Back to skill

Security audit

Temu全球站-订单

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real LinkFox Temu order tool, but it needs Review because it handles credentials and customer order data with broad proxy access and weak local storage controls.

Install only if you are comfortable giving the skill LinkFox and Temu order credentials, including access to customer shipping data. Prefer passing tokens only when needed, avoid using the generic proxy for unrelated APIs, keep the token store and saved response directory private, delete saved responses when no longer needed, and verify any billing or QR-payment action before proceeding.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:28
Finding

Temu access tokens are stored in plaintext without restrictive file permissions

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store serializes Temu access tokens directly into a plaintext JSON file under `~/.linkfox/temu-access-tokens.json`. The file is opened with the ordinary Python `open()` API without explicitly setting a restrictive permission mode. Consequently, the resulting permissions depend on the process umask. In environments with a permissive umask, the token file may be readable by other local users or processes. The implementation also does not verify that an existing token-store path is a regular file owned by the current user, leaving additional symlink and file-replacement concerns in hostile shared environments. These access tokens are subsequently used to access Temu order, shipping, customization, and potentially decrypted shipping-information APIs. They must therefore be treated as high-value credentials. ### Attack Path 1. A user saves a Temu token through `save_temu_access_token.py`. 2. `_save_store()` writes the raw token to `~/.linkfox/temu-access-tok ...[truncated 1042 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:176
Finding

Sensitive order responses may be persisted in undocumented and weakly protected fallback locations

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root fallback = os.path.abspath(candidates[-1]) _LF_SESSION_CACHE["_root"] = fallback return fallback ``` ```python def emit_result(result, slug=SLUG, inline=False): """落盘完整响应到 linkfox///data/-.json;大响应只打印摘要。无缓存。""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug ...[truncated 2507 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_global_common.py:67
Finding

File-download proxy accepts arbitrary destinations without URL validation

Content
View full analysis
dict: if "tokenPurpose" not in params and params.get("storeKey") and not params.get("accessToken"): params = dict(params) params.setdefault("tokenPurpose", DEFAULT_TOKEN_PURPOSE) from _temu_common import require_text # noqa: E402 site = str(params.get("site", DEFAULT_SITE)).strip().lower() or DEFAULT_SITE management_type = ( str(params.get("managementType", DEFAULT_MANAGEMENT_TYPE)).strip().lower() or DEFAULT_MANAGEMENT_TYPE ) body = { "site": site, "managementType": management_type, "accessToken": resolve_access_token(params), "url": require_text(params, "url"), } return call_temu_api(FILE_DOWNLOAD_URL, body, timeout=timeout, linkfox_params=params) ``` ### Technical Analysis The `url` parameter is accepted as arbitrary text and forwarded to the LinkFox `/temu/fileDownload` gateway together with a Temu access token. The client performs no validation of: - URL scheme. - Destination hostname. - Literal IP addresses. - Loopback, private, link-local, or reserved address ranges. - Embedded credentials. - Redirect destinations. - Whether the host belongs to an expected Temu download domain. If the LinkFox gateway fetches the supplied URL without independent validation, this creates a server-side request forgery primitive. Client-side validation alone would not fully resolve the issue, but its absence means the Skill imposes no destination restrictions before issuing the gateway request. The audit cannot confirm the remote gateway's internal controls, so final exploitability depends on behavior outside this repository. ### Attack Path 1. An attacker or untr ...[truncated 1246 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/onboarding.py:161
Finding

