Back to skill

Security audit

Temu欧洲站-商品管理

Security checks for vulnerabilities and agentic risk

Overview

This Temu EU product-management skill has a real business purpose, but it needs review because it can mutate live catalog data while handling credentials, billing, and local persistence too broadly.

Install only if you trust LinkFox with Temu merchant data and need live EU catalog management. Use minimally scoped Temu permissions instead of selecting all permissions, avoid printing or logging tokens, protect any local token file with owner-only permissions, verify product IDs before mutations, and treat the billing/order flow as a separate payment action requiring deliberate approval.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:10
Finding

Temu access tokens are stored in plaintext without enforced restrictive permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/_temu_token_store.py:10-35, scripts/_temu_token_store.py:62-68
Vulnerability Type: Plaintext credential storage with environment-dependent file permissions
Risk Level: High

Evidence

python
DEFAULT_STORE_PATH = os.path.expanduser("~/.linkfox/temu-access-tokens.json")

def store_path() -> str:
    return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH)

def _load_store() -> dict:
    path = store_path()
    if not os.path.isfile(path):
        return {"stores": []}
    with open(path, encoding="utf-8") as f:
        data = json.load(f)
    if "stores" not in data or not isinstance(data["stores"], list):
        return {"stores": []}
    return data

def _save_store(data: dict) -> None:
    path = store_path()
    parent = os.path.dirname(path)
    if parent:
        os.makedirs(parent, exist_ok=True)
    with open(path, "w", encoding="utf-8") as f:
        json.dump(data, f, indent=2, ensure_ascii=False)
        f.write("\n")

The sensitive value written to this file is constructed as follows:

python
entry = {
    "site": site,
    "managementType": management_type,
    "tokenPurpose": token_purpose,
    "accessToken": access_token,
    "updatedAt": _utc_now(),
}

Technical Analysis

Temu access tokens are persisted as unencrypted JSON. The implementation does not explicitly create the containing directory with mode 0700 or the credential file with mode 0600. Consequently, effective permissions depend on the process umask and any permissions already present on the configured path.

The TEMU_TOKEN_STORE_PATH environment variable also permits an arbitrary storage path. This is useful for configuration, but no checks ensure that the destination is a regular owner-controlled file, that its parent directory is trustworthy, or that an existing destination is not a symbolic link.

The iss ...[truncated 1526 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer an operating-system credential manager, such as Keychain, Credential Manager, or Secret Service, instead of a plaintext JSON file.
  2. If file storage remains necessary:
    • Create the parent directory with mode 0700.
    • Create a new credential file atomically with mode 0600.
    • Verify and repair permissions on existing files before reading or writing them.
    • Reject symbolic links and non-regular destination files.
    • Write to a securely created temporary file in the same directory, call fsync, and atomically replace the destination.
  3. Validate that the configured storage path is owner-controlled.
  4. Avoid storing tokens longer than required and provide token deletion and rotation commands.
  5. Document that plaintext credentials may be included in backups and synchronized home directories.
  6. Where supported, store only a credential-manager reference in the JSON metadata.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/get_temu_access_token.py:48
Finding

Credential retrieval and onboarding commands expose complete secrets through stdout

Content
View full analysis

Vulnerability Details

File Location: scripts/get_temu_access_token.py:48-59, scripts/onboarding.py:481-508
Vulnerability Type: Sensitive credential disclosure through command output
Risk Level: High

Evidence

get_temu_access_token.py prints the complete Temu token:

python
print(
    json.dumps(
        {
            "found": True,
            "storeKey": store_key,
            "site": site,
            "managementType": management_type,
            "tokenPurpose": token_purpose,
            "accessToken": token,
        },
        indent=2,
        ensure_ascii=False,
    )
)

