Back to skill

Security audit

Temu全球站-商品管理

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Temu product-management gateway, but it handles sensitive commerce credentials and live store mutations with overbroad proxying, weak local secret handling, and under-scoped safeguards.

Review this skill carefully before installing. It can use LinkFox and Temu credentials to read and modify live store data, including stock, sale status, compliance fields, and product deletion. Avoid using environment overrides for gateway/login URLs unless you control them, treat saved response files and ~/.linkfox/temu-access-tokens.json as sensitive, and confirm destructive or payment-related actions explicitly before running the scripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:27
Finding

Temu Access Tokens Stored in Plaintext Without Enforced Owner-Only Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/_temu_token_store.py, lines 7, 27–35, and 61–68
Vulnerability Type: Plaintext credential storage and insufficient file-permission hardening
Risk Level: High

Vulnerable Code

python
DEFAULT_STORE_PATH = os.path.expanduser("~/.linkfox/temu-access-tokens.json")
python
def _save_store(data: dict) -> None:
    path = store_path()
    parent = os.path.dirname(path)
    if parent:
        os.makedirs(parent, exist_ok=True)
    with open(path, "w", encoding="utf-8") as f:
        json.dump(data, f, indent=2, ensure_ascii=False)
        f.write("\n")

The sensitive value written through _save_store is constructed as follows:

python
entry = {
    "site": site,
    "managementType": management_type,
    "tokenPurpose": token_purpose,
    "accessToken": access_token,
    "updatedAt": _utc_now(),
}

Technical Analysis

The token store persists reusable Temu access tokens as unencrypted JSON under ~/.linkfox/temu-access-tokens.json. Neither the containing directory nor the file is explicitly created with owner-only permissions. Actual access permissions therefore depend on the process umask and any pre-existing file permissions.

Temu access tokens authorize product-management operations routed through the LinkFox gateway. Storing these credentials in plaintext creates a credential-disclosure risk if another local account, compromised process, backup service, workspace collector, or incorrectly configured file-sharing mechanism can read the file.

Rewriting an existing file with open(path, "w") also does not correct permissions that were previously too broad.

Attack Path

  1. A user saves a Temu token through save_temu_access_token.py.
  2. _save_store writes the complete token to the default JSON file without enforcing mode 0600.
  3. A local attacker, compromised process, backup collector, or other principal with file-read access obtains `~/.linkfox/temu-access-tokens. ...[truncated 1084 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer an operating-system credential store, such as Windows Credential Manager, macOS Keychain, or a Linux Secret Service implementation.
  2. If file storage is unavoidable:
    • Create ~/.linkfox with mode 0700.
    • Create the token file atomically with mode 0600.
    • Reject symbolic links and unexpected non-regular files.
    • Verify ownership and permissions before every read and write.
    • Correct overly broad permissions on existing token files.
  3. Write updates to a protected temporary file in the same directory, flush and synchronize it, and atomically replace the destination.
  4. Avoid storing token metadata in shared workspaces or backup locations unless storage is encrypted.
  5. Add token deletion, expiration tracking, revocation guidance, and rotation support.
  6. Document that the token file contains reusable credentials and must not be committed, synchronized, or included in support bundles.
  7. Add automated tests that verify directory mode, file mode, ownership, and safe handling of pre-existing files.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_temu_access_token.py:50
Finding

Complete Temu Access Token Disclosed Through Standard Output

Content
View full analysis

Vulnerability Details

File Location: scripts/get_temu_access_token.py, lines 50–61
Vulnerability Type: Sensitive credential exposure through command output
Risk Level: Medium

Vulnerable Code

python
print(
    json.dumps(
        {
            "found": True,
            "storeKey": store_key,
            "site": site,
            "managementType": management_type,
            "tokenPurpose": token_purpose,
            "accessToken": token,
        },
        indent=2,
        ensure_ascii=False,
    )
)

Technical Analysis

The token-retrieval command prints the complete reusable Temu access token to standard output. Standard output is frequently captured by agent transcripts, shell pipelines, terminal recording systems, CI logs, remote execution platforms, debugging tools, and support bundles.

Although retrieving a stored token is the command's intended purpose, returning the complete credential by default violates secure-output principles. The project already demonstrates a safer masking pattern in list_temu_access_tokens.py through the token-store listing function, but the retrieval command does not apply equivalent protection.

The exposure is particularly relevant in an AI-agent environment because tool invocations and their output may be retained in session histories or made available to other automation components.

