Back to skill

Security audit

Temu美国站-发货

Security checks for vulnerabilities and agentic risk

Overview

This Temu fulfillment skill appears purpose-built rather than malicious, but it needs review because it can perform real shipping/account actions while storing sensitive tokens and responses locally and trusting environment-controlled endpoints.

Use this only if you trust LinkFox with your Temu merchant tokens and fulfillment data. Before running it, keep gateway/login endpoint environment variables unset unless they point to known LinkFox HTTPS hosts, confirm every state-changing shipping action, avoid the generic proxy for unrelated Temu APIs, and protect or regularly delete the local token store and saved response files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:15
Finding

Environment-Controlled API Endpoints Can Redirect Authentication Credentials

Content
View full analysis
dict: """Call the Temu gateway API; a LinkFox user token is required.""" linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) ``` The onboarding subsystem exposes the same class of behavior for additional credentials: ```python def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` ```python def _http_post(url: str, body: dict, headers: dict, timeout: int = 30) -> dict: """Generic requests POST, returning JSON or {_error, _body}.""" try: _require_requests() except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() ``` ### Technical Analysis The Skill legitimately needs to transmit a LinkFox API key and Temu access token ...[truncated 2261 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_token_store.py:14
Finding

Temu Access Tokens Are Persisted in Plaintext Without Enforced File Permissions

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The persisted entry contains the complete token: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store writes complete Temu access tokens to a JSON file. The implementation neither encrypts the data nor explicitly creates the parent directory and file with restrictive permissions. The resulting access control is therefore determined by the process umask and the properties of any existing path. In permissive environments, another local account or process may be able to read the token. The implementation also performs a conventional path-based write without explicit symlink protection or atomic replacement, increasing exposure in environments where the configured token path is not fully trusted. The optional `TEMU_TOKEN_STORE_PATH` override can place the credential in an unintended or shared location. This override is useful operationally, but it needs containment and permission safeguards because the stored value is a reusable merchant credential. ### Attack Path 1. The user invokes `save_temu_access_token.py` or otherwise calls `save_token`. 2. The Skill creates or overwrites the configured JSON tok ...[truncated 1180 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:310
Finding

Complete Fulfillment Responses Are Persisted Without Access Controls or Retention Limits

Content
View full analysis
//data/-.json.""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf-8") as f: f.write(serialized) print(f"Saved full response: {out} ({len(serialized)} bytes)") ``` The associated metadata is also written using default permissions: ```python with open(meta_path, "w", encoding="utf-8") as f: json.dump(meta, f, ensure_ascii=False, indent=2) ``` ### Technical Analysis Every API response is serialized and stored in full regardless of whether the caller needs persistent output. No field-level redaction is performed, no restrictive file mode is enforced, and no expiration or cleanup policy is implemented. Fulfillment APIs can return order and package identifiers, shipment and tracking information, shipping labels, signed document URLs, warehouse data, and other merchant logistics information. Persisting all responses expands the lifetime and number of copies of this data beyond the network transaction. The implementation attempts multiple output roots, including the working directory, home directory, and system temporary dire ...[truncated 1533 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:211
Finding

