Back to skill

Security audit

Temu欧洲站-定价

Security checks for vulnerabilities and agentic risk

Overview

This skill includes real Temu EU pricing functions, but it also handles credentials, payments, generic API proxying, file downloads, and local storage in ways that are broader than a narrowly scoped pricing skill.

Install only after reviewing whether you want an agent to handle LinkFox and Temu credentials, change merchant prices, create paid LinkFox orders, and store tokens/API responses locally. Prefer the EU-specific scripts, avoid the generic proxy/downloader unless needed, keep endpoint environment variables pointed only at trusted LinkFox hosts, use least-privilege Temu tokens, and lock down or avoid the local token store on shared machines.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:15
Finding

Credential-bearing requests can be redirected to attacker-controlled endpoints

Content
View full analysis
dict: linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) try: with urlopen(req, timeout=timeout) as response: return json.loads(response.read().decode("utf-8")) ``` The onboarding flow independently supports similar overrides: ```python def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` Sensitive onboarding credentials are then sent to those endpoints: ```python def _login_by_token(access_token: str, refresh_token: str) -> dict: resp = _http_post(f"{_agent_user_base()}/account/loginByToken", { "token": access_token, "refreshToken": refresh_token, "device": {"aid": "3026344186", "did": "", "type": "Windows", "os": "10", "model": "149.0.0.0", "brand": "Chrome"}, }, _headers("agent-linkfox-web", "agent.linkfox.com", access_token=access_token)) `` ...[truncated 2786 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:10
Finding

Temu access tokens are stored in plaintext without enforced owner-only permissions

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store writes reusable Temu access tokens directly into a JSON file. File and directory permissions are inherited from the current process umask; the implementation does not enforce `0600` for the token file or `0700` for its parent directory. The file is also written directly rather than through an atomic, securely created temporary file. The configurable `TEMU_TOKEN_STORE_PATH` is not checked for symlinks, ownership, or placement in a shared directory. Encryption or operating-system credential storage is not used. Masking in the token-listing command does not protect the underlying plaintext file. ### Attack Path 1. A user runs `save_temu_access_token.py`, causing a reusable merchant token to be stored. 2. The process has a permissive umask, or `TEMU_TOKEN_STORE_PATH` points to a shared or attacker-observable location. 3. Another local user or compromised process reads the JSON file. 4. The attacker extracts the complete `accessToken`. 5. The attacker uses the token through LinkFox or another compatible Temu API client for any operation covered by its authorization s ...[truncated 521 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:176
Finding

Complete API responses can be persisted in shared temporary storage

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root ``` ```python def emit_result(result, slug=SLUG, inline=False): serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf-8") as f: f.write(serialized) print(f"Saved full response: {out} ({len(serialized)} bytes)") ``` ### Technical Analysis ...[truncated 1608 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/temu_proxy.py:34
Finding

Generic proxy permits operations beyond the declared EU pricing scope

Content
View full analysis
dict: site = validate_site(require_text(params, "site")) management_type = validate_management_type( require_text(params, "managementType") ) access_token = resolve_access_token(params) api_type = require_text(params, "type") body = { "site": site, "managementType": management_type, "accessToken": access_token, "type": api_type, } if "params" in params and params["params"] is not None: if not isinstance(params["params"], dict): print("Error: 'params' must be a JSON object.", file=sys.stderr) sys.exit(1) body["params"] = params["params"] return body ``` The permitted site set is broader than the Skill's EU scope: ```python VALID_SITES = frozenset({"cn", "partner", "us", "global", "eu"}) VALID_MANAGEMENT_TYPES = frozenset({"full-managed", "semi-managed"}) ``` ### Technical Analysis The Skill is primarily declared as an EU pricing integration exposing four named pricing operations. However, `temu_proxy.py` accepts any nonempty `type`, multiple regions, and both full-managed and semi-managed modes. The script validates only the shape of `params`, not whether the requested operation belongs to the declared pricing scope. It has no operation allowlist, per-operation schema, read-versus-write classification, or confirmation requirement for destructive actions. This becomes especially significant when used with stored tokens that were granted broad regular and sensitive permissions. The gateway may impose independent controls, but the Skill itself does not enforce least privilege. ### Attack Path 1. A broadly authorized Temu token is saved locally or s ...[truncated 795 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/onboarding.py:162
Finding

