Back to skill

Security audit

Temu全球站-广告

Security checks for vulnerabilities and agentic risk

Overview

The skill mainly supports Temu ads through LinkFox, but it exposes broader account authority than the ads purpose suggests and handles tokens, full responses, and billing flows in ways users should review carefully.

Install only if you are comfortable giving this skill LinkFox and Temu seller-token access. Use least-privilege Temu tokens, check that LINKFOX_* gateway environment variables point to expected LinkFox domains, avoid placing tokens in shell history where possible, protect ~/.linkfox and project linkfox output files, and manually confirm any ad creation, deletion, budget/ROAS change, or payment order before running it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:28
Finding

Temu access tokens are stored and disclosed in plaintext

Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` The retrieval command prints the complete secret: ```python print( json.dumps( { "found": True, "storeKey": store_key, "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": token, }, indent=2, ensure_ascii=False, ) ) ``` The documented interface also places the token in a command-line argument: ```python Usage: python save_temu_access_token.py '{ "storeKey": "my-shop", "site": "cn", "managementType": "semi-managed", "tokenPurpose": "product-inventory", "accessToken": "PASTE_TOKEN_HERE", "label": "中国半托管主店" }' ``` ### Technical Analysis Temu access tokens are persisted directly in a JSON file without encryption and without explicitly enforcing owner-only file or directory permissions. The resulting access controls depend entirely on the process umask and preexisting directory permissions. The save interface accepts the token as command-line JSON. Depending on the operating system and shell configuration, this can expose the token through shell history, process listings, terminal recording, ...[truncated 1713 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:181
Finding

Full API responses are persisted using unsafe path and permission handling

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root fallback = os.path.abspath(candidates[-1]) _LF_SESSION_CACHE["_root"] = fallback return fallback ``` `SESSION_ID` is accepted without path validation: ```python def _lf_session_id(ts: float) -> str: env = os.environ.get("SESSION_ID") if env: return env.strip() if "_auto" not in _LF_SESSION_CACHE: _LF_SESSION_CACHE["_auto"] = ( _lf_time.strftime("%H%M%S", _lf_time.localtime(ts)) + "-" + _lf_secrets.token_hex(3) ) return _LF_SESSION_CACHE["_auto"] ``` Metadata and complete API responses are written without explicit restrictive modes: ```python wi ...[truncated 4413 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/onboarding.py:162
Finding

Onboarding recommends installation of unpinned third-party packages

Content
View full analysis
dict: try: import qrcode except ImportError: err = "缺少 qrcode 依赖,请运行: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ### Technical Analysis When QR dependencies are unavailable, the Skill instructs the user to install `qrcode` and `pillow` without fixed versions, hashes, a lockfile, or an explicitly trusted package index. The script does not automatically execute the installation command, which materially limits the risk. Exploitation requires the user or an Agent to follow the recommendation. Nevertheless, package installation executes package build or installation logic with the installing user's privileges, and the effective code can change independently of the reviewed Skill. Potential sources of compromise include a malicious or misconfigured package index, dependency substitution, future upstream compromise, or an unexpectedly unsafe package release. ### Attack Path 1. The user invokes the onboarding order command on a system where `qrcode` is not installed. 2. QR rendering returns an error recommending `pip install qrcode pillow`. 3. The user or supervising Agent executes the suggested command. 4. Pip resolves packages from the configured index without enforcing reviewed versions or hashes. 5. A compromised index, substituted package, or malicious upstream release supplies attacker-controlled installation or runtime code. 6. That code executes with the privileges of the user running pip or is later imported by `onboarding.py`. ### Impact Assessment Successful exploitation can execute arbitrary code with the privileges of the account that performs the package installation or ...[truncated 361 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (63)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The script builds login and agent-user URLs from environment variables and then sends highly sensitive data to them via requests.post, including phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys. If an attacker can influence the runtime environment, they can redirect these requests to an attacker-controlled endpoint and exfiltrate credentials or session tokens; this is especially dangerous because this file is an onboarding flow handling authentication material.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway URL is derived from environment variables and used by urllib.request.urlopen together with the Authorization header carrying LINKFOX API credentials. An attacker who can set LINKFOX_AGENT_API_URL or fallback variables can redirect authenticated gateway traffic, capturing API keys and manipulating package/order responses, which can lead to account abuse and fraudulent payment flows.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A universal proxy inside an ads-branded skill can forward arbitrary Temu API types beyond the declared ads scope. That is dangerous because it can bypass user expectations and policy segmentation, enabling access to broader partner APIs with the same credentials and gateway path.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements LinkFox account onboarding, SMS login, API key issuance, package discovery, and payment ordering, which are outside the declared Temu Global Ads API forwarding scope. Scope mismatch is dangerous in a skill because it expands the trust boundary and enables collection of user credentials and monetization actions unrelated to the advertised functionality, increasing the likelihood of deceptive behavior and abuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The order creation and QR payment rendering code enables direct monetization and payment collection inside a skill that is supposed to proxy Temu ads APIs. This is dangerous because it can steer users into purchasing unrelated services, and if combined with manipulated package data or endpoint redirection, it can facilitate fraudulent charges or social-engineering-based payment abuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code forwards a user-supplied 'type' and arbitrary 'params' to a shared proxy without enforcing that the requested API belongs to the advertised Temu Global Ads surface. In an agent setting, this creates a confused-deputy/overbroad-capability issue: a caller invoking an Ads skill can drive non-Ads Temu operations if they possess or can induce use of a valid access token.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents capabilities that involve environment access, network calls, and filesystem writes, but it does not declare an explicit tool/permission scope. That weakens containment and reviewability because an operator or runtime cannot easily enforce least privilege or confirm that the documented behavior matches the allowed capabilities.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs that every full API response must be written to project-local files, and those responses may contain access tokens, account identifiers, reports, or user-supplied sensitive business data. Persistent local logging of full responses substantially increases exposure through source trees, shared workspaces, backups, later tool access, or accidental commits.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation says the skill covers Ads APIs, but the listed utilities include saving, listing, and retrieving Temu tokens locally. This hidden secret-handling scope is dangerous because it normalizes credential persistence and access in a context where users expect ad operations, increasing the risk of accidental credential disclosure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is described as ads-limited, yet the documented gateway scripts are generic multi-site proxy and file-download tools. This weakens trust boundaries and makes it easier to invoke broader capabilities than intended, especially when combined with shared credentials and an undeclared universal proxy pattern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This documentation describes an operation that creates live ads with required budget and ROAS parameters, but it does not prominently warn that invoking the API can immediately create spend-bearing advertising objects. In an agent setting, that omission increases the risk of unintended financial actions if a user asks exploratory questions or the agent auto-completes an example into a real execution flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly supports destructive state-changing operations such as delete, pause, reopen, and budget/ROAS changes, but it does not instruct the agent or user to obtain clear confirmation before executing them. In an agent skill context, this raises the risk of accidental or prompt-induced destructive ad changes, especially because the skill is designed to act on advertising resources directly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/apis/temu-searchrec-ad-modify.md (reported line 84)May include surrounding context.

├── success / errorCode / errorMsg └── result ├── successModifyProductNum (INTEGER) └── modifyGoodsRespList[] ├── goodsId, reason, success

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/apis/temu-searchrec-ad-modify.md (reported line 102)May include surrounding context.

├── success / errorCode / errorMsg └── result ├── successModifyProductNum (INTEGER) └── modifyGoodsRespList[] ├── goodsId, reason, success

text

Static analysis

No suspicious patterns detected.