Unsanitized SESSION_ID Enables Output-Path Traversal

Content
View full analysis
str: env = os.environ.get("SESSION_ID") if env: return env.strip() if "_auto" not in _LF_SESSION_CACHE: _LF_SESSION_CACHE["_auto"] = ( _lf_time.strftime("%H%M%S", _lf_time.localtime(ts)) + "-" + _lf_secrets.token_hex(3) ) return _LF_SESSION_CACHE["_auto"] ``` The unvalidated value is then used as a path component: ```python sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf-8") as f: f.write(serialized) ``` Onboarding uses the same environment variable without validation: ```python def session_dir() -> str: ts = time.time() sid = (os.environ.get("SESSION_ID") or "").strip() or ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3)) path = os.path.join(_linkfox_root(), time.strftime("%Y-%m-%d", time.localtime(ts)), sid) os.makedirs(path, exist_ok=True) return path ``` ### Technical Analysis `SESSION_ID` is treated as a trusted directory name, but it is supplied by the process environment and may contain: - Absolute paths. - `..` traversal components. - Platform-specific directory separators. - Paths to existing attacker-selected directories. With `os.path.join`, an absolute final component can discard the previously constructed root on relevant platforms. Relative traversal sequences can escap ...[truncated 2139 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (82)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The script builds request destinations from environment-controlled base URLs and then sends sensitive material including phone numbers, SMS codes, bearer tokens, refresh tokens, generated API keys, and team identifiers to those endpoints. In a skill/onboarding context, environment variables are often supplied by the host or deployment, so an attacker who can influence them can redirect authentication traffic and credential exchange to an attacker-controlled server, causing credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway helper constructs its URL from environment-controlled base configuration and attaches the LinkFox API key in the Authorization header before calling urlopen. If the base URL is redirected via environment manipulation, the CLI will transmit the account API key and business actions such as package lookup, order creation, and order queries to an untrusted endpoint, enabling credential theft and spoofed responses.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill exposes a generic proxy script described as usable for arbitrary type values, while the skill is presented as a narrowly scoped Temu US fulfillment tool. In an agent environment, that mismatch can let callers invoke unrelated Temu APIs through a trusted shipping-themed skill, expanding data access and action scope beyond user expectations.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains package browsing, order creation, and payment QR rendering for LinkFox plans, which is out of scope for a Temu US fulfillment integration. In-context, this broadens the skill from fulfillment operations into monetization and billing actions, creating risk of unauthorized purchases or deceptive prompts under a misleading skill identity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements SMS login and returns an account-level LinkFox API key, which is unrelated to the declared Temu fulfillment function of the skill. That mismatch is dangerous because a user invoking a shipping skill would not reasonably expect it to perform account onboarding and credential minting, increasing the chance of covert credential collection or privilege expansion under misleading scope.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares network, environment-variable, and local file-write behavior but provides no explicit tool scope or permission boundary. In an agent setting, missing scope makes it easier for the skill to access sensitive credentials, write persistent data, or call remote endpoints without clear policy constraints or user visibility.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger text is very broad and includes many common shipping-related phrases, increasing the chance of accidental activation on unrelated requests. In a networked skill that can write files and call external APIs, over-triggering can cause unintended data disclosure, unnecessary remote actions, or wasted user credits.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description and operational guidance are written entirely for a Chinese-speaking workflow while targeting a US-site integration, with no indication that users may choose another language. Under the policy, a fixed language/locale without user opt-in should be flagged unless clearly justified as region-specific and documented as such.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to always persist full API responses into session-organized local files. Because fulfillment responses can contain customer addresses, tracking numbers, order details, tokens, and other sensitive business data, mandatory bulk logging creates unnecessary retention risk, expands the blast radius of compromise, and may violate data-minimization expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs users to save a Temu access token locally in a predictable file path and even paste the secret directly into command examples, but it does not warn that the token is a sensitive credential or explain the risks of plaintext-at-rest storage. If the host is shared, compromised, backed up insecurely, or has lax file permissions, the token could be recovered and used to access Temu shipping and fulfillment APIs as the seller.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This section documents operationally irreversible or hard-to-reverse fulfillment actions such as label purchase, shipment confirmation, pickup reservation, and scan form creation without an explicit warning that these steps can trigger real shipping charges, carrier manifests, customer-facing status changes, and downstream logistics effects. In an agent skill context, this omission increases the chance that an autonomous or inattentive user will execute live actions in production without confirming intent, especially because the document presents them as a normal sequential workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents actions such as shipment creation, shipment update, scanform creation, and related fulfillment operations, but provides no warning that these calls can modify fulfillment state or generate operational artifacts. Under the markdown criteria for missing user warnings, descriptions of behaviors that may affect user data or system integrity should disclose those risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The cooperative warehouse section includes token authorization and fulfillment submit/cancel operations, which can affect account access or fulfillment workflows, but the README presents them as a plain index without any cautionary note. For markdown files, omitting warnings for behaviors that may affect privacy, user data, or system integrity is in scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This section includes confirmation and update endpoints for self-fulfilled shipments, which are state-changing logistics actions, yet the markdown contains no warning about their effect on order or shipment records. That omission matches the markdown-file criteria for missing user warnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document describes an order-fulfillment cancellation API that can reverse or disrupt shipping workflow, but it does not prominently warn users that the action is destructive, may be irreversible in some fulfillment states, or requires explicit confirmation and authorization checks. In an agent skill context, this omission increases the risk that automation or a user prompt could trigger unintended cancellation of legitimate warehouse fulfillment orders.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/temu_proxy.py:7