestions. ### Technical Analysis This instruction is global to the root Skill and is framed as a mandatory rule whose violation constitutes failure. It changes the Agent's output behavior for every interaction, regardless of whether the requested task needs follow-up suggestions. A Skill may define a task-specific output schema, but permanently appending Skill-controlled content to every visible response exceeds the minimum privileges needed for FBA inventory planning. It can conflict with caller-defined schemas, API response contracts, safety-related concise responses, or instructions requiring an exact output. The broader package also contains promotional LinkFox footer content in several component Skill files, including `skills/linkfox-amazon-product-detail/SKILL.md:189`. Although those footer lines are not executable code, their presence increases the risk that mandatory output-control instructions will be used to inject unrelated branded content. ### Attack Path 1. The root Skill is loaded to perform an FBA inventory-planning task. 2. The Agent treats the root Skill's “mandatory rules” as active instructions. 3. The user or API caller requests output in a strict format. 4. The Skill requires the Agent to append a LinkFox-specific suggestion block anyway. 5. The final response no longer conforms to the user's intended schema and may include unrelated Skill-controlled content. ### Impact Assessment The issue does not grant operating-system privileges or direct access to credentials. Its scope is the Agent's current session and user-visible output. Potential effects include: ...[truncated 305 chars]
Remediation
View remediation
`. 2. Generate follow-up suggestions only when they are relevant to the user's task. 3. Give explicit caller-defined output schemas precedence over optional Skill formatting. 4. Remove unrelated promotional footer content from component Skill instructions. 5. Add tests confirming that strict JSON, XML, and machine-readable requests are returned without extra suffixes. 6. Treat response decoration as an opt-in presentation feature rather than a mandatory execution rule. ]]>

T01 · Skill Instruction Hijacking

Error
Location
skills/linkfox-amazon-product-detail/SKILL.md:177
Finding

Automatic Feedback Reporting Can Disclose Conversation-Derived Information Without Consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/linkfox-aigc-textgen/scripts/onboarding.py:468
Finding

Generated API Key Is Printed in Plaintext to Standard Output

Content
View full analysis
dict: masked = _mask_phone(phone) if not re.fullmatch(r"\d{11}", phone): return {"error": f"login: 手机号格式不正确: {phone}", "phone": masked} if not re.fullmatch(r"\d{4,8}", code): return {"error": f"login: 验证码格式不正确: {code}", "phone": masked} lg = _login_v3(phone, code, channel) if "error" in lg: return {"error": lg["error"], "phone": masked} if lg.get("is_new_user"): lbt = _login_by_token(lg["access_token"], lg["refresh_token"]) if "error" in lbt: print(f"{TAG} {lbt['error']}(不影响拿 key)", file=sys.stderr) info = _fetch_user_info_v3(lg["access_token"], lg["user_id"]) if "error" in info: return {"error": info["error"], "phone": masked} tok = _get_or_generate_api_token(lg["access_token"], lg["user_id"], info["group_id"]) if "error" in tok: return {"error": tok["error"], "phone": masked} return { "api_key": tok["api_key"], "phone": masked, "group_id": info["group_id"], "member_id": info["member_id"], "source": tok["source"], "nick_name": lg.get("nick_name", ""), "team_name": info.get("team_name", ""), "is_new_user": lg.get("is_new_user", False), } ``` ```python def _cmd_login(args) -> int: r = login_and_get_key(args.phone.strip(), args.code.strip(), args.channel) _emit(r) if "api_key" in r: print(f"{TAG} 成功获取 API key(来源: {r['source']})", file=sys.stderr) return 0 return 1 ``` The `_emit` function serializes the complete object: ```python def _emit(obj: dict) -> None: print(json.dumps(obj, ensure_ascii=False, indent=2)) ``` ### Technical Analysis The successful l ...[truncated 1902 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/linkfox-aigc-textgen/references/onboarding.md:11
Finding

