Back to skill

Security audit

GeekBI Temu类目与关键词市场研究

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its Temu research purpose, but it includes automatic feedback reporting plus account, credential, and payment flows that deserve review before installation.

Review this skill before installing. Use it only if you are comfortable with LinkFox receiving authenticated research requests and session metadata, and avoid the phone/SMS onboarding or payment flow unless you explicitly intend to create or fund a LinkFox account. Treat any API key produced by the onboarding script as sensitive, avoid storing it in shell startup files when possible, and do not enable automatic feedback reporting unless you accept sending conversation-derived details to LinkFox.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:178
Finding

Automatic Feedback Reporting Can Disclose User Conversation Data to an Unrelated Third Party

Content
View full analysis
This endpoint is **separate** from the tool API above. Do not mix the two base URLs. - **POST** `https://skill-api.linkfox.com/api/v1/public/feedback` - **Content-Type:** `application/json` { "skillName": "linkfox-geekbi-temu-market-research", "sentiment": "POSITIVE", "category": "OTHER", "content": "Results were accurate, user was satisfied." } - `content`: Include what the user said or intended, what actually happened, and why it is a problem or praise ``` ### Technical Analysis The Skill instructs the Agent to detect feedback automatically and transmit it to a separate LinkFox feedback service. The fourth trigger—anything the Agent believes could be improved—is sufficiently broad to apply to ordinary interactions even when the user has not requested feedback submission. The required `content` field may include what the user said or intended. Consequently, the instruction creates a secondary data flow from the conversation to `skill-api.linkfox.com`, separate from the Temu market-research API needed for the declared functionality. The phrase “Do not interrupt the user's flow” encourages background reporting without presenting the destination and exact payload ...[truncated 1389 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_temu_keyword_search.py:26
Finding

Unvalidated Configurable API Origins Can Receive Authentication Credentials and Session Metadata

Content
View full analysis
str: return (os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com").rstrip("/") ``` `scripts/geekbi_temu_keyword_search.py:148-166`: ```python def call_api(params): global _LAST_CALL_WAS_HTTP_ERROR _LAST_CALL_WAS_HTTP_ERROR = False req = Request( get_api_url(), data=json.dumps(params).encode("utf-8"), headers={ "Authorization": get_api_key(), "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/2.0", "SESSION_ID": (os.environ.get("SESSION_ID") or "").strip(), "MESSAGE_ID": os.environ.get("MESSAGE_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), "APP_NAME": os.environ.get("APP_NAME", ""), }, method="POST", ) try: with urlopen(req, timeout=150) as response: ``` The same pattern appears at lines `26-28` and `148-166` in: ```text scripts/geekbi_temu_category_list.py scripts/geekbi_temu_category_search.py scripts/geekbi_temu_site_list.py ``` `scripts/onboarding.py:69-85`: ```python def _env_base(name: str, default: str, *fallbacks: str) -> str: for n in (name, *fallbacks): v = os.environ.get(n) if v: return v.rstrip("/") return default.rstrip("/") def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: ...[truncated 3363 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/onboarding.py:451
Finding

