T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:28- Finding
Temu Access Tokens Are Stored in Plaintext and Can Be Printed Without Masking
- Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The dedicated retrieval command prints the complete token: ```python print( json.dumps( { "found": True, "storeKey": store_key, "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": token, }, indent=2, ensure_ascii=False, ) ) ``` The listing command also permits masking to be disabled: ```python def main(): mask = True if len(sys.argv) >= 2: try: params = json.loads(sys.argv[1]) mask = params.get("mask", True) except json.JSONDecodeError as e: print(f"Invalid parameter format: {e}", file=sys.stderr) sys.exit(1) print(json.dumps(list_stores(mask=mask), indent=2, ensure_ascii=False)) ``` ### Technical Analysis Temu access tokens are persisted as plaintext JSON in the configured token-store path, which defaults to `~/.linkfox/temu-access-tokens.json`. The write operation uses ordinary `open()` semantics and does not explicitly create the parent directory with mode `0700` or the token file with mode `0600`. Consequently, effective permissions depend on the process umask and any pre-existing file permissions. The project also provides two direct credential-disclosure channels: 1. `get_temu_access_token.py` always prints the full token t ...[truncated 1777 chars]- Remediation
View remediation
