Back to skill

Security audit

Temu欧洲站-订单

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed Temu EU order tool, but it handles merchant credentials and customer shipping data with overly broad local storage and proxy behavior.

Install only after reviewing whether you are comfortable with local plaintext storage of Temu tokens and full order responses. Use a dedicated workspace, avoid inline full output for shipping or decrypted-address calls, keep endpoint override environment variables trusted, and run login, API-key generation, or payment flows only when explicitly intended.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:28
Finding

Temu Access Tokens Are Stored in Plaintext and Can Be Printed Without Masking

Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The dedicated retrieval command prints the complete token: ```python print( json.dumps( { "found": True, "storeKey": store_key, "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": token, }, indent=2, ensure_ascii=False, ) ) ``` The listing command also permits masking to be disabled: ```python def main(): mask = True if len(sys.argv) >= 2: try: params = json.loads(sys.argv[1]) mask = params.get("mask", True) except json.JSONDecodeError as e: print(f"Invalid parameter format: {e}", file=sys.stderr) sys.exit(1) print(json.dumps(list_stores(mask=mask), indent=2, ensure_ascii=False)) ``` ### Technical Analysis Temu access tokens are persisted as plaintext JSON in the configured token-store path, which defaults to `~/.linkfox/temu-access-tokens.json`. The write operation uses ordinary `open()` semantics and does not explicitly create the parent directory with mode `0700` or the token file with mode `0600`. Consequently, effective permissions depend on the process umask and any pre-existing file permissions. The project also provides two direct credential-disclosure channels: 1. `get_temu_access_token.py` always prints the full token t ...[truncated 1777 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:309
Finding

Complete Order and Decrypted Shipping Responses Are Persisted Without Enforced Access Controls

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root ``` Every complete API response is then written to disk: ```python def emit_result(result, slug=SLUG, inline=False): """落盘完整响应到 linkfox///data/-.json;大响应只打印摘要。无缓存。""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: ...[truncated 2474 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:15
Finding

Credential-Bearing Requests Can Be Redirected Through Unrestricted Environment-Controlled Base URLs

Content
View full analysis
str: for n in (name, *fallbacks): v = os.environ.get(n) if v: return v.rstrip("/") return default.rstrip("/") def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` ### Technical Analysis The code accepts complete base URLs from environment variables without validating the URL scheme or destination host. Subsequent requests attach sensitive credentials, including LinkFox API keys, Temu access tokens, phone numbers, SMS verification codes, login access tokens, and refresh tokens. Endpoint overrides can be useful for development, but unrestricted overrides create a credential-redirection hazard in shared, managed, or compromised execution environments. An attacker who can influence environment variables does not need to modify the Skill code; they can point requests to an attacker-controlled HTTP or HTTPS server. This issue alone does not allow ...[truncated 1543 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:162
Finding

