T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:29- Finding
Temu access tokens are stored in plaintext without enforced restrictive permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/_temu_token_store.py, lines 10 and 29–35, with the sensitive value constructed at lines 62–68
Vulnerability Type: Plaintext credential storage and unsafe file permissions
Risk Level: HighVulnerable Code
python DEFAULT_STORE_PATH = os.path.expanduser("~/.linkfox/temu-access-tokens.json")python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n")The object passed to this function contains the unencrypted token:
python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), }Technical Analysis
The Skill stores long-lived Temu shop access tokens as plaintext JSON. The file is created with the process's default permissions, which depend on the current
umask; the code does not enforce mode0600, protect the containing directory with mode0700, reject symbolic links, or use an operating-system credential manager.Because these tokens authorize Temu shop API operations, possession of the file may be sufficient to impersonate the affected shop through the proxy. The optional
TEMU_TOKEN_STORE_PATHenvironment variable can also direct storage to a less secure location.Attack Path
- A user invokes
save_temu_access_token.py, causing a Temu token to be saved. - The token is written to
~/.linkfox/temu-access-tokens.json, or to the path specified byTEMU_TOKEN_STORE_PATH. - Another local user, compromised process, backup service, or workspace tool reads the file.
- The attacker extracts the plaintext
accessToken. - The attacker submits the token to compatible Temu or LinkFox proxy operations and acts with the token's ...[truncated 380 chars]
- A user invokes
- Remediation
View remediation
Remediation Suggestions
- Store tokens in an operating-system credential manager instead of a plaintext JSON file.
- If file storage is unavoidable:
- Create
~/.linkfoxwith mode0700. - Atomically create the token file with mode
0600. - Apply
os.chmod(path, 0o600)to existing stores during migration. - Reject symbolic links and verify that the resolved path is an expected regular file.
- Write through a securely created temporary file and atomically replace the destination.
- Create
- Avoid allowing arbitrary token-store paths unless explicitly required.
- Document token revocation, rotation, and cleanup procedures.
- Consider encrypting tokens at rest using a key held outside the token file.
