T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:27- Finding
Temu Access Tokens Stored in Plaintext Without Restrictive Permissions
- Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The data written by this function includes the complete Temu access token: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The Skill stores complete Temu merchant access tokens in `~/.linkfox/temu-access-tokens.json`. The file is created using the process's default umask and no explicit owner-only permission mode is enforced. The parent directory is also created without explicitly requiring mode `0700`. The implementation additionally performs a direct, non-atomic overwrite. It does not reject symbolic links or use an exclusive temporary file followed by an atomic rename. Consequently: - A permissive umask can make the token file readable by other local users. - Backups, support bundles, or filesystem indexing may capture the plaintext token. - A local attacker able to manipulate the token path may potentially redirect writes through a symbolic link. - A crash during the write can corrupt the credential store. Plaintext persistence is part of the declared token-reuse feature, but storing a merchant credential without operating-system credential protection or enforced filesystem permissions exceeds secure minimum handling requirements. ### Attack Path 1. A user runs `save_temu_access_token.py`, causing the complete Temu access token to be stored in the local JSON file. 2. The file is created u ...[truncated 1222 chars]- Remediation
View remediation