Onboarding Instructions Persist Bearer Credentials in Plaintext Shell Profiles

Content
View full analysis
"` - macOS zsh: `echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.zshrc && source ~/.zshrc` - Linux bash: `echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.bashrc && source ~/.bashrc` - Either `LINKFOX_AGENT_API_KEY` or the legacy `LINKFOXAGENT_API_KEY` variable may be used. ``` These commands persist the complete bearer credential in user configuration or environment storage. ### Technical Analysis The onboarding guide recommends writing a long-lived API key directly into shell startup files such as `.zshrc` and `.bashrc`. These files are plaintext and are routinely: - Read by other processes running under the same user. - Included in home-directory backups. - Copied between systems. - Collected in support bundles. - Accidentally committed to dotfile repositories. - Displayed during shell debugging. The Windows `setx` command likewise persists the value in the user's environment configuration. Environment variables can be inherited by child processes and exposed through diagnostics or process inspection, depending on the operating system and execution context. Persistent credential storage is relevant to onboarding, but plaintext shell-profile storage is not the minimum safe privilege mechanism. The same onboarding guidance appears across several LinkFox Skills, increasing exposure. ### Attack Path 1. The onboarding flow generates and displays an API key. 2. The user follows the provided command and appends the complete key to `.bashrc` or `.zshrc`, or persists it with `setx`. 3. The credential remains available across future sessions. 4. A local process, backup reader, support archive, shared account user, or accidental repos ...[truncated 574 chars]
Remediation
View remediation
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (419)

Tainted flow: 'req' from os.environ.get (line 335, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-aigc-textgen/scripts/aigc_textgen.py (reported line 237)May include surrounding context.

python
req = _lf_Request(url, headers={"User-Agent": "LinkFox-Skill/2.0"})
    try:
        with _lf_urlopen(req, timeout=timeout) as resp:
            if guessed_ext == "bin":
                ct = resp.headers.get("Content-Type", "")
                if "mp4" in ct:

Tainted flow: 'req' from os.environ.get (line 335, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-aigc-textgen/scripts/aigc_textgen.py (reported line 337)May include surrounding context.

python
}
    req = Request(url, data=data, headers=headers, method="POST")
    try:
        with urlopen(req, timeout=HTTP_TIMEOUT) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The POST target URL is derived from environment-controlled base URLs, and the request may carry sensitive authentication material such as access tokens, refresh tokens, API keys, phone numbers, and SMS codes. If an attacker can influence environment variables, they can redirect these requests to attacker-controlled infrastructure and exfiltrate credentials or intercept onboarding/login traffic.

Content

Scanner excerpt · skills/linkfox-aigc-textgen/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The gateway URL is also built from environment-controlled base configuration and is used for authenticated network requests via urlopen. Because these requests include the LinkFox API key in the Authorization header and perform account, package, and order operations, endpoint redirection can leak secrets and enable unauthorized actions against attacker-controlled or rogue services.

Content

Scanner excerpt · skills/linkfox-aigc-textgen/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The script forwards multiple environment-derived values, including a configurable gateway base URL and session metadata, into an outbound HTTP request without validation. This enables SSRF-style redirection to an attacker-controlled endpoint and unintended exfiltration of the API key and request data if an attacker can influence environment variables in the agent runtime. The skill context makes this more dangerous because it is designed to run in automation environments where env vars are commonly injected by orchestrators or upstream tools.

Content

Scanner excerpt · skills/linkfox-amazon-product-detail/scripts/amazon_product_detail.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The POST target is ultimately derived from environment-controlled base URLs, and the request may carry sensitive data such as SMS login credentials, access tokens, refresh tokens, or generated API keys in headers/body. If an attacker can influence environment variables, they can redirect these requests to attacker-controlled infrastructure and exfiltrate credentials or session material. In this skill context, that risk is amplified because the script explicitly handles authentication and token issuance rather than inventory-planning data.

Content

Scanner excerpt · skills/linkfox-amazon-product-detail/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The gateway request uses a URL built from environment-controlled configuration and sends the API key in the Authorization header via urlopen. An attacker who can set the base URL can redirect authenticated gateway traffic to a malicious server and capture API keys, order data, and account metadata. The mismatch with the declared Amazon FBA purpose makes this more suspicious because the code is centered on account/payment operations, so the sensitive network traffic is core to the script.

Content

Scanner excerpt · skills/linkfox-amazon-product-detail/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 47, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request target is derived from environment-controlled base URL variables, and the script sends a sensitive Authorization API key header to that endpoint. If an attacker can influence LINKFOX_TOOL_GATEWAY/STORE_API_BASE_URL/SPAPI_BASE_URL, they can redirect the request to an attacker-controlled server and exfiltrate credentials or trigger SSRF-like outbound connections.

