T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:27- Finding
Temu Access Tokens Stored in Plaintext Without Enforced Owner-Only Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/_temu_token_store.py, lines 7, 27–35, and 61–68
Vulnerability Type: Plaintext credential storage and insufficient file-permission hardening
Risk Level: HighVulnerable Code
python DEFAULT_STORE_PATH = os.path.expanduser("~/.linkfox/temu-access-tokens.json")python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n")The sensitive value written through
_save_storeis constructed as follows:python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), }Technical Analysis
The token store persists reusable Temu access tokens as unencrypted JSON under
~/.linkfox/temu-access-tokens.json. Neither the containing directory nor the file is explicitly created with owner-only permissions. Actual access permissions therefore depend on the process umask and any pre-existing file permissions.Temu access tokens authorize product-management operations routed through the LinkFox gateway. Storing these credentials in plaintext creates a credential-disclosure risk if another local account, compromised process, backup service, workspace collector, or incorrectly configured file-sharing mechanism can read the file.
Rewriting an existing file with
open(path, "w")also does not correct permissions that were previously too broad.Attack Path
- A user saves a Temu token through
save_temu_access_token.py. _save_storewrites the complete token to the default JSON file without enforcing mode0600.- A local attacker, compromised process, backup collector, or other principal with file-read access obtains `~/.linkfox/temu-access-tokens. ...[truncated 1084 chars]
- A user saves a Temu token through
- Remediation
View remediation
Remediation Suggestions
- Prefer an operating-system credential store, such as Windows Credential Manager, macOS Keychain, or a Linux Secret Service implementation.
- If file storage is unavoidable:
- Create
~/.linkfoxwith mode0700. - Create the token file atomically with mode
0600. - Reject symbolic links and unexpected non-regular files.
- Verify ownership and permissions before every read and write.
- Correct overly broad permissions on existing token files.
- Create
- Write updates to a protected temporary file in the same directory, flush and synchronize it, and atomically replace the destination.
- Avoid storing token metadata in shared workspaces or backup locations unless storage is encrypted.
- Add token deletion, expiration tracking, revocation guidance, and rotation support.
- Document that the token file contains reusable credentials and must not be committed, synchronized, or included in support bundles.
- Add automated tests that verify directory mode, file mode, ownership, and safe handling of pre-existing files.
