Back to skill

Security audit

Temu欧洲站-促销

Security checks for vulnerabilities and agentic risk

Overview

This skill is a mostly disclosed Temu promotion connector, but it gives agents broader API, credential, billing, and local persistence capabilities than a narrow EU promotion skill needs.

Review carefully before installing. Use it only with Temu and LinkFox accounts you intend to expose to this connector, avoid the generic proxy unless necessary, do not store broad or long-lived tokens in the plaintext local store, verify all update/deactivation/payment actions before running them, and treat saved linkfox output directories as sensitive data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:29
Finding

Temu access tokens are stored in plaintext without enforced restrictive permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/_temu_token_store.py, lines 10 and 29–35, with the sensitive value constructed at lines 62–68
Vulnerability Type: Plaintext credential storage and unsafe file permissions
Risk Level: High

Vulnerable Code

python
DEFAULT_STORE_PATH = os.path.expanduser("~/.linkfox/temu-access-tokens.json")
python
def _save_store(data: dict) -> None:
    path = store_path()
    parent = os.path.dirname(path)
    if parent:
        os.makedirs(parent, exist_ok=True)
    with open(path, "w", encoding="utf-8") as f:
        json.dump(data, f, indent=2, ensure_ascii=False)
        f.write("\n")

The object passed to this function contains the unencrypted token:

python
entry = {
    "site": site,
    "managementType": management_type,
    "tokenPurpose": token_purpose,
    "accessToken": access_token,
    "updatedAt": _utc_now(),
}

Technical Analysis

The Skill stores long-lived Temu shop access tokens as plaintext JSON. The file is created with the process's default permissions, which depend on the current umask; the code does not enforce mode 0600, protect the containing directory with mode 0700, reject symbolic links, or use an operating-system credential manager.

Because these tokens authorize Temu shop API operations, possession of the file may be sufficient to impersonate the affected shop through the proxy. The optional TEMU_TOKEN_STORE_PATH environment variable can also direct storage to a less secure location.

Attack Path

  1. A user invokes save_temu_access_token.py, causing a Temu token to be saved.
  2. The token is written to ~/.linkfox/temu-access-tokens.json, or to the path specified by TEMU_TOKEN_STORE_PATH.
  3. Another local user, compromised process, backup service, or workspace tool reads the file.
  4. The attacker extracts the plaintext accessToken.
  5. The attacker submits the token to compatible Temu or LinkFox proxy operations and acts with the token's ...[truncated 380 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store tokens in an operating-system credential manager instead of a plaintext JSON file.
  2. If file storage is unavoidable:
    • Create ~/.linkfox with mode 0700.
    • Atomically create the token file with mode 0600.
    • Apply os.chmod(path, 0o600) to existing stores during migration.
    • Reject symbolic links and verify that the resolved path is an expected regular file.
    • Write through a securely created temporary file and atomically replace the destination.
  3. Avoid allowing arbitrary token-store paths unless explicitly required.
  4. Document token revocation, rotation, and cleanup procedures.
  5. Consider encrypting tokens at rest using a key held outside the token file.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:310
Finding

Complete API responses are persistently stored without redaction or access controls

Content
View full analysis

Vulnerability Details

File Location: scripts/_temu_common.py, lines 310–327
Vulnerability Type: Persistent storage of potentially sensitive API data
Risk Level: Medium

Vulnerable Code

python
def emit_result(result, slug=SLUG, inline=False):
    """落盘完整响应到 linkfox/<date>/<session>/data/<slug>-<ts>.json;大响应只打印摘要。无缓存。"""
    serialized = json.dumps(result, ensure_ascii=False, indent=2)
    ts = _lf_time.time()
    date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts))
    sid = _lf_session_id(ts)
    root = _lf_root()
    session_dir = os.path.join(root, date_str, sid)
    os.makedirs(session_dir, exist_ok=True)
    _lf_ensure_meta(root, session_dir, date_str, sid, ts)
    data_dir = os.path.join(session_dir, "data")
    os.makedirs(data_dir, exist_ok=True)
    out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json")
    try:
        with open(out, "w", encoding="utf-8") as f:
            f.write(serialized)
        print(f"Saved full response: {out} ({len(serialized)} bytes)")
    except OSError as e:
        print(f"Failed to save to {out}: {e}", file=sys.stderr)
    _lf_update_meta(session_dir, skill=slug, file_rel=os.path.relpath(out, session_dir), ts=ts)