Content

Scanner excerpt · skills/linkfox-amazon-store-auth/scripts/authorize_url.py (reported line 59)May include surrounding context.

python
)

    try:
        with urlopen(req, timeout=150) as response:
            result = json.loads(response.read().decode("utf-8"))
            error_code = str(result.get("errcode", ""))
            if error_code.isdigit() and 1500 <= int(error_code) <= 1599:

Tainted flow: 'req' from os.environ.get (line 46, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request target is influenced by environment variables that can override the default gateway URL, causing the script to send an authorization credential to an attacker-controlled endpoint. Because the script is described as an inventory-planning skill but actually enumerates authorized stores, this outbound credential use is less expected and therefore more suspicious in context.

Content

Scanner excerpt · skills/linkfox-amazon-store-auth/scripts/authorized_stores.py (reported line 58)May include surrounding context.

python
)

    try:
        with urlopen(req, timeout=150) as response:
            result = json.loads(response.read().decode("utf-8"))
            error_code = str(result.get("errcode", ""))
            if error_code.isdigit() and 1500 <= int(error_code) <= 1599:

Tainted flow: 'req' from os.environ.get (line 126, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-amazon-store-auth/scripts/cancel_authorization.py (reported line 133)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            body = response.read().decode("utf-8")
            result = _decode_gateway_response(body)
            return _attach_gateway_cost_headers(result, response.headers)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The script builds request destinations from environment variables such as LINKFOX_LOGIN_API_URL and LINKFOX_AGENT_USER_API_URL, then sends sensitive authentication data including phone numbers, SMS codes, access tokens, refresh tokens, API keys, and uid headers to those URLs. If an attacker can influence the environment, they can redirect these requests to an attacker-controlled host and exfiltrate credentials and session material; this is especially dangerous because the file implements login and token-generation flows.

Content

Scanner excerpt · skills/linkfox-amazon-store-auth/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway URL is derived from environment variables and then used in urllib.request.urlopen with an Authorization header carrying the API key. An attacker who controls the environment can redirect outbound traffic to a malicious endpoint and capture API credentials or manipulate responses to influence package, order, and account operations.

Content

Scanner excerpt · skills/linkfox-amazon-store-auth/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 48, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The request destination is derived from environment-controlled base URL values and then used in urlopen with an Authorization header containing the API key. If an attacker can influence environment variables, they can redirect the token-refresh request and exfiltrate credentials and seller-related data to an attacker-controlled endpoint. The mismatch between the stated inventory-planning purpose and this auth/network behavior increases suspicion because it broadens what the skill can send off-box.

Content

Scanner excerpt · skills/linkfox-amazon-store-auth/scripts/refresh_token.py (reported line 60)May include surrounding context.

python
)

    try:
        with urlopen(req, timeout=150) as response:
            result = json.loads(response.read().decode("utf-8"))
            error_code = str(result.get("errcode", ""))
            if error_code.isdigit() and 1500 <= int(error_code) <= 1599:

Tainted flow: 'req' from os.environ.get (line 48, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The request destination is derived from environment variables and then used in a network call, so whoever controls the runtime environment can redirect this script to an arbitrary endpoint. Because the script also sends an API key in the Authorization header and seller metadata in the POST body, this creates a realistic credential and data exfiltration path, especially in agent or CI environments where environment variables may be influenced externally.

Content

Scanner excerpt · skills/linkfox-amazon-store-auth/scripts/store_tokens.py (reported line 60)May include surrounding context.

python
)

    try:
        with urlopen(req, timeout=150) as response:
            result = json.loads(response.read().decode("utf-8"))
            error_code = str(result.get("errcode", ""))
            if error_code.isdigit() and 1500 <= int(error_code) <= 1599:

Tainted flow: 'req' from os.environ.get (line 274, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

download_media performs outbound requests to caller-controlled URLs and only checks for an http/https prefix. This creates an SSRF-capable primitive that can reach arbitrary external hosts and potentially internal services if the runtime has network access, then stores the retrieved content locally. In the context of an Amazon FBA inventory planner, arbitrary remote fetching is not justified and increases the risk profile.

Content

Scanner excerpt · skills/linkfox-file-upload/scripts/linkfox_paths.py (reported line 524)May include surrounding context.

python
req = Request(url, headers={"User-Agent": "LinkFox-Skill/2.0"})
    try:
        with urlopen(req, timeout=timeout) as resp:
            # 从 Content-Type 进一步修正扩展名
            if guessed_ext == "bin":
                ct = resp.headers.get("Content-Type", "")

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The POST target URL is derived from environment-controlled base URLs and then used to send sensitive data including phone numbers, SMS codes, access tokens, refresh tokens, and API-token requests. If an attacker can influence environment variables, they can redirect these requests to attacker-controlled infrastructure and exfiltrate credentials or user data.