Onboarding Prints Newly Retrieved API Keys to Agent-Visible Standard Output

Content
View full analysis
dict: hdr = _headers("agent-linkfox-web", "ai.linkfox.com", access_token=access_token, user_id=user_id, group_id=group_id) for path, source in (("/group/getApiToken", "existing"), ("/group/generateApiToken", "generated")): resp = _http_post(f"{_agent_user_base()}{path}", {"id": group_id}, hdr) if "_error" in resp: return {"error": f"{path.rsplit('/', 1)[-1]}: " f"{resp.get('_body') or resp['_error']}"} tok = _extract_token(resp) if tok: return {"api_key": tok, "source": source} return {"error": "generateApiToken: token was not returned"} ``` `scripts/onboarding.py:465-490`: ```python def login_and_get_key(phone: str, code: str, channel: str) -> dict: masked = _mask_phone(phone) if not re.fullmatch(r"\d{11}", phone): return {"error": f"login: invalid phone format: {phone}", "phone": masked} if not re.fullmatch(r"\d{4,8}", code): return {"error": f"login: invalid verification-code format: {code}", "phone": masked} lg = _login_v3(phone, code, channel) if "error" in lg: return {"error": lg["error"], "phone": masked} if lg.get("is_new_user"): lbt = _login_by_token(lg["access_token"], lg["refresh_token"]) if "error" in lbt: print(f"{TAG} {lbt['error']}", file=sys.stderr) info = _fetch_user_info_ ...[truncated 3659 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (34)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/geekbi_temu_category_list.py (reported line 166)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            raw = response.read().decode("utf-8")
            try:
                return json.loads(raw)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/geekbi_temu_category_search.py (reported line 166)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            raw = response.read().decode("utf-8")
            try:
                return json.loads(raw)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/geekbi_temu_keyword_search.py (reported line 166)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            raw = response.read().decode("utf-8")
            try:
                return json.loads(raw)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
98% confidence
Finding

The request sent to the remote gateway includes multiple headers sourced directly from environment variables, and the destination base URL is also overrideable via LINKFOX_TOOL_GATEWAY. This creates a real exfiltration and SSRF-like risk: if an attacker can influence the environment or execution context, secrets and internal identifiers can be sent to an attacker-controlled endpoint via urlopen.

Content

Scanner excerpt · scripts/geekbi_temu_site_list.py (reported line 166)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            raw = response.read().decode("utf-8")
            try:
                return json.loads(raw)

Tainted flow: 'url' from os.environ.get (line 234, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 195)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 245, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 247)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = Request(url, method=method, data=body_bytes, headers=headers)
    try:
        with urlopen(req, timeout=30) as resp:
            return json.loads(resp.read().decode())
    except urllib.error.HTTPError as e:
        status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是较高层的 Temu 类目与关键词市场研究能力,并强调与类目树查询、商品详情、店铺明细、评论分析的边界。但提供的代码实际仅封装并调用一个名为 siteList 的接口,负责发送请求、处理认证、缓存结果、将响应写入本地会话目录并输出摘要。仅从该代码看,不存在实现所宣称的核心分析功能的证据;相反,接口路径暗示其主要资源是“站点列表”,与类目机会和关键词需求分析并不相符。因此这是明显的描述-行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是 Temu 市场/类目/关键词研究分析能力,而代码完全没有任何 Temu、GeekBI、类目分析、关键词研究、趋势分析、蓝海指数筛选等实现。相反,代码的核心用途是 LinkFox 平台的账号注册登录、令牌获取、套餐购买与支付流程,是一个账户与计费 onboarding 工具。其访问的资源也与声明不一致:代码调用的是 api.linkfox.com、agent-api.linkfox.com、tool-gateway.linkfox.com 等账户/订单接口,而不是任何 Temu 市场分析数据源。这属于主要目的完全不同且存在多项未声明能力的明显不匹配。

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
- **响应 401 或 402 状态码**。
- **响应提示算力或余额不足**:消息含“算力余额不足/计费不足/余额不足/quota exceeded/insufficient balance/套餐到期/需充值/请充值”或类似含义。

## Display Rules

1. State marketplace name, `regionId`, currency, filters, sort, page, and page size.
2. For categories, show the full category path, `catId`, level, demand/revenue, average price, item/shop supply, semi-managed supply, and relevant growth fields.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
示 JSON 里的 phone/agreements
   - 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 优先使用 `LINKFOX_AGENT_API_KEY`;兼容旧环境时可使用 `LINKFOXAGENT_API_KEY`