Onboarding Recommends Installing Unpinned Third-Party Dependencies

Content
View full analysis
dict: try: import qrcode except ImportError: err = "缺少 qrcode 依赖,请运行: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} os.makedirs(out_dir, exist_ok=True) png_path = os.path.join(out_dir, f"qr-{int(time.time() * 1_000_000)}.png") qr = qrcode.QRCode(border=1) qr.add_data(content) qr.make(fit=True) qr.make_image(fill_color="black", back_color="white").save(png_path) buf = io.StringIO() qr.print_ascii(out=buf, invert=True) return {"png_path": png_path, "ascii_qr": buf.getvalue()} def _require_requests() -> None: if requests is None: raise RuntimeError("缺少 requests 依赖,请运行: pip install requests") ``` ### Technical Analysis The onboarding script directs users to install `qrcode`, `pillow`, and `requests` without specifying exact versions, cryptographic hashes, a lockfile, or a trusted package index. Package resolution therefore depends on mutable package-index state at installation time. Python package installation can execute build-system and installation code. A compromised upstream release, dependency-confusion condition, package-index compromise, or malicious transitive dependency could therefore execute code with the privileges of the user running `pip`. No evidence was found that the Skill itself automatically executes these installation commands. Exploitation requires the user or an agent to follow the displayed recommendation. ### Attack Path 1. The onboarding environment lacks one or more optional dependencies. 2. The script displays a command such as `pip install qrcode pillow` or `pip install requests`. 3. A user o ...[truncated 920 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (63)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code sends authentication material and other request data to a URL derived from environment-controlled base URLs without validating the destination. If an attacker can influence environment variables such as LINKFOX_LOGIN_API_URL or LINKFOX_AGENT_USER_API_URL, they can redirect requests containing phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys to an attacker-controlled server, causing credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway request uses urlopen on a Request built from an environment-derived base URL while attaching the LinkFox API key in the Authorization header. An attacker who controls LINKFOX_AGENT_API_URL or related variables can redirect traffic and capture the API key and business data, or force the tool to interact with unintended internal or external services.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Generating authorization guidance based on token-purpose, shop type, or site is not inherently unsafe, but when embedded in a skill advertised for order operations it becomes a trust and control issue. Users may trigger credential-related flows without understanding that the skill is acting outside its declared business function.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file adds package listing, purchase, order creation, and payment QR generation to a Temu EU order-management skill. Mixing billing and subscription purchase flows into an unrelated operational skill broadens the attack surface and can enable unexpected charges or social-engineering-style payment prompts in a context where users do not expect financial operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill is described as a Temu EU order-management integration, but the file includes onboarding flows that log users in and generate LinkFox API keys. That is a powerful credential-issuance capability unrelated to the stated skill purpose, increasing the risk of covert credential collection, privilege expansion, and misuse if the skill is invoked under a different trust assumption than a dedicated onboarding tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script is a generic Temu API proxy that forwards caller-controlled type, site, managementType, and params rather than enforcing the manifest's stated scope of EU order-management operations. This creates a capability mismatch: an agent or user invoking this skill could access non-order or non-EU Temu APIs through the same gateway, violating least privilege and potentially enabling unauthorized data access or actions outside the approved skill boundary.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill declares broad capabilities involving environment access, file writes, and network requests, but does not define an explicit tool scope such as allowed-tools or permissions. That creates an unnecessary trust gap: consumers cannot easily determine what the skill is permitted to do, while the documented behavior includes sensitive operations like token handling and response persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Overly broad trigger descriptions can cause the skill to activate in contexts where the user did not intend order-data handling, token use, or external API access. In a skill that touches order, address, and verification data, ambiguous activation boundaries increase the risk of unnecessary data exposure and accidental privileged actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill handles highly sensitive data types, including order details, shipping addresses, and potentially SN/IMEI verification information, yet does not warn users about storage, logging, or exposure risks. In this context, missing data-handling warnings materially increases the likelihood of unsafe operator behavior and privacy violations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to always persist full API responses and optionally print them inline, even though those responses may contain shipping addresses, order details, and device identifiers such as SN or IMEI. This creates a direct confidentiality risk through local storage, logs, model context, and shared session artifacts, especially because persistence is mandatory rather than opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly recommends storing Temu access tokens locally and provides a default filesystem path, but it does not warn that these tokens are sensitive credentials or describe the risks of plaintext local storage, file permission exposure, backups, shared machines, or accidental disclosure. In this skill context, the risk is elevated because the token grants access to order and shipping APIs, which can expose customer data and enable operational actions if the local token store is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly exposes an endpoint for retrieving decrypted sensitive shipping address data but does not include any warning, access limitation guidance, or privacy-handling requirements. In an order-management skill, this makes unauthorized or overbroad access to personal data easier to normalize, increasing the risk of privacy violations, accidental disclosure, or misuse of customer PII.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file describes a workflow that fetches parent order groups and then calls shipping-info and decrypt-shipping-info APIs to obtain addresses. That behavior affects user data/privacy, but the document provides no warning or caution about sensitive order information handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document exposes an API flow for bulk retrieval of customized order content, including customer-provided text, uploaded images, and downloadable SVG/compressed files, but it does not include privacy handling guidance, minimization requirements, or operator warnings about sensitive personal data. In an order-management skill, these fields can contain PII or highly sensitive user-generated content, so omission of guardrails increases the risk of unnecessary collection, broad access, unsafe storage, or downstream leakage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.