Back to skill

Security audit

Temu全球站-定价

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly disclosed as a Temu pricing gateway, but it includes broad proxy, download, billing, and credential-storage powers that deserve manual review before use.

Review this before installing if you will use real seller credentials. Use it only in a trusted environment, avoid raw token output, restrict file permissions on token stores, verify gateway environment variables, and require explicit human confirmation before any batch price changes or billing/order actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_token_store.py:28
Finding

Temu Access Tokens Are Stored in Plaintext Without Enforced File Permissions

Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The data written by this function includes the reusable Temu access token: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store defaults to `~/.linkfox/temu-access-tokens.json` and persists reusable Temu access tokens as unencrypted JSON. The save operation uses the process's default `umask` and does not explicitly enforce restrictive permissions on either the parent directory or the token file. Consequently, the final permissions may allow other local accounts, processes, containers, backup agents, or workspace-integrated tools to read the credentials. The implementation also uses a direct non-atomic write and does not protect against symbolic-link replacement. These weaknesses are particularly significant because the stored value is an authentication credential used to invoke merchant APIs. Local persistence is consistent with the documented `storeKey` feature, but persisting a bearer-style credential without explicit access controls exceeds the minimum safe implementation needed for that feature. ### Attack Path 1. A user saves a Temu access token using `save_temu_access_token.py`. 2. `_save_store()` creates or replaces the JSON file using permissions derived only from the current `umask`. 3. A local process or account with access to the user's home directory reads `~/.l ...[truncated 898 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_temu_access_token.py:51
Finding

Credential Retrieval Command Exposes the Complete Temu Access Token on Standard Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/onboarding.py:162
Finding

Onboarding Guidance Recommends Installing Unpinned Third-Party Packages

Content
View full analysis
dict: try: import qrcode except ImportError: err = "Missing qrcode dependency; run: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} os.makedirs(out_dir, exist_ok=True) png_path = os.path.join(out_dir, f"qr-{int(time.time() * 1_000_000)}.png") qr = qrcode.QRCode(border=1) qr.add_data(content) qr.make(fit=True) qr.make_image(fill_color="black", back_color="white").save(png_path) buf = io.StringIO() qr.print_ascii(out=buf, invert=True) return {"png_path": png_path, "ascii_qr": buf.getvalue()} def _require_requests() -> None: if requests is None: raise RuntimeError("Missing requests dependency; run: pip install requests") ``` The displayed English messages above are faithful translations of the source messages; the recommended package commands are unchanged. ### Technical Analysis The onboarding utility directs users to install `qrcode`, `pillow`, and `requests` directly from the configured Python package index without fixed versions, integrity hashes, or a reviewed lockfile. Package resolution therefore depends on mutable registry state and the user's package-index configuration at installation time. This does not prove that the named packages are malicious. The risk is that future compromised releases, a malicious configured mirror, dependency confusion, or incompatible package updates could introduce code that runs in the user's Python environment. Python packages may execute installation-time build logic and will execute imported module code at runtime. ### Attack Path 1. The onboarding command runs in an environment wh ...[truncated 1105 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (56)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The POST destination is derived from environment-controlled base URLs, and the function sends highly sensitive data including SMS login credentials, access tokens, refresh tokens, and generated API tokens to those endpoints. If an attacker can influence environment variables in the skill runtime, they can redirect authentication traffic to an attacker-controlled server and capture credentials or session material. The mismatch between the skill's declared Temu pricing purpose and this onboarding/login behavior increases suspicion because the exfiltration path is unrelated to the advertised function.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The gateway URL is also environment-derived, and urllib is used to send authenticated requests with the LINKFOX_AGENT_API_KEY in the Authorization header to whatever host the environment selects. This can leak API keys, user/package/order data, and enable server-side request forgery to arbitrary internal or external endpoints if runtime environment variables are attacker-controlled. In this skill, that is especially concerning because the code performs account, package, and payment operations unrelated to the declared Temu Global pricing scope.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary Temu API types and arbitrary site values is materially broader than a skill marketed as only five global pricing interfaces. Overbroad proxying can be abused to invoke unintended APIs, potentially expanding impact from pricing queries into unrelated account or product operations.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file's documented behavior is an onboarding/account-management CLI for SMS login, plan purchase, order querying, and API-key retrieval, which does not match the manifest's stated purpose of Temu Global pricing APIs. This kind of scope mismatch is a strong indicator of deceptive packaging or hidden functionality, making it easier to smuggle credential collection and payment operations into a skill users would trust for a narrower purpose. The dangerousness is amplified by the sensitivity of the handled data and the billing-related side effects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code can create paid orders and generate API tokens, capabilities that are unrelated to a Temu Global pricing skill and materially expand what the skill can do on behalf of a user. Such hidden or unnecessary capabilities create an opportunity for unauthorized purchases, account manipulation, and secret issuance under the guise of a benign pricing integration. The context makes this more dangerous because users invoking a pricing skill would not reasonably expect billing and token-provisioning workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements a generic Temu signed file download capability, which is outside the stated scope of a pricing-only global pricing skill. Scope mismatch in agent skills is dangerous because it silently expands the actions the agent can perform, enabling unintended access to signed resources or data exfiltration through a capability users and reviewers would not expect in this skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script exposes a file-download action even though the skill is described as a Temu Global pricing skill limited to pricing-related APIs. Scope expansion like this is dangerous because it gives the agent access to arbitrary download behavior via a user-supplied URL and access token, creating a capability mismatch that can enable data exfiltration or retrieval of unintended sensitive files through the LinkFox/Temu gateway.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script implements a generic Temu proxy that accepts an arbitrary API 'type' and forwards requests to the backend, while the skill metadata claims it is limited to 5 global pricing endpoints. That mismatch expands the reachable API surface far beyond the declared scope, enabling use of unrelated Temu operations with the caller's access token and undermining least-privilege and user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The build_request function copies user-controlled 'type' and 'params' directly into the forwarded body with no endpoint allowlist or operation-level authorization. In a pricing-only skill, this creates arbitrary API forwarding capability, which could be abused to query or mutate unrelated Temu resources if the upstream token has those permissions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documents capabilities to read environment variables, write files, and perform network requests, but it does not declare any explicit tool scope or allowed-tools boundary. In an agent environment, missing scope declarations can permit broader-than-expected access and make review, sandboxing, and policy enforcement significantly weaker.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L038 明确写明“本工具会消耗积分”,并要求失败或空结果时不要自动继续检索以避免额外消耗;但 L182 又写“不消耗积分”。这是同一技能文档内部对费用/副作用的直接矛盾,会误导调用方对执行成本和重试策略的判断。

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Always writing full API responses containing token-backed seller data to local session files, and sometimes echoing full JSON to stdout, creates a significant data leakage risk. Sensitive business data, identifiers, and possibly credentials can be exposed to other tools, logs, later prompts, or users with filesystem access, and the risk is amplified because the behavior is mandatory by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes batch price modification capability without a prominent warning about its write-side effects, approval expectations, or potential business impact. In an agent setting, insufficient user warning before state-changing commerce operations raises the risk of accidental mass repricing and financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document recommends persisting a Temu access token locally and even shows a plaintext example value, but it does not clearly warn that this token is a sensitive credential or describe the risks of storing it on disk. If the token file is readable by other local users, included in backups, synced to cloud storage, or accidentally committed/logged, an attacker could reuse it to access Temu business APIs and perform unauthorized operations such as price queries or bulk repricing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.