The onboarding flow returns the complete LinkFox API key and emits it as JSON:

python
return {
    "api_key": tok["api_key"], "phone": masked,
    "group_id": info["group_id"], "member_id": info["member_id"],
    "source": tok["source"], "nick_name": lg.get("nick_name", ""),
    "team_name": info.get("team_name", ""),
    "is_new_user": lg.get("is_new_user", False),
}
python
def _emit(obj: dict) -> None:
    print(json.dumps(obj, ensure_ascii=False, indent=2))


def _cmd_login(args) -> int:
    r = login_and_get_key(args.phone.strip(), args.code.strip(), args.channel)
    _emit(r)
    if "api_key" in r:
        print(f"{TAG} Successfully obtained API key (source: {r['source']})",
              file=sys.stderr)
        return 0
    return 1

The final message in the second snippet is an English rendering of the source log message; the security-relevant behavior is the unmodified _emit(r) call.

Technical Analysis

Both commands serialize reusable credentials to stdout without masking or requiring a dedicated confirmation flag. In agent-driven environments, stdout may be copied into model context, transcripts, CI logs, terminal capture, command-history systems, or orchestration logs.

This is particularly risky because the normal onboarding wor ...[truncated 1551 chars]

Remediation
View remediation

Remediation Suggestions

  1. Mask credentials by default and return only metadata such as whether a token exists, its update time, and a short fingerprint.
  2. Remove ordinary plaintext retrieval functionality. Use the stored token internally through storeKey.
  3. If plaintext revelation is unavoidable:
    • Require an explicit --reveal-secret option.
    • Require an interactive terminal and confirmation.
    • Refuse to reveal secrets when stdout is redirected unless a second explicit override is supplied.
    • Print a warning that output may be logged.
  4. For onboarding, save the generated key directly to an approved credential manager after user confirmation rather than returning it in normal JSON output.
  5. Never include bearer credentials in diagnostic messages or error responses.
  6. Accept secrets through protected stdin, environment variables, or credential-store references instead of command-line JSON.
  7. Add automatic redaction for fields named accessToken, api_key, Authorization, Token, and equivalent variants in all output and logging paths.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/access-token.md:26
Finding

Authorization guidance requests permissions broader than the declared product-management scope

Content
View full analysis

Vulnerability Details

File Location: references/access-token.md:26-55
Vulnerability Type: Violation of least privilege through broad application authorization
Risk Level: High

Evidence

The product and inventory authorization instructions direct the user to:

text
1. Sign in to the Temu seller portal.
2. Open System Management, Service Marketplace, and Authorization Management.
3. Select the Coolbird Seller Assistant application.
4. Select all regular and special permissions, confirm, and copy the access token.
5. Invoke the API with the documented site and management type.

The local-store authorization instructions similarly direct the user to:

text
1. Open Apps and Services and Manage Your Apps.
2. Authorize a new application and locate Cyber-ERP.
3. Select all general and sensitive permissions, confirm, and copy the token.

These are faithful English renderings of the authorization steps at references/access-token.md:26-55.

Technical Analysis

The Skill declares support for 24 Temu EU product-management endpoints, but its instructions request every available regular, special, or sensitive application permission. This does not follow the principle of least privilege.

Product listing, product editing, inventory updates, compliance management, and status changes should be authorized with only the scopes required for those operations. Selecting all permissions may grant access to unrelated business domains such as orders, shipping, financial information, or other sensitive seller functions, depending on the permissions offered by the selected Temu application.

The audit cannot establish the precise additional privileges because the repository does not enumerate the external application's available scopes. Nevertheless, the explicit instruction to select all sensitive permissions is broader than the Skill's declared product-management functionality.