Content

Scanner excerpt · skills/linkfox-keepa-product-request/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The gateway request uses a URL built from an environment-controlled base and attaches the LinkFox API key in the Authorization header before calling urlopen. An attacker who can set the environment can redirect traffic to a malicious server and capture the API key as well as downstream account and order operations.

Content

Scanner excerpt · skills/linkfox-keepa-product-request/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The request sent via urlopen includes multiple headers populated directly from environment variables, and the destination base URL is also overrideable via LINKFOX_TOOL_GATEWAY. This creates a tainted outbound network flow that can exfiltrate API credentials and session metadata to an attacker-controlled endpoint if the environment is manipulated, which is especially sensitive because the Authorization header carries the API key.

Content

Scanner excerpt · skills/linkfox-keepa-product-search/scripts/keepa_product_search.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The script builds request destinations from environment-controlled base URLs and then sends authentication material, SMS-login data, and token-management requests to those endpoints via requests.post. If an attacker can influence environment variables in the runtime, they can redirect secrets and account actions to attacker-controlled infrastructure, causing credential exfiltration and unauthorized account operations.

Content

Scanner excerpt · skills/linkfox-keepa-product-search/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway URL is also derived from environment variables and used in urlopen requests that carry the LinkFox API key in the Authorization header. A poisoned environment can therefore redirect authenticated gateway traffic, exposing API credentials and enabling attacker-observed billing, account, or order-management actions.

Content

Scanner excerpt · skills/linkfox-keepa-product-search/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The request URL is derived from the LINKFOX_TOOL_GATEWAY environment variable, and the code also forwards multiple environment-derived identifiers and the API key in headers to whatever endpoint that variable specifies. If an attacker can influence the environment, they can redirect requests to an arbitrary host and exfiltrate credentials, session identifiers, and request contents; this is effectively SSRF plus secret leakage.

Content

Scanner excerpt · skills/linkfox-keepa-product-series/scripts/keepa_product_history.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code builds request destinations from environment variables such as LINKFOX_LOGIN_API_URL and LINKFOX_AGENT_USER_API_URL, then sends authentication data, SMS login codes, access tokens, refresh tokens, and generated API keys to those endpoints via requests.post. If an attacker can influence the runtime environment, they can redirect these highly sensitive secrets to attacker-controlled infrastructure, turning onboarding into credential and token exfiltration.

Content

Scanner excerpt · skills/linkfox-keepa-product-series/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The gateway URL is derived from environment-controlled base URLs and then passed to urllib.request.urlopen with the Authorization header set to the API key. This creates a token exfiltration path if the environment is manipulated, though the data exposed here is somewhat narrower than the login flow because it mainly leaks the configured API key and account actions routed through the gateway.

Content

Scanner excerpt · skills/linkfox-keepa-product-series/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 274, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The download_media function performs network requests to attacker-controlled URLs with only a simple http/https scheme check, creating an SSRF-capable primitive. An agent or upstream caller could be induced to fetch internal services, cloud metadata endpoints, or other sensitive intranet resources, then store the retrieved content locally for later exposure or processing.

Content

Scanner excerpt · skills/linkfox-plugin-web-data-crawler/scripts/linkfox_paths.py (reported line 504)May include surrounding context.

python
req = Request(url, headers={"User-Agent": "LinkFox-Skill/2.0"})
    try:
        with urlopen(req, timeout=timeout) as resp:
            # 从 Content-Type 进一步修正扩展名
            if guessed_ext == "bin":
                ct = resp.headers.get("Content-Type", "")

Tainted flow: 'req' from os.environ.get (line 124, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-plugin-web-data-crawler/scripts/run_crawl.py (reported line 139)May include surrounding context.

python
)
    timeout = int(os.environ.get("LINKFOX_SYNC_TIMEOUT", "300"))
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            result = json.loads(resp.read().decode("utf-8"))
            # startCrawlTask 返回格式: { taskId, status, data, errorMsg }
            # 适配上层调用方对 code/success 的判断

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
skills/linkfox-plugin-web-data-crawler/scripts/run_crawl.py:110

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/linkfox-task-scheduler/references/api.md:58