Runtime installation instructions use unpinned third-party dependencies

Content
View full analysis
dict: try: import qrcode except ImportError: err = "缺少 qrcode 依赖,请运行: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError("缺少 requests 依赖,请运行: pip install requests") ``` ### Technical Analysis The onboarding script tells users to install `qrcode`, `pillow`, and `requests` directly by package name without specifying reviewed versions or integrity hashes. Package names resolve to mutable content from the configured Python package index. The identified packages are well-known projects, and no evidence indicates that the current packages are malicious. Nevertheless, the installation pattern does not provide reproducibility or protection against a future compromised release, compromised package-index account, malicious index configuration, dependency confusion, or incompatible update. Because package installation and import execute third-party code under the user's account, compromise of the dependency chain would affect the local environment rather than only the Skill's API data. ### Attack Path 1. A required dependency is absent. 2. The script instructs the user to run an unpinned `pip install` command. 3. The user's package index supplies the latest available release or a package from an untrusted configured index. 4. A compromised or malicious package executes installation or import-time code. 5. That code gains the privileges of the user running `pip` or the Skill. 6. It may read local files, environment variables, LinkFox API keys, or plaintex ...[truncated 780 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (59)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The POST destination is derived from environment-controlled base URLs, and the request includes sensitive material such as login tokens, API keys, and user identifiers in headers and body. If an attacker can influence the runtime environment, they can redirect these authenticated requests to attacker-controlled servers and exfiltrate credentials or payment/login data.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The gateway request URL is also built from environment-controlled base configuration and is used with an Authorization header containing the LinkFox API key. A compromised environment can silently reroute these requests to an attacker endpoint, exposing API credentials and any order/account data returned by the remote service.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that allows arbitrary API type forwarding instead of restricting calls to the documented 9 order APIs materially increases attack surface. In this skill context, that could let a caller invoke unrelated Temu or gateway operations with the provided token, bypassing intended functional boundaries.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file implements LinkFox account onboarding, SMS login, API key acquisition, package purchasing, and payment QR generation, which is unrelated to a Temu Global order-management skill. Such capability mismatch is dangerous because it broadens the skill into credential capture and billing operations users would not reasonably expect from the declared functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill can create LinkFox purchase orders and produce payment QR codes, which is outside the declared Temu Global order-management scope. This mismatch is dangerous because it enables unexpected billing flows and social-engineering opportunities under the guise of a different business function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code can fetch or generate LinkFox API tokens for a group, a highly sensitive privilege unrelated to Temu order handling. In the context of a mislabeled skill, token generation creates a direct path to credential minting and downstream account compromise or unauthorized API use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script implements a generic Temu proxy that forwards arbitrary API type values and caller-supplied parameters, while the skill manifest describes a much narrower Global order-management capability. This creates a scope-break vulnerability: a user or downstream agent can invoke unrelated Temu APIs through this skill, potentially accessing or modifying data outside the declared permission boundary and misleading operators about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises capabilities that involve environment access, local file writes, and network requests, but it does not declare an explicit tool/permission scope. That weakens least-privilege controls and makes it harder for a host system or reviewer to constrain what the skill may access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that complete API responses are automatically persisted locally, but it does not clearly warn that those responses may contain sensitive order, address, shipping, or customer data. In an order-management context, silent persistence increases the risk of data exposure through local files, backups, or later reuse by other tools.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Always writing full API responses to local storage can capture names, addresses, order details, and other sensitive merchant/customer information. In this skill context, mandatory persistence creates unnecessary data-at-rest exposure and expands the impact of workstation compromise, shared-project access, or accidental check-in of saved JSON files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L037 明确写明“本工具会消耗积分”,并要求失败或空结果时不要自动连续试探;但 L231-L233 又声明“不消耗积分”。这不是单纯信息缺失,而是文档内部对同一能力成本属性的直接矛盾,可能误导调用方的使用决策。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly advertises an API for retrieving decrypted shipping address data but does not include any warning about the sensitivity of the data, least-privilege requirements, logging restrictions, or privacy/compliance obligations. In an order-management skill this access may be legitimate, but normalizing decryption of recipient PII without guardrails increases the risk of unnecessary access, mishandling, or secondary exposure through logs and downstream tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation enables bulk retrieval of customized order content, preview images, SVGs, and downloadable files that may contain user-supplied personal or sensitive data, but it provides no warning about data classification, access controls, minimization, retention, or safe handling. In an order-shipping context, this makes accidental over-collection, improper exposure, or downstream leakage more likely, especially because the API supports file download via short-lived signed URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This documentation exposes an API specifically intended to retrieve highly sensitive personal data, including full recipient name, phone numbers, email, and complete shipping address, but provides no privacy warning, access-limitation guidance, or data-handling constraints. In an agent skill context, that omission is dangerous because it can normalize unrestricted collection and display of PII, increasing the chance of overbroad access, accidental disclosure, or misuse by downstream agents and users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.