Back to skill

Security audit

Temu全球站-发货

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a real Temu fulfillment integration, but it grants broad credential-bearing API authority with weak endpoint and local-storage controls.

Install only if you trust the publisher and runtime environment. Use it with explicit confirmation for shipment creation, confirmation, cancellation, token storage, and paid plan purchases; avoid custom gateway environment variables unless you control the endpoint; protect or delete the local LinkFox output and token files because they may contain reusable credentials and customer or merchant fulfillment data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:10
Finding

Temu access tokens are stored in plaintext without enforced access permissions

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The Skill stores reusable Temu access tokens directly in a JSON file. No encryption or operating-system credential manager is used, and the implementation does not explicitly enforce owner-only permissions on either the `~/.linkfox` directory or the token file. The effective permissions therefore depend on the user's umask, existing directory permissions, filesystem defaults, and any pre-existing file at the configured path. The `TEMU_TOKEN_STORE_PATH` environment variable can also place the file in a shared or otherwise insecure location. These tokens are operational credentials used by fulfillment, shipment confirmation, cooperative-warehouse authorization, tracking, and label-related APIs. Storing them as ordinary plaintext creates a direct credential-theft opportunity. ### Attack Path 1. A user runs `save_temu_access_token.py` and supplies a valid Temu access token. 2. `_save_store()` writes the token in plaintext to `~/.linkfox/temu-access-tokens.json` or to the path selected through `TEMU_TOKEN_STORE_PATH` ...[truncated 987 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:176
Finding

Complete fulfillment responses are persistently stored with unsafe fallback behavior

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root fallback = os.path.abspath(candidates[-1]) _LF_SESSION_CACHE["_root"] = fallback return fallback ``` ```python def emit_result(result, slug=SLUG, inline=False): """落盘完整响应到 linkfox///data/-.json;大响应只打印摘要。无缓存。""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with op ...[truncated 2856 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:15
Finding

Environment-controlled gateway URL can redirect credential-bearing requests to an untrusted endpoint

Content
View full analysis
dict: """调用 Temu 网关接口;必须先具备 LinkFox 用户 Token。""" linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) try: with urlopen(req, timeout=timeout) as response: return json.loads(response.read().decode("utf-8")) except HTTPError as e: raw = e.read().decode("utf-8") if e.fp else "" try: return json.loads(raw) except json.JSONDecodeError: return {"error": f"HTTP {e.code}: {e.reason}", "details": raw} except URLError as e: return {"error": f"Connection failed: {e.reason}"} ``` The request headers are constructed as follows: ```python def build_gateway_headers(linkfox_token: str) -> dict: """网关鉴权:Authorization(全站通用)+ Token(TEMU_API_SPEC 约定)。""" return { "Authorization": linkfox_token, "Token": linkfox_token, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/1.0", } ``` ### Technical Analysis The gateway base URL is selected from environment variables without validation of: - URL scheme. - Destination hostname. - Port. - User-information components. - Whether TLS ...[truncated 2192 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (72)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The code allows base URLs for login and agent-user requests to be overridden via environment variables and then sends sensitive data such as phone numbers, SMS codes, access tokens, refresh tokens, and derived API tokens to those URLs with requests.post. In a skill/onboarding context, environment variables are part of the execution boundary and may be attacker-influenced in some deployments, so this creates a realistic exfiltration/SSRF path for credentials and personal data.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The gateway URL is constructed from environment-controlled base variables and used in urllib.request.urlopen with the Authorization API key header attached. If an attacker can influence those environment variables, API keys and order/account data can be sent to an attacker-controlled server, and the code will also perform outbound requests to arbitrary hosts.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented temu_global_proxy.py is described as handling arbitrary type, which makes this skill effectively a generic API proxy rather than a narrowly scoped fulfillment wrapper. In practice, that can allow invocation of unrelated Temu APIs, expanding privilege beyond user expectations and enabling data access or state-changing operations outside the intended shipping domain.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This documentation embeds account onboarding, authentication recovery, and billing workflows inside a Temu fulfillment skill, which materially expands the skill's effective scope beyond shipping APIs. That scope creep increases the chance an operator will collect credentials, phone numbers, or trigger account/payment actions unrelated to fulfillment, creating unnecessary account and privacy risk if the content is invoked in the wrong context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented capability includes SMS-based registration/login, API key retrieval, and plan purchasing, none of which are necessary to perform Temu Global fulfillment actions. In a tool context, these instructions could lead an operator or agent to facilitate account creation, credential acquisition, and payment flows on behalf of a user, which is a sensitive expansion of privileges and data handling.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file implements LinkFox account onboarding, SMS login, plan purchase, payment QR generation, and order querying, which are unrelated to the stated Temu fulfillment skill purpose. Capability drift of this kind is dangerous because it can trick the host or user into running credential collection and billing actions under the guise of a shipping integration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implemented behavior is materially inconsistent with the skill description: instead of Temu Global fulfillment APIs, it performs account login, token generation, billing, and payment workflows for LinkFox. In a plugin/agent ecosystem, this mismatch is a strong indicator of deceptive behavior and increases the likelihood of credential harvesting or unauthorized purchases.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares network, environment-variable, and file-write behavior but does not bound them with an explicit tool scope such as allowed-tools or permissions. In a skill that can call remote gateways, read API keys/tokens, and write response data to disk, missing scope increases the chance of overbroad execution and makes review and enforcement harder.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states both that continued retrieval may create extra cost and later that the skill does not consume credits. Contradictory cost semantics can mislead operators into unintended repeated calls, causing billing surprises, unsafe automation decisions, or abuse of quota-sensitive APIs under false assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that full API responses are always written to local JSON files, and fulfillment responses may contain access tokens, shipping labels, names, addresses, phone numbers, tracking numbers, and other sensitive business data. Mandatory persistence without explicit user consent, minimization, retention limits, or protection requirements creates a material risk of local data leakage and unauthorized secondary use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly recommends storing a live Temu access token in a local JSON file and even shows an example containing the raw accessToken value, but it does not warn that this credential is sensitive or that the default storage appears to be plaintext on disk. If the host is shared, compromised, backed up insecurely, or the file permissions are weak, an attacker could recover the token and use it to access Temu business APIs as the seller account.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation for a global-site fulfillment skill says the request body requires or defaults to site=us, which can cause callers to send fulfillment and shipping operations to the wrong regional API context. In this skill, that mistake is operationally significant because fulfillment APIs can create shipments, labels, confirmations, or tracking actions against the wrong environment, leading to misrouting, failed requests, or unintended cross-region handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This document exposes a destructive cancellation API for warehouse fulfillment orders without an explicit warning that invoking it will cancel an already-submitted fulfillment request and may disrupt shipping operations. In an agent-skill context, missing safety guidance increases the chance that an LLM or user triggers cancellation based on ambiguous intent, leading to operational loss, delayed shipments, or accidental order handling changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This documentation describes an operation that submits order-shipping and fulfillment data to an external Temu/cooperative warehouse service, and in some modes also uploads shipping label content as Base64. Without an explicit user-facing warning about external transmission and label upload, an agent could trigger the action without the user clearly understanding that potentially sensitive operational data is being sent to a third party.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/temu_proxy.py:7