Back to skill

Security audit

Temu美国站-订单

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches Temu order-management work, but it handles merchant credentials, customer shipping data, payments, and broad gateway actions with weak scoping and unsafe local persistence.

Install only if you are comfortable giving the skill access to LinkFox and Temu merchant credentials, customer shipping/contact data, order records, customization files, and verification uploads. Prefer storeKey use over pasting tokens into commands, avoid shared machines, review or restrict endpoint override environment variables, clean up saved response files, and do not proceed with onboarding or paid package purchase flows unless you intentionally requested them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:10
Finding

Temu access tokens are stored in plaintext without restrictive file permissions

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python def save_token( store_key: str, site: str, management_type: str, access_token: str, token_purpose: str = "default", label: str | None = None, ) -> dict: data = _load_store() store = _find_store(data, store_key) if store is None: store = {"storeKey": store_key, "label": label or store_key, "tokens": []} data["stores"].append(store) elif label: store["label"] = label key = _token_key(site, management_type, token_purpose) entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis Temu access tokens are serialized directly into a plaintext JSON file. The code uses ordinary `os.makedirs()` and `open(..., "w")` calls without explicitly enforcing owner-only permissions. Consequently, the effective directory and file permissions depend on the process umask and the state of any existing path. On a shared system, a permissive umask can make the credential store readable by other local users. The implementation also does not guard against symbolic-link replacement, does not use atomic replacement, and does not encrypt the stor ...[truncated 1201 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:177
Finding

Complete order and recipient responses are persistently written to potentially unsafe locations

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root fallback = os.path.abspath(candidates[-1]) _LF_SESSION_CACHE["_root"] = fallback return fallback ``` ```python def emit_result(result, slug=SLUG, inline=False): """Write full response to linkfox///data/-.json; summarize large responses.""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.js ...[truncated 2339 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/get_temu_access_token.py:48
Finding

Credentials are exposed through process arguments, standard output, and shell startup files

Content
View full analysis
dict: if len(argv) < 2: return {} try: return json.loads(argv[1]) except json.JSONDecodeError as e: print(f"Invalid parameter format: {e}", file=sys.stderr) sys.exit(1) ``` `scripts/get_temu_access_token.py:48-62` prints the complete token: ```python print( json.dumps( { "found": True, "storeKey": store_key, "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": token, }, indent=2, ensure_ascii=False, ) ) ``` `scripts/onboarding.py:488-500` returns and emits the complete LinkFox API key: ```python return { "api_key": tok["api_key"], "phone": masked, "group_id": info["group_id"], "member_id": info["member_id"], "source": tok["source"], "nick_name": lg.get("nick_name", ""), "team_name": info.get("team_name", ""), "is_new_user": lg.get("is_new_user", False), } ``` ```python def _emit(obj: dict) -> None: print(json.dumps(obj, ensure_ascii=False, indent=2)) ``` `references/onboarding.md:11-15` recommends persistent plaintext shell configuration: ```text - Windows PowerShell (persistent): setx LINKFOX_AGENT_API_KEY "" - macOS zsh: echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.zshrc && source ~/.zshrc - Linux bash: echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.bashrc && source ~/.bashrc ``` ### Technical Analysis The documented invocation model places comp ...[truncated 1758 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:14
Finding

Environment-controlled API endpoints can redirect credential-bearing requests to untrusted servers

Content
View full analysis
dict: """Call the Temu gateway API; a LinkFox user token is required.""" linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) try: with urlopen(req, timeout=timeout) as response: return json.loads(response.read().decode("utf-8")) ``` `scripts/onboarding.py:68-85` independently permits arbitrary login and account-service origins: ```python def _env_base(name: str, default: str, *fallbacks: str) -> str: for n in (name, *fallbacks): v = os.environ.get(n) if v: return v.rstrip("/") return default.rstrip("/") def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` ### T ...[truncated 1915 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:162
Finding

