T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:28- Finding
Temu access tokens are stored and disclosed in plaintext
- Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` The retrieval command prints the complete secret: ```python print( json.dumps( { "found": True, "storeKey": store_key, "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": token, }, indent=2, ensure_ascii=False, ) ) ``` The documented interface also places the token in a command-line argument: ```python Usage: python save_temu_access_token.py '{ "storeKey": "my-shop", "site": "cn", "managementType": "semi-managed", "tokenPurpose": "product-inventory", "accessToken": "PASTE_TOKEN_HERE", "label": "中国半托管主店" }' ``` ### Technical Analysis Temu access tokens are persisted directly in a JSON file without encryption and without explicitly enforcing owner-only file or directory permissions. The resulting access controls depend entirely on the process umask and preexisting directory permissions. The save interface accepts the token as command-line JSON. Depending on the operating system and shell configuration, this can expose the token through shell history, process listings, terminal recording, ...[truncated 1713 chars]- Remediation
View remediation