Runtime guidance recommends unpinned third-party dependency installation

Content
View full analysis
dict: try: import qrcode except ImportError: err = "Missing qrcode dependency; run: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError("Missing requests dependency; run: pip install requests") ``` The quoted English messages above represent the installation commands contained in the source; the original user-facing prose is localized. ### Technical Analysis The suggested `pip install` commands do not pin versions, verify hashes, use a lockfile, or specify an approved package index. Following these instructions resolves whatever versions are current at installation time. This does not demonstrate that the named packages are malicious. The risk is that installation is not reproducible and relies on mutable third-party package distribution. A compromised package release, malicious index configuration, or dependency substitution could introduce code that executes during installation or import. ### Attack Path 1. The onboarding script reports that an optional dependency is missing. 2. The user follows the displayed installation command. 3. `pip` resolves packages from the user's configured indexes without version or hash restrictions. 4. A compromised release, unsafe mirror, or substituted package is downloaded. 5. Package installation or later import executes the supplied code with the user's privileges. ### Impact Assessment Successful supply-chain compromise would execute code under the account running the Skill. That code could access environment variables, LinkFox credentials, local Temu token fil ...[truncated 217 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (60)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The POST target URL is derived from environment-controlled base URLs and is used to transmit login data, access tokens, refresh tokens, and API-token management requests. If an attacker can influence environment variables, they can redirect these sensitive requests to an attacker-controlled endpoint, causing credential exfiltration or SSRF-like behavior. The danger is amplified because this file handles onboarding and token issuance rather than the advertised Temu EU pricing scope.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The gateway request uses a URL built from environment-controlled configuration and attaches the LinkFox API key in the Authorization header before calling urlopen. An attacker who controls the environment can redirect these authenticated requests to an arbitrary server and capture the API key or abuse the process as a network pivot. In this skill, that is especially risky because the code is unrelated to Temu price management and performs account/payment onboarding actions.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims pricing-management capability, but the reported implementation instead focuses on authorization guide generation and shop/token metadata. This mismatch is dangerous because it may coax users into providing credentials to a skill that does not actually perform the promised business task, while still handling sensitive auth material.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements LinkFox account onboarding, SMS login, API key issuance, package purchase, and payment flows, which are materially unrelated to the stated Temu EU product pricing skill. This functionality expansion creates an unjustified credential-collection and billing surface inside a mismatched skill, a strong indicator of hidden or deceptive behavior. Skill-context mismatch makes the issue more dangerous because users invoking a pricing tool would not reasonably expect account enrollment and payment handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The order creation and QR payment generation logic introduces direct monetization capability unrelated to the declared Temu EU pricing API purpose. This can steer users into unexpected purchases, expose them to fraudulent or confusing payment flows, and increase the blast radius if the skill is misused. In context, embedding payment functionality in a pricing-management skill is a severe scope violation and a strong trust/safety concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code performs SMS-based authentication, retrieves user/team metadata, and generates or fetches API tokens, all outside the advertised Temu EU pricing functionality. That means the skill can collect phone numbers, verification codes, access tokens, and issue reusable API credentials under false functional pretenses. In a mismatched skill context, this is highly dangerous because it can facilitate credential harvesting and unauthorized account access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script persists a Temu access token locally for later reuse, which is materially broader than the advertised EU price-management function of the skill. In an agent ecosystem, adding credential-storage behavior outside the declared scope increases the chance of unauthorized reuse, hidden capability expansion, and operator confusion about what secrets the skill is collecting and retaining.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The utility saves a general Temu access token to a local store, but nothing in this file enforces that the token is limited to EU pricing operations. A locally persisted broad-scope token can be reused by other scripts or future actions for unrelated Temu operations, turning a price-management skill into a credential-harvesting or cross-function access foothold.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script exposes a generic signed-file download capability that is not aligned with the skill's declared Temu EU price-management purpose. In an agent setting, scope drift like this is dangerous because it can be invoked to fetch arbitrary Temu signed resources using an access token, potentially enabling unintended data access or exfiltration beyond pricing workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script is a generic Temu API proxy that accepts an arbitrary API 'type', site, and params, then forwards them via a shared proxy endpoint. That behavior materially exceeds the declared skill scope of EU price-management operations and can enable callers to invoke unrelated Temu APIs, creating a capability-expansion and authorization-bypass risk at the skill layer.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares broad capabilities involving environment access, file writes, and network calls but does not define any explicit tool scope or permission boundary. In an agent setting, this weakens least-privilege controls and increases the chance that a pricing skill can access credentials, persist sensitive data, or make unintended outbound requests beyond its stated purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation gives contradictory statements about whether calls consume credits. This is not a direct exploit primitive, but it is a security-relevant integrity issue because it can mislead operators into making repeated or automated calls they would otherwise gate, increasing the chance of abuse, denial of budget, or unexpected account impact.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs that complete API responses should always be persisted to session directories and fully printed to stdout for small responses. In a system handling tokens, pricing data, and business records, this creates a significant risk of sensitive data retention, accidental disclosure in logs/transcripts, and broadened access to secrets or confidential merchant information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs users to save a live Temu accessToken locally in a predictable file path and even shows placing the raw token directly in command arguments, but it does not warn that this is a sensitive credential or advise on file permissions, encryption, shell history exposure, or secure secret storage. If the workstation is shared, compromised, backed up insecurely, or monitored via process listings/history, the token could be stolen and used to perform authenticated Temu business API actions through the LinkFox flow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.