Back to skill

Security audit

Temu欧洲站-广告

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed Temu Ads gateway tool, but it handles seller credentials, payment flows, broad proxy calls, and persistent local storage with weak scoping safeguards.

Review carefully before installing. Use only in an isolated environment, avoid passing production Temu or LinkFox credentials unless you trust LinkFox and the local runtime, check that endpoint override environment variables are not set, do not use mask=false token listing in shared logs, and require explicit human confirmation before any ad deletion, pause, budget/ROAS change, or payment order.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:27
Finding

Temu Access Tokens Are Stored in Plaintext and Can Be Printed Unmasked

Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ```python for item in store.get("tokens", []): token = item.get("accessToken", "") if mask and token: shown = token[:6] + "..." + token[-4:] if len(token) > 12 else "***" else: shown = token tokens.append( { "site": item.get("site"), "managementType": item.get("managementType"), "tokenPurpose": item.get("tokenPurpose", "default"), "accessToken": shown, "updatedAt": item.get("updatedAt"), } ) ``` ```python def main(): mask = True if len(sys.argv) >= 2: try: params = json.loads(sys.argv[1]) mask = params.get("mask", True) except json.JSONDecodeError as e: print(f"Invalid parameter format: {e}", file=sys.stderr) sys.exit(1) print(json.dumps(list_stores(mask=mask), indent=2, ensure_ascii=False)) ``` ### Technical Analysis Reusable Temu seller access tokens are serialized directly into a plaintext JSON file. The save routine does not explicitly create the containing directory with owner-only permissions, create the token file with mode `0600`, reject symbolic links, or use atomic secure-file creation. The token-listing interface also a ...[truncated 1763 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:15
Finding

Environment-Controlled Service Endpoints Can Redirect Sensitive Credentials

Content
View full analysis
dict: return { "Authorization": linkfox_token, "Token": linkfox_token, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/1.0", } ``` ```python def call_temu_api( url: str, body: dict, timeout: int = 150, linkfox_params=None, ) -> dict: linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) try: with urlopen(req, timeout=timeout) as response: return json.loads(response.read().decode("utf-8")) ``` The onboarding service destinations are similarly configurable: ```python def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` ```python def _http_post(url: str, body: dict, headers: dict, timeout: int = 30) -> dict: try: _require_requests() except RuntimeError as e: return {"_error": str(e)} try: ...[truncated 2515 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/temu_eu_proxy.py:25
Finding

Generic Proxy, Download, and Billing Capabilities Exceed the Narrow EU Ads Function

Content
View full analysis
'", file=sys.stderr) sys.exit(1) params = load_json_arg(sys.argv) params.setdefault("site", DEFAULT_SITE) api_type = require_text(params, "type") result = parse_nested_body(eu_proxy_call(params, api_type)) emit_result(result, inline=lf_inline_flag()) ``` The multi-site proxy also forwards any type: ```python def build_request(params: dict) -> dict: site = validate_site(require_text(params, "site")) management_type = validate_management_type( require_text(params, "managementType") ) access_token = resolve_access_token(params) api_type = require_text(params, "type") body = { "site": site, "managementType": management_type, "accessToken": access_token, "type": api_type, } if "params" in params and params["params"] is not None: if not isinstance(params["params"], dict): print("Error: 'params' must be a JSON object.", file=sys.stderr) sys.exit(1) body["params"] = params["params"] return body ``` The signed-file helper forwards an arbitrary supplied URL: ```python def eu_file_download_call(params: dict, timeout: int = 150) -> dict: if "tokenPurpose" not in params and params.get("storeKey") and not params.get("accessToken"): params = dict(params) params.setdefault("tokenPurpose", DEFAULT_TOKEN_PURPOSE) from _temu_common import require_text site = str(params.get("site", DEFAULT_SITE)).strip().lower() or DEFAULT_SITE ...[truncated 3058 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:163
Finding

