Back to skill

Security audit

Temu美国站-广告

Security checks for vulnerabilities and agentic risk

Overview

This Temu ads skill has useful advertised functions, but it also handles powerful credentials, payment-order creation, broad proxy calls, and persistent plaintext storage in ways users should review carefully.

Install only if you trust LinkFox and are comfortable giving this skill LinkFox and Temu credentials that can read or change ad settings and potentially create billing orders. Prefer per-session credentials or a secure credential manager, avoid committing `linkfox/` outputs or shell profiles, rotate exposed keys, and use the named ads scripts instead of the arbitrary proxy unless you intentionally need broader access.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_token_store.py:27
Finding

Temu Access Tokens Stored in Plaintext Without Restrictive Permissions

Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The data written by this function includes the complete Temu access token: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The Skill stores complete Temu merchant access tokens in `~/.linkfox/temu-access-tokens.json`. The file is created using the process's default umask and no explicit owner-only permission mode is enforced. The parent directory is also created without explicitly requiring mode `0700`. The implementation additionally performs a direct, non-atomic overwrite. It does not reject symbolic links or use an exclusive temporary file followed by an atomic rename. Consequently: - A permissive umask can make the token file readable by other local users. - Backups, support bundles, or filesystem indexing may capture the plaintext token. - A local attacker able to manipulate the token path may potentially redirect writes through a symbolic link. - A crash during the write can corrupt the credential store. Plaintext persistence is part of the declared token-reuse feature, but storing a merchant credential without operating-system credential protection or enforced filesystem permissions exceeds secure minimum handling requirements. ### Attack Path 1. A user runs `save_temu_access_token.py`, causing the complete Temu access token to be stored in the local JSON file. 2. The file is created u ...[truncated 1222 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_temu_access_token.py:48
Finding

Complete Temu Access Token Disclosed Through Standard Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/onboarding.py:487
Finding

Newly Issued LinkFox API Key Returned in Plaintext Output

Content
View full analysis
int: r = login_and_get_key(args.phone.strip(), args.code.strip(), args.channel) _emit(r) if "api_key" in r: print(f"{TAG} Successfully obtained API key", file=sys.stderr) return 0 return 1 ``` The actual source message in the repository is localized, but `_emit(r)` serializes the complete `api_key` value regardless of display language. ### Technical Analysis The onboarding flow obtains or generates a long-lived LinkFox API key and returns it in stdout JSON. The documentation further expects an Agent to relay that value to the user. This means the key can become part of the Agent's context and any associated logging or transcript-retention systems. Obtaining a key is relevant to LinkFox onboarding, but exposing the key through general-purpose stdout is not the minimum necessary approach. A safer implementation would install the credential directly into a protected store and return only confirmation. ### Attack Path 1. A user supplies a telephone number and SMS verification code to the onboarding command. 2. The script authenticates to LinkFox and obtains or generates an API key. 3. `login_and_get_key` includes the full key in the returned dictionary. 4. `_cmd_login` serializes the dictionary to stdout. 5. The key is captured in an Agent tool result, terminal lo ...[truncated 984 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/onboarding.md:12
Finding