Onboarding recommends unpinned runtime installation of third-party packages

Content
View full analysis
dict: try: import qrcode except ImportError: err = "Missing qrcode dependency; run: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ### Technical Analysis When QR support is unavailable, the script directs the user to install `qrcode` and `pillow` without version constraints, integrity hashes, an approved package index, or an isolated environment. A bare `pip install` resolves mutable package versions at installation time. Installation may execute package build backends or installation hooks under the user's account. The absence of a lockfile and hashes prevents users from verifying that they received the dependency versions reviewed with the Skill. This finding does not establish that either named package is malicious. The risk arises from the unpinned and unverifiable installation process. ### Attack Path 1. A user invokes the payment QR functionality without the optional dependencies installed. 2. The script instructs the user to run the displayed `pip install` command. 3. Package resolution uses the user's configured index, mirrors, and current package versions. 4. A compromised release, mirror, account, or dependency in the resolved graph supplies malicious installation or runtime code. 5. The code executes with the privileges of the user performing the installation or running onboarding. ### Impact Assessment A compromised dependency can execute arbitrary code under the installing user's account. This can expose local files, stored Temu tokens, LinkFox API keys, order-response archives, and other credentials accessible to that account. The practical likel ...[truncated 112 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (65)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Undeclared file retrieval capability is risky because it gives the agent a network/file acquisition primitive that users may not expect from an order-management skill. Hidden or weakly documented retrieval features increase the chance of abuse, data overcollection, and policy bypass through innocuous-seeming order prompts.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements LinkFox account onboarding, SMS login, API-key issuance, package purchase, and payment QR generation, which is materially different from the declared Temu US order-management purpose. This capability mismatch is dangerous because it can trick users or orchestrators into disclosing phone numbers, verification codes, and generating platform credentials or payments under an unrelated skill identity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code contains expansive account and billing functions unjustified by the stated order-management role, including SMS verification, login, team lookup, API token retrieval/generation, plan listing, order creation, and payment handling. In the context of a Temu-order skill, these features broaden the trust boundary and create a credible path for credential harvesting, unauthorized account linking, and unintended charges.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises capabilities that require environment access, local file writes, and network calls, but it does not declare any explicit tool scope or allowed-tools restrictions. In an agent setting, missing scope boundaries increases the blast radius of prompt-triggered actions and makes it harder to enforce least privilege or review what the skill is permitted to do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly says it will always persist full API responses, yet it does not warn that those responses may contain sensitive order, address, and potentially PII-bearing shipping data. In a multi-step agent workflow, silent persistence of sensitive records increases privacy, retention, and accidental disclosure risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to always write complete API responses to session-linked local files, which likely includes shipping addresses, order identifiers, and verification-related data. Mandatory bulk persistence of sensitive data expands exposure through local compromise, cross-task leakage, backups, logs, and accidental inclusion in later prompts or artifacts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest and main description frame this skill as a Temu US order-management API wrapper covering order list/detail/shipping/address/amount/combined shipment/customization/verification upload. However, the documented bundled scripts also include saving, listing, and retrieving Temu access tokens locally, which is a broader credential-management function rather than an order API operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to persist Temu access tokens locally in a predictable file path and even shows an example containing a pasted token, but it does not warn about filesystem exposure, permissions, encryption, shell history leakage, or avoiding plaintext storage on shared machines. Because these tokens authorize order, shipping, and other business API actions, compromise of the local token store could let an attacker access sensitive order data or perform unauthorized operations through the gateway.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents a bg.order.decryptshippinginfo.get endpoint, which strongly implies access to decrypted shipping details and therefore sensitive user data. The README provides no warning or privacy notice about the sensitivity of this operation or the need for careful handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The temu.local.order.verification.upload entry indicates an upload operation that may send documents, images, or other potentially sensitive verification data. The markdown index contains no warning about data transmission, privacy impact, or the need to avoid uploading unnecessary sensitive content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill documentation explains how to fetch customized product content for orders, which can include user-provided text, images, and SVG files, but it does not include any user warning about handling sensitive customer content or privacy implications. Under the markdown-file criteria, behaviors that affect user data or privacy should be accompanied by a warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This documentation describes an API that returns full shipping address and contact details, including recipient name, phone numbers, email, and complete address fields, but it provides no privacy, consent, minimization, masking, or handling guidance. In a skill specifically designed for order operations, this omission is risky because it normalizes broad access to PII and increases the chance of unnecessary exposure, logging, or downstream misuse by agents and operators.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.