Back to skill

Security audit

Temu欧洲站-发货

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to support Temu EU fulfillment, but it handles powerful seller credentials and sensitive order data with broad scope and weak local safeguards.

Review this skill before installing in any real Temu seller environment. Use it only in a dedicated workspace, avoid shared machines, do not grant broader Temu permissions than needed, treat saved tokens and response files as sensitive, avoid endpoint override environment variables, and confirm any payment, shipment confirmation, cancellation, or POD upload before running it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/access-token.md:28
Finding

Excessive Temu Authorization Scope

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:9
Finding

Temu Access Tokens Stored in Plaintext Without Restrictive File Permissions

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The sensitive value is stored directly in the JSON structure: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The Temu access token is written in plaintext to `~/.linkfox/temu-access-tokens.json`, or to an environment-selected path. The implementation uses ordinary `os.makedirs()` and `open(..., "w")`, so permissions depend entirely on the current process umask and any pre-existing file. The code does not: - Create the parent directory with mode `0700`. - Create the credential file with mode `0600`. - Verify file ownership or existing permissions. - Prevent symbolic-link traversal. - Use atomic replacement. - Encrypt the credential or use an operating-system credential store. Because the documentation also asks users to grant broad sensitive permissions, disclosure of this token may have substantial consequences. ### Attack Path 1. A user invokes `save_temu_access_token.py`. 2. `_save_store()` creates or overwrites the JSON file using default filesystem permissions. 3. A permissive umask, shared home directory, unsafe custom `TEMU_TOKEN_STORE_PATH`, backup process, or pre-positioned symbolic link makes th ...[truncated 622 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:176
Finding

Complete Sensitive API Responses Are Persisted Insecurely and May Fall Back to a Temporary Directory

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root ``` Every complete response is then written with default permissions: ```python def emit_result(result, slug=SLUG, inline=False): serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf-8") as f: f.write(serialized) ``` The docu ...[truncated 2445 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:15
Finding

Environment-Controlled Endpoint Overrides Can Redirect Credentials and Business Data

Content
View full analysis
dict: return { "Authorization": linkfox_token, "Token": linkfox_token, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/1.0", } ``` The request body may also contain the Temu seller token: ```python def call_temu_api(url: str, body: dict, timeout: int = 150, linkfox_params=None) -> dict: linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) with urlopen(req, timeout=timeout) as response: return json.loads(response.read().decode("utf-8")) ``` Onboarding uses the same unrestricted pattern for credential-bearing services: ```python def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` The access and refresh tokens are then sent to those selected endpoints: ```python resp = _http_post(f"{_agent_user_base()}/account/loginByToken", { "token": ...[truncated 2554 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:163
Finding

