T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:28- Finding
Temu Access Tokens Are Stored in Plaintext Without Enforced File Permissions
- Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The data written by this function includes the reusable Temu access token: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store defaults to `~/.linkfox/temu-access-tokens.json` and persists reusable Temu access tokens as unencrypted JSON. The save operation uses the process's default `umask` and does not explicitly enforce restrictive permissions on either the parent directory or the token file. Consequently, the final permissions may allow other local accounts, processes, containers, backup agents, or workspace-integrated tools to read the credentials. The implementation also uses a direct non-atomic write and does not protect against symbolic-link replacement. These weaknesses are particularly significant because the stored value is an authentication credential used to invoke merchant APIs. Local persistence is consistent with the documented `storeKey` feature, but persisting a bearer-style credential without explicit access controls exceeds the minimum safe implementation needed for that feature. ### Attack Path 1. A user saves a Temu access token using `save_temu_access_token.py`. 2. `_save_store()` creates or replaces the JSON file using permissions derived only from the current `umask`. 3. A local process or account with access to the user's home directory reads `~/.l ...[truncated 898 chars]- Remediation
View remediation