Onboarding Recommends Installing Unpinned Runtime Dependencies

Content
View full analysis
dict: try: import qrcode except ImportError: err = "Missing qrcode dependency; run: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError("Missing requests dependency; run: pip install requests") ``` ### Technical Analysis The onboarding script instructs users to install `qrcode`, `pillow`, and `requests` without fixed versions, hashes, a lockfile, or an explicitly trusted package index. Package resolution therefore depends on the user's current pip configuration and the latest package releases available at installation time. The reviewed Skill package does not itself download or execute a remote payload. The risk arises when users follow the runtime installation guidance: Python package installation may execute build backends or installation logic, and the effective dependency contents can change after the Skill audit. ### Attack Path 1. A user invokes onboarding in an environment where one of the optional packages is missing. 2. The script displays an unpinned `pip install` command. 3. The user or agent executes that command using the environment's configured package index. 4. A compromised index, dependency-confusion condition, compromised upstream release, or malicious future package version is selected. 5. Package build or installation code executes with the privileges of the user running pip. 6. The malicious dependency gains access to files, environment variables, and credentials available to that process. ### Impact Assessment Exploitation can ...[truncated 432 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (71)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code builds request destinations from environment-controlled base URLs and then sends sensitive data and authorization headers to them via requests.post. If an attacker can influence LINKFOX_LOGIN_API_URL or LINKFOX_AGENT_USER_API_URL in the runtime environment, they can redirect SMS login, access tokens, refresh tokens, and generated API keys to attacker-controlled infrastructure, causing credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway URL is derived from environment variables and used in urllib.request.urlopen together with the LinkFox API key in the Authorization header. An attacker who can control LINKFOX_AGENT_API_URL or LINKFOX_TOOL_GATEWAY can redirect authenticated requests to a malicious server and capture API keys, user/account metadata, and order operations.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Returning broad token authorization/setup guidance for multiple shop types and token purposes is not itself an exploit, but it is inconsistent with a narrowly scoped ads skill and encourages reuse of credentials across domains. That widens the operational surface and can lead to accidental over-privilege.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script is a generic credential-retrieval utility that returns whatever Temu access token matches user-supplied store, site, management type, and token purpose, rather than restricting retrieval to the skill's advertised EU Ads scope. In an agent-skill context, this broad token broker behavior can enable cross-scope credential access, including non-Ads tokens, which could let downstream tooling call unrelated APIs with stored credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This onboarding script includes login, package purchase, order creation, and payment QR generation capabilities that are unrelated to a Temu EU Ads API skill. In a skill context, bundling unrelated account monetization flows increases phishing and social-engineering risk because users may be induced to authenticate or pay outside the expected product scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file's primary behavior is LinkFox authentication, API-key retrieval, team/account discovery, and commerce workflows rather than Temu EU Ads actions. That mismatch makes the skill more dangerous because users invoking an ads skill may not expect credential issuance and subscription flows, which can facilitate deceptive credential collection and account takeover paths.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares network, environment-variable, and file-write behaviors but does not define an explicit tool scope such as allowed tools or permissions. In an agent environment, this weakens containment and can let a broadly triggered skill access sensitive tokens, write local data, and call external endpoints without a clear least-privilege boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger terms are broad enough to match common ad-related discussion, which can cause the skill to activate in contexts where the user did not clearly request networked API actions. Because the skill also has credential, file-write, and proxying behaviors, over-triggering materially increases the chance of unintended data access or external calls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest description is entirely written as Chinese-language operational guidance for the skill, and the file does not indicate that users may choose another language or locale. Under the stated policy, a fixed language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs always writing full API responses to session-linked local files, and those responses may contain access tokens, account identifiers, report data, or other sensitive business information. Persistent local storage increases exposure to later leakage through other tools, workspace sharing, backups, or accidental inclusion in prompts and commits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation describes a workflow that creates, modifies, pauses, and deletes live advertising objects, but it does not warn users that these operations can change spend, delivery, and campaign state in a production seller account. In an ads-management skill, omission of change-risk guidance increases the chance of accidental destructive or costly actions, especially if an agent automates the sequence without explicit confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill documents destructive ad operations including delete, pause, and budget/ROAS changes, but it does not instruct the agent to obtain explicit user confirmation or warn about irreversible business impact. In an agent setting, that omission can lead to accidental destructive changes to live advertising campaigns, especially when triggered from natural-language requests.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/apis/temu-searchrec-ad-modify.md (reported line 84)May include surrounding context.

├── success / errorCode / errorMsg └── result ├── successModifyProductNum (INTEGER) └── modifyGoodsRespList[] ├── goodsId, reason, success

text

Static analysis

No suspicious patterns detected.