T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:27- Finding
Temu Access Tokens Are Stored in Plaintext and Can Be Printed Unmasked
- Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ```python for item in store.get("tokens", []): token = item.get("accessToken", "") if mask and token: shown = token[:6] + "..." + token[-4:] if len(token) > 12 else "***" else: shown = token tokens.append( { "site": item.get("site"), "managementType": item.get("managementType"), "tokenPurpose": item.get("tokenPurpose", "default"), "accessToken": shown, "updatedAt": item.get("updatedAt"), } ) ``` ```python def main(): mask = True if len(sys.argv) >= 2: try: params = json.loads(sys.argv[1]) mask = params.get("mask", True) except json.JSONDecodeError as e: print(f"Invalid parameter format: {e}", file=sys.stderr) sys.exit(1) print(json.dumps(list_stores(mask=mask), indent=2, ensure_ascii=False)) ``` ### Technical Analysis Reusable Temu seller access tokens are serialized directly into a plaintext JSON file. The save routine does not explicitly create the containing directory with owner-only permissions, create the token file with mode `0600`, reject symbolic links, or use atomic secure-file creation. The token-listing interface also a ...[truncated 1763 chars]- Remediation
View remediation