Unpinned Runtime Dependency Installation Guidance

Content
View full analysis
dict: try: import qrcode except ImportError: err = "Missing qrcode dependency. Run: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError("Missing requests dependency. Run: pip install requests") ``` ### Technical Analysis The runtime error messages direct users to install mutable package names without specifying reviewed versions, cryptographic hashes, a lockfile, an isolated environment, or a trusted package index. The identified package names are common legitimate packages; the audit found no evidence that they are intentionally malicious or typosquatted. The weakness is supply-chain reproducibility: package behavior can change over time, and installation depends on the user's configured index and dependency resolver. Python package installation and subsequent import can execute package-controlled code. A compromised package release, malicious configured index, dependency confusion condition, or resolver drift could therefore introduce code that was not included in the reviewed Skill. ### Attack Path 1. The user runs onboarding on a system without `requests`, `qrcode`, or `Pillow`. 2. The script tells the user to execute an unpinned `pip install` command. 3. Pip resolves packages and transitive dependencies from the user's configured package index. 4. A compromised release, unsafe mirror, malicious index configuration, or future incompatible package is installed. 5. Package-controlled code executes during installation or when onboarding imports and uses the package. 6. The i ...[truncated 487 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (84)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code allows API base URLs to be overridden via environment variables and then uses those values to send login, access tokens, refresh tokens, phone numbers, SMS codes, and generated API keys to whatever endpoint is configured. In an agent or shared runtime, a malicious or compromised environment can redirect these sensitive requests to attacker-controlled infrastructure, causing credential exfiltration and account takeover.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway request path constructs a URL from environment-controlled base values and then transmits authenticated requests with the LINKFOX agent API key in the Authorization header. If the environment is tampered with, all privileged gateway traffic can be redirected to an attacker endpoint, leaking API keys and enabling unauthorized actions under the user's account.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly advertises a generic proxy script, temu_eu_proxy.py, for invoking arbitrary type values through a shared gateway. In context, that broad invocation surface can bypass the claimed narrow fulfillment scope and enable access to unrelated Temu APIs if downstream validation is weak or absent.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements unrelated onboarding, SMS login, API-key issuance, package purchase, and payment flows even though the skill is presented as a Temu EU fulfillment/shipping integration. That scope mismatch is dangerous because it creates an undisclosed credential-harvesting and commerce surface inside a logistics skill, increasing the likelihood of user deception and unauthorized account monetization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code can create orders and generate payment QR codes for subscription purchases, which is not justified by the stated fulfillment purpose of the skill. Embedding payment collection logic in a logistics skill can be used to pressure users into making off-scope purchases or disguise billing actions as operational requirements.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares network, environment-variable, and file-write behavior but does not explicitly scope or constrain those capabilities via permissions or allowed-tools metadata. That increases the chance an agent can invoke sensitive operations beyond what a reviewer or user would reasonably infer from the manifest.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Conflicting statements about whether the tool consumes credits can mislead users and autonomous agents into performing paid or rate-limited operations without informed consent. In an agent setting, contradictory cost guidance increases the risk of unnecessary retries, budget overrun, or unintended economic impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that full API responses are always written to project-local files, but it does not adequately warn that those responses may contain order, shipping, customer, tracking, or POD data. Silent persistence of business and personal data to the working directory increases exposure to later disclosure through source control, backups, shared workspaces, or other tools scanning the project.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Always persisting complete API responses by default is dangerous because fulfillment APIs commonly return personally identifiable information, addresses, phone numbers, tracking data, and proof-of-delivery artifacts. Writing that data into session-linked local files in the current project directory creates a durable, discoverable record that can be exfiltrated by other tools, committed to repositories, or accessed by unauthorized users on the same machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly recommends storing Temu access tokens locally and shows commands that persist them, but it does not clearly warn that these are sensitive credentials or require secure file permissions, encryption, or secret-management hygiene. If a user follows this guidance on a shared machine, in backups, or in a repo-adjacent workspace, the token could be exposed and used to access Temu business APIs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents actions such as confirming packages as shipped and canceling pickup reservations, which can affect order fulfillment state and downstream logistics operations. The surrounding text presents them as normal API calls and workflow steps but does not include any caution, confirmation, or warning about using them only when the user intends to modify live fulfillment records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documented flow instructs uploading POD images to Temu storage and then submitting proof URLs, which involves transmitting potentially sensitive delivery evidence. The section does not warn users that delivery documents or images may contain personal data and will be sent to external systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document describes an irreversible or business-impacting cancellation action for cooperative warehouse fulfillment without an explicit warning, confirmation requirement, or operator-safety guidance. In an agent skill context, this increases the chance that an automated agent or user triggers cancellation on a valid fulfillment order and disrupts shipping operations, causing order delays, failed deliveries, or financial/merchant workflow impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents a networked fulfillment submission flow and lists sensitive fields such as accessToken, authorizeToken, customer codes, tracking numbers, shipping labels, and order identifiers. Although the API purpose is described, there is no explicit user-facing warning that using the skill sends these business and potentially sensitive logistics data to an external Partner/Temu service.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/temu_proxy.py:7