Attack Path

1 ...[truncated 1117 chars]

Remediation
View remediation

Remediation Suggestions

  1. Enumerate the exact Temu permissions required by each of the 24 supported endpoints.
  2. Replace all instructions to select every permission with a minimal scope checklist.
  3. Explicitly instruct users not to authorize unrelated order, shipping, finance, advertising, or other sensitive permissions.
  4. Use separate tokens for product management, inventory, orders, shipping, and other business domains.
  5. If the external application cannot issue narrowly scoped tokens, clearly disclose that limitation and its security consequences before authorization.
  6. Where the gateway can inspect scope metadata, reject or warn about unnecessarily privileged tokens.
  7. Provide token revocation and rotation instructions and recommend immediate revocation after suspected exposure.
  8. Periodically review the required scope list because external Temu application permissions may change.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (85)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The code builds request destinations from environment-controlled base URLs and then sends sensitive authentication material such as access tokens, API keys, phone numbers, SMS codes, and payment/order data to those endpoints. If an attacker can influence environment variables in the skill runtime, they can redirect traffic to attacker-controlled servers and exfiltrate credentials or induce SSRF-style access to internal services.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The gateway helper constructs urllib requests using a URL derived from environment variables and attaches the LinkFox agent API key in the Authorization header. A manipulated runtime environment could redirect these outbound requests to an attacker endpoint or internal network target, exposing credentials and enabling unintended network access.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local persistence of access tokens for reuse, especially when the skill is described as a simple EU product-management wrapper, increases the chance that operators will supply secrets without understanding retention or cross-site reuse. Support for non-EU values also weakens the trust boundary implied by the skill name and description.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown explicitly lists temu.local.goods.delete, which is a destructive operation affecting user data. There is no accompanying warning, confirmation note, or caution in the document about irreversible deletion or the need to confirm the correct product before use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill is presented as a Temu EU product-management integration, but the embedded script performs unrelated account onboarding, SMS login, API-key retrieval, plan listing, order creation, and payment handling for LinkFox. That scope mismatch is dangerous because it can trick users or downstream agents into disclosing phone numbers, one-time codes, and payment actions under false pretenses.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code can create purchase orders and render payment QR codes even though the skill's declared purpose is Temu EU product management. In context, that hidden billing capability materially increases risk of unauthorized charges, phishing-style monetization, or deceptive upsell workflows unrelated to the requested business function.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares capabilities that involve environment access, file writes, and network calls, but it does not constrain them with an explicit tool/permission scope. In an agent setting, missing scope boundaries increases the chance of over-broad execution, especially because the skill also handles credentials and writes API responses to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly covers destructive actions such as delete, stock changes, and publish/unpublish without requiring confirmation or warning. In an agent context, that is dangerous because a natural-language misunderstanding or prompt injection could trigger irreversible business-impacting operations against live catalog data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states both that the tool consumes credits and later that it does not consume credits, which can mislead users and agents about the cost and risk of repeated API calls. In an automated workflow, contradictory charging semantics can cause unintended spend or repeated retries under false assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs the agent to always write full API responses into the current working directory without any privacy warning or minimization guidance. Because these responses may contain product data, business metadata, and possibly credential-adjacent information, automatic persistence increases exposure to other tools, users, or source-control accidents.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Always persisting complete API responses in the project directory is a concrete sensitive-data exposure risk. In this skill's context, responses can include merchant product information, operational data, and potentially tokens or identifiers supplied by the user, making leakage via local reuse, backups, logs, or git commits much more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs users to persist a live Temu access token in a local JSON file and shows examples embedding the token directly in command arguments, but it does not clearly warn about filesystem permissions, shell history leakage, backups, logs, or multi-user host exposure. Because this skill manages products for Temu EU stores, compromise of the token could enable unauthorized product edits, inventory changes, listing status changes, or deletions through the proxied API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents editing and deletion API operations, including temu.local.goods.delete, but provides no warning that these actions can modify or remove product data. For markdown files, the absence of warnings about behaviors that may affect user data or system integrity is in scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The section includes operations such as stock edits and sale status changes, which can affect product availability and business operations, but the document does not warn readers about these impacts. In markdown skill documentation, potentially integrity-affecting actions should be disclosed to users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs users to submit sensitive compliance materials, including qualification files, inspection reports, product photos, and responsible-person identifiers, through an external gateway without any privacy notice, data-handling constraints, or guidance on minimizing shared personal data. In an agent skill context, this can lead to unintentional transmission of regulated or personal information to third-party services without informed user consent or adequate safeguards.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/temu_proxy.py:7