Documentation Encourages Persistent API-Key Storage in Shell Startup Files

Content
View full analysis
"` - macOS zsh: `echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.zshrc && source ~/.zshrc` - Linux bash: `echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.bashrc && source ~/.bashrc` ``` The original documentation contains equivalent instructions with localized explanatory text. ### Technical Analysis The onboarding documentation directs users and Agents to persist a long-lived LinkFox API key in shell startup configuration. Shell profile files are plaintext and are commonly: - Included in workstation backups and migration bundles. - Read by interactive shell processes. - Collected in diagnostic archives. - Accidentally copied into dotfile repositories. - Exposed to applications that inherit the shell environment. An environment variable can also propagate to child processes that do not require the credential. Persistent configuration is convenient but grants the credential a broader lifetime and process scope than necessary for a single Skill invocation. This is credential persistence rather than the cross-session backdoor installation covered by `T06: System Persistence`; the best matching classification is insecure credential handling under T09. ### Attack Path 1. The user follows the onboarding instructions and appends the complete key to `.bashrc` or `.zshrc`, or stores it through `setx`. 2. The key remains present across future sessions. 3. A local process, malicious shell plugin, dotfile repository, backup system, support bundle, or environment-dump operation captures the value. 4. An attacker obtains the persisted key. 5. The attacker submits authenticated requests to LinkFox services using the victim's credential. 6. The attacker accesses functions allowed by the ...[truncated 799 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (59)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The HTTP client posts to URLs derived from environment-controlled base URLs, and these requests carry sensitive material such as SMS-login credentials, access tokens, refresh tokens, and generated API keys in headers or bodies. If an attacker can influence environment variables in the skill runtime, they can redirect traffic to an attacker-controlled endpoint and exfiltrate credentials or tokens via SSRF-style endpoint substitution.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The gateway request path uses urllib to contact a base URL sourced from environment variables and attaches the LinkFox API key in the Authorization header. An attacker who can set or poison the environment can redirect these authenticated requests to a malicious server, exposing API keys and enabling unauthorized account, billing, or order operations.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill explicitly exposes generic proxying of arbitrary Temu US API types and implies non-Ads product-inventory usage, despite being labeled as Ads-only. This discrepancy can bypass least-privilege expectations and allow operators to reach broader commerce APIs than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the operator to collect and pass a user's phone number into a registration/login script, but it does not require explicit informed consent, minimization, or privacy handling. That creates unnecessary exposure of personal data and could lead to misuse, logging, or retention of phone numbers and verification flows without clear user authorization.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements SMS verification, account login, package listing, ordering, and API-key acquisition, which are materially outside the declared Temu US Ads management scope. This mismatch is dangerous because a user or host may invoke the skill expecting ad operations while the code instead collects phone numbers, authentication codes, and account tokens and initiates account onboarding flows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Billing and payment QR generation are unrelated to the stated ads API skill purpose and introduce the ability to create purchase orders and payment artifacts. In the context of an ads-management skill, hidden commerce functionality increases the risk of deceptive charges, social engineering, or misuse of a user's linked account and credits.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script is a generic Temu proxy that forwards caller-supplied type and params to a shared proxy endpoint, rather than enforcing the skill’s advertised US Ads-only scope. In this skill context, that creates a scope-bypass primitive: a user invoking an ads skill could reach unrelated Temu APIs if they possess a valid token, undermining least privilege and enabling unauthorized cross-domain operations through a misleading interface.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises capabilities that involve environment access, network calls, and file writes, but it does not declare any explicit tool scope or permissions boundary. This increases the chance of overbroad execution and makes it harder for reviewers or runtime controls to constrain sensitive operations such as credential access, network exfiltration, and persistent storage.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Default persistent logging of full API responses is dangerous because those responses may include tokens, business metrics, campaign data, or account identifiers, and they are stored in a project-local path. In this skill’s context, the danger is elevated because the tool also handles authentication material and generic proxy operations, making sensitive spillover more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill writes complete API responses to project-local files by default without warning that those responses may contain sensitive ad, account, or token-related data. In a shared development directory, this can lead to accidental exposure through local search, backups, or source-control commits.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Documenting token persistence and retrieval utilities within an Ads skill normalizes credential handling outside its stated business purpose. This increases the risk that users invoke secret-management behaviors without realizing they are outside the core advertised scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Persistent local storage of Temu access tokens creates a durable secret-exposure risk, especially in shared workspaces or repos where project files may be browsed, backed up, or committed. For an Ads skill, this storage is not clearly necessary and broadens compromise impact beyond a single execution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L036 says the tool consumes credits and L046-L052 discuss handling 402 and insufficient balance errors, indicating billed usage. The later statement '不消耗积分' directly contradicts that documented behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.