T05 · Unauthorized Access and Privilege Escalation
- Location
references/access-token.md:28- Finding
Excessive Temu Authorization Scope
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to support Temu EU fulfillment, but it handles powerful seller credentials and sensitive order data with broad scope and weak local safeguards.
Review this skill before installing in any real Temu seller environment. Use it only in a dedicated workspace, avoid shared machines, do not grant broader Temu permissions than needed, treat saved tokens and response files as sensitive, avoid endpoint override environment variables, and confirm any payment, shipment confirmation, cancellation, or POD upload before running it.
references/access-token.md:28Excessive Temu Authorization Scope
scripts/_temu_token_store.py:9Temu Access Tokens Stored in Plaintext Without Restrictive File Permissions
scripts/_temu_common.py:176Complete Sensitive API Responses Are Persisted Insecurely and May Fall Back to a Temporary Directory
scripts/_temu_common.py:15Environment-Controlled Endpoint Overrides Can Redirect Credentials and Business Data
scripts/onboarding.py:163Unpinned Runtime Dependency Installation Guidance
The code allows API base URLs to be overridden via environment variables and then uses those values to send login, access tokens, refresh tokens, phone numbers, SMS codes, and generated API keys to whatever endpoint is configured. In an agent or shared runtime, a malicious or compromised environment can redirect these sensitive requests to attacker-controlled infrastructure, causing credential exfiltration and account takeover.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway request path constructs a URL from environment-controlled base values and then transmits authenticated requests with the LINKFOX agent API key in the Authorization header. If the environment is tampered with, all privileged gateway traffic can be redirected to an attacker endpoint, leaking API keys and enabling unauthorized actions under the user's account.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
This file implements unrelated onboarding, SMS login, API-key issuance, package purchase, and payment flows even though the skill is presented as a Temu EU fulfillment/shipping integration. That scope mismatch is dangerous because it creates an undisclosed credential-harvesting and commerce surface inside a logistics skill, increasing the likelihood of user deception and unauthorized account monetization.
The code can create orders and generate payment QR codes for subscription purchases, which is not justified by the stated fulfillment purpose of the skill. Embedding payment collection logic in a logistics skill can be used to pressure users into making off-scope purchases or disguise billing actions as operational requirements.
The skill declares network, environment-variable, and file-write behavior but does not explicitly scope or constrain those capabilities via permissions or allowed-tools metadata. That increases the chance an agent can invoke sensitive operations beyond what a reviewer or user would reasonably infer from the manifest.
Conflicting statements about whether the tool consumes credits can mislead users and autonomous agents into performing paid or rate-limited operations without informed consent. In an agent setting, contradictory cost guidance increases the risk of unnecessary retries, budget overrun, or unintended economic impact.
The skill states that full API responses are always written to project-local files, but it does not adequately warn that those responses may contain order, shipping, customer, tracking, or POD data. Silent persistence of business and personal data to the working directory increases exposure to later disclosure through source control, backups, shared workspaces, or other tools scanning the project.
Always persisting complete API responses by default is dangerous because fulfillment APIs commonly return personally identifiable information, addresses, phone numbers, tracking data, and proof-of-delivery artifacts. Writing that data into session-linked local files in the current project directory creates a durable, discoverable record that can be exfiltrated by other tools, committed to repositories, or accessed by unauthorized users on the same machine.
The documentation explicitly recommends storing Temu access tokens locally and shows commands that persist them, but it does not clearly warn that these are sensitive credentials or require secure file permissions, encryption, or secret-management hygiene. If a user follows this guidance on a shared machine, in backups, or in a repo-adjacent workspace, the token could be exposed and used to access Temu business APIs.
This markdown file documents actions such as confirming packages as shipped and canceling pickup reservations, which can affect order fulfillment state and downstream logistics operations. The surrounding text presents them as normal API calls and workflow steps but does not include any caution, confirmation, or warning about using them only when the user intends to modify live fulfillment records.
The documented flow instructs uploading POD images to Temu storage and then submitting proof URLs, which involves transmitting potentially sensitive delivery evidence. The section does not warn users that delivery documents or images may contain personal data and will be sent to external systems.
The document describes an irreversible or business-impacting cancellation action for cooperative warehouse fulfillment without an explicit warning, confirmation requirement, or operator-safety guidance. In an agent skill context, this increases the chance that an automated agent or user triggers cancellation on a valid fulfillment order and disrupts shipping operations, causing order delays, failed deliveries, or financial/merchant workflow impact.
This markdown file documents a networked fulfillment submission flow and lists sensitive fields such as accessToken, authorizeToken, customer codes, tracking numbers, shipping labels, and order identifiers. Although the API purpose is described, there is no explicit user-facing warning that using the skill sends these business and potentially sensitive logistics data to an external Partner/Temu service.
Detected: suspicious.exposed_secret_literal