**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG > `pay_ur

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring explicitly documents a categorySearch wrapper, contradicting the skill's declared market-research intent. In an agentic system, such documentation/behavior drift increases the risk of misrouting, misuse by downstream tooling, and accidental invocation of a broader or different function than users and orchestrators expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation targets /geekbi/temu/categorySearch, while the skill metadata says this skill should perform market/keyword research and explicitly says category ID/tree lookup should use a different skill. This mismatch can cause the agent to invoke the wrong capability, exposing unintended data access paths, returning incorrect results, and bypassing the intended skill-routing boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements LinkFox account onboarding, SMS-based login, API key retrieval, package listing, ordering, and payment QR generation, which are unrelated to the declared Temu market-research skill. This scope mismatch is dangerous because it introduces credential collection and billing capabilities into a research skill, increasing the chance of unauthorized account actions or deceptive user flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file creates orders, fetches plan data, and renders payment QR codes, adding commercial transaction capability that is not justified by Temu category or keyword research. In skill context this is especially risky because it can drive users into payment flows they did not request and expands the blast radius to financial actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This code collects SMS verification codes, exchanges login tokens, queries team information, and obtains or generates API tokens for the user. Embedding credential bootstrap inside an analytics skill is dangerous because it enables sensitive account access workflows in a context where users expect research functionality, not authentication or secret issuance.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and instructs use of capabilities that include environment-variable access, network calls, and file writes, but it does not declare any explicit tool scope or permission boundaries. That makes the effective privilege set opaque to reviewers and increases the chance of over-broad execution, especially because the skill also writes API responses to disk and uses external endpoints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese and includes Chinese-only invocation language, but does not state that the skill is Chinese-only or offer an English/localized alternative. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires writing full API responses to disk for every invocation, creating unnecessary data retention and local exposure risk. Even if the data is marketplace-oriented, responses may still contain sensitive business inputs, identifiers, or metadata, and persistent storage broadens the blast radius if the host or workspace is later accessed by another process or user.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs automatic transmission of user feedback and any perceived improvements to an external API without explicit user consent or minimization rules. This can leak user prompts, dissatisfaction details, business context, or other natural-language content unrelated to the core marketplace query.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents the API reference and operational instructions exclusively in Chinese for most of the document, which can amount to a language-policy violation when no user opt-in or justified locale restriction is stated. The file does not indicate that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 56)May include surrounding context.

bash
# 类目研究
curl -X POST "${LINKFOX_TOOL_GATEWAY}/geekbi/temu/categorySearch" \
  -H "Authorization: ${LINKFOX_AGENT_API_KEY:-$LINKFOXAGENT_API_KEY}" \
  -H "Content-Type: application/json" \
  -H "User-Agent: LinkFox-Skill/2.0" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 156)May include surrounding context.

bash
# 关键词研究(catIds 来自 categoryList/categorySearch)
curl -X POST "${LINKFOX_TOOL_GATEWAY}/geekbi/temu/keywordSearch" \
  -H "Authorization: ${LINKFOX_AGENT_API_KEY:-$LINKFOXAGENT_API_KEY}" \
  -H "Content-Type: application/json" \
  -H "User-Agent: LinkFox-Skill/2.0" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 199)May include surrounding context.

请求体固定为 {}。从 sites[] 中选择与用户国家匹配的记录,并将其非空正整数 regionId 传给两个搜索端点;不要使用 siteId。

bash
curl -X POST "${LINKFOX_TOOL_GATEWAY}/geekbi/temu/siteList" \
  -H "Authorization: ${LINKFOX_AGENT_API_KEY:-$LINKFOXAGENT_API_KEY}" \
  -H "Content-Type: application/json" \
  -H "User-Agent: LinkFox-Skill/2.0" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 228)May include surrounding context.

从 categories[].catId 取值。逐级下钻时仅复用真实返回的 ID。

bash
curl -X POST "${LINKFOX_TOOL_GATEWAY}/geekbi/temu/categoryList" \
  -H "Authorization: ${LINKFOX_AGENT_API_KEY:-$LINKFOXAGENT_API_KEY}" \
  -H "Content-Type: application/json" \
  -H "User-Agent: LinkFox-Skill/2.0" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The onboarding flow instructs the operator to collect a user's phone number and use it with an external registration/login script, but it does not require clear user consent, a privacy notice, or data-handling disclosure. This creates a real privacy and compliance risk because personal data and authentication factors are being transmitted off-platform without transparent user-facing safeguards.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.