T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:10- Finding
Temu access tokens are stored in plaintext without enforced access permissions
- Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The Skill stores reusable Temu access tokens directly in a JSON file. No encryption or operating-system credential manager is used, and the implementation does not explicitly enforce owner-only permissions on either the `~/.linkfox` directory or the token file. The effective permissions therefore depend on the user's umask, existing directory permissions, filesystem defaults, and any pre-existing file at the configured path. The `TEMU_TOKEN_STORE_PATH` environment variable can also place the file in a shared or otherwise insecure location. These tokens are operational credentials used by fulfillment, shipment confirmation, cooperative-warehouse authorization, tracking, and label-related APIs. Storing them as ordinary plaintext creates a direct credential-theft opportunity. ### Attack Path 1. A user runs `save_temu_access_token.py` and supplies a valid Temu access token. 2. `_save_store()` writes the token in plaintext to `~/.linkfox/temu-access-tokens.json` or to the path selected through `TEMU_TOKEN_STORE_PATH` ...[truncated 987 chars]- Remediation
View remediation