Attack Path

  1. A user or automation process invokes get_temu_access_token.py for a configured store.
  2. The script prints the complete token as JSON to standard output.
  3. An agent transcript, CI system, terminal logger, shell redirection, monitoring service, or downstream pipeline stores the output.
  4. An attacker or unauthorized operator gains access to that retained output.
  5. The attacker extracts the accessToken.
  6. If valid LinkFox gateway authorization is also available, the attacker submits the token to supported Temu product-management calls.

Impact Assessment

A disclosed token can b ...[truncated 587 chars]

Remediation
View remediation

Remediation Suggestions

  1. Mask the token by default, showing only a short prefix and suffix.
  2. Require an explicit option such as --reveal-token for full disclosure.
  3. Require interactive confirmation before revealing the token and refuse full disclosure when standard output is not attached to a terminal.
  4. Prefer passing credentials directly from the protected store to API operations rather than returning them to users or automation.
  5. If machine-readable secret retrieval is required, write the value only to a caller-provided protected file descriptor or integrate with a secret-management API.
  6. Clearly warn that revealed output must not be logged, copied into prompts, committed, or placed in shell history.
  7. Add automatic redaction for errors, diagnostic output, and agent-facing results.
  8. Support rapid token revocation and rotation following suspected output disclosure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (76)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The script builds request destinations from environment variables such as LINKFOX_LOGIN_API_URL and LINKFOX_AGENT_USER_API_URL, then sends sensitive data including phone numbers, SMS codes, access tokens, refresh tokens, generated API keys, and identifying headers to those URLs via requests.post. If an attacker can influence the runtime environment, they can redirect authentication and token-generation traffic to an attacker-controlled host, causing credential exfiltration and account compromise; this is especially dangerous because the file is an onboarding helper unrelated to the advertised Temu product-management purpose.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

Gateway requests are sent with an Authorization API key to a URL derived from environment-controlled base settings, so a manipulated environment can redirect paid account, package, and order operations to an attacker-controlled endpoint. This enables exfiltration of API keys and potentially SSRF-like outbound access from the agent runtime; the risk is amplified because this skill is supposed to manage Temu products, not perform account onboarding and payment flows.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A general proxy that accepts arbitrary site values and arbitrary API type strings is much more dangerous than a bounded wrapper over 24 declared endpoints. It can be repurposed to access unintended APIs or regions, bypassing the trust users place in a narrowly described skill.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements LinkFox account onboarding, SMS login, API-key retrieval, package listing, ordering, and payment support, which is materially unrelated to a Temu Global product-management skill. This hidden scope expansion creates a credential-harvesting and monetization path inside an unrelated skill, increasing the chance that users or host agents disclose phone numbers, OTPs, and account tokens under false pretenses.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Embedding subscription purchase, order creation, and QR-code payment generation inside a product-management skill is unjustified and can be abused to trigger financial actions that users did not expect from this skill. The mismatch between declared functionality and actual code increases social-engineering risk and could facilitate unauthorized charges or deceptive upsell flows.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill declares no explicit tool/permission scope even though it is documented to use environment variables, network access, and local file writes. In an agent environment, missing scope boundaries can let the skill exercise broader capabilities than users expect, including credential handling and persistent storage of sensitive API responses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states that full API responses are always written to local disk, which may include product data, identifiers, tokens, or other sensitive business information. Silent persistence increases exposure through source trees, backups, shared workspaces, and later agent reads, especially because users are not warned or asked to opt in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes destructive catalog mutations such as delete, stock edits, and sale-status changes without an explicit warning that these actions affect live commerce data. In an agent setting, missing guardrails can lead to accidental inventory corruption, unintended delisting, or irreversible production changes from ambiguous prompts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly says e-commerce compliance tasks should use linkfox-temu-compliance-global, separating them from this Manage Product skill's purpose. Yet the script inventory for this skill includes bg.local.compliance.goods.list.query and bg.local.goods.compliance.edit, which makes the skill handle compliance capabilities despite documentation claiming those belong elsewhere.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims a bounded 24-endpoint scope but also exposes arbitrary proxy and file-download capabilities. Hidden expansion beyond the declared interface set undermines least privilege and lets the skill access network actions users did not consent to.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document explicitly recommends storing Temu access tokens in a local JSON file and shows commands that persist raw tokens to disk, but it does not warn that these are sensitive bearer credentials or provide guidance on file permissions, encryption, rotation, or avoiding accidental disclosure. If the host is multi-user, compromised, backed up insecurely, or the file is later copied into logs/repos, an attacker could reuse the token to perform authenticated Temu product-management actions through the gateway.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents editing and deletion API operations, including temu.local.goods.delete, but provides no warning that these actions can modify or remove product data. For markdown files, safety-relevant behaviors that affect user data or system integrity should be disclosed to help users understand the risk before invoking the related skill or API.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/temu_proxy.py:7