Technical Analysis

Every API result is serialized and stored in full. There is no field-level redaction, sensitivity classification, retention period, encryption, or explicit restrictive file mode.

Promotion and generic Temu API responses can contain product identifiers, supplier pricing, inventory quantities, promotion details, account metadata, operational results, and gateway error details. Even when stdout only displays a summary for large responses, the complete response remains on disk.

The implementation also falls back to the user's home directory and then the system temporary directory if preferred locations are unavailable. This expands the number of locations in which sensitive data may be retained.

Attack Path

  1. A user executes a pro ...[truncated 715 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make response persistence opt-in rather than mandatory.
  2. Redact credentials, authorization values, personal information, and sensitive commercial fields before writing.
  3. Create storage directories with mode 0700 and response files with mode 0600.
  4. Encrypt sensitive response archives at rest.
  5. Add configurable retention and secure deletion policies.
  6. Do not fall back to a shared temporary directory for sensitive data.
  7. Warn users before persisting responses and clearly report the storage location.
  8. Add ignore rules to prevent the linkfox/ output directory from being committed to source control.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:209
Finding

Unsanitized SESSION_ID permits path traversal and output redirection

Content
View full analysis

Vulnerability Details

File Location: scripts/_temu_common.py, lines 209–214 and 315–322; equivalent behavior also exists in scripts/onboarding.py, lines 152–159
Vulnerability Type: Path traversal through an environment-controlled path component
Risk Level: High

Vulnerable Code

python
def _lf_session_id(ts: float) -> str:
    env = os.environ.get("SESSION_ID")
    if env:
        return env.strip()
    if "_auto" not in _LF_SESSION_CACHE:
        _LF_SESSION_CACHE["_auto"] = (
            _lf_time.strftime("%H%M%S", _lf_time.localtime(ts)) + "-" + _lf_secrets.token_hex(3)
        )
    return _LF_SESSION_CACHE["_auto"]

The value is subsequently used directly in a filesystem path:

python
sid = _lf_session_id(ts)
root = _lf_root()
session_dir = os.path.join(root, date_str, sid)
os.makedirs(session_dir, exist_ok=True)
_lf_ensure_meta(root, session_dir, date_str, sid, ts)
data_dir = os.path.join(session_dir, "data")
os.makedirs(data_dir, exist_ok=True)
out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json")

The onboarding implementation has the same issue:

python
sid = (os.environ.get("SESSION_ID") or "").strip() or (
    time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3))
path = os.path.join(_linkfox_root(), time.strftime("%Y-%m-%d", time.localtime(ts)), sid)
os.makedirs(path, exist_ok=True)

Technical Analysis

SESSION_ID is treated as a trusted directory name even though it comes from the process environment. Values containing .., path separators, or an absolute path can escape the intended linkfox/&lt;date&gt;/ directory.

Python's os.path.join() discards preceding components when a later component is absolute. Relative traversal components can also resolve outside the intended directory. The code does not normalize the resulting path and verify that it remains under the approved root.

The exploitable output includes API response JSON, session metadata, and onboarding ...[truncated 1108 chars]

Remediation
View remediation

Remediation Suggestions

  1. Validate SESSION_ID against a strict allowlist, such as:
    python
    if not re.fullmatch(r"[A-Za-z0-9._-]{1,64}", sid):
        raise ValueError("Invalid SESSION_ID")
    
  2. Explicitly reject absolute paths, .., /, \, null bytes, and platform-specific separators.
  3. Resolve the candidate and root paths and verify containment using os.path.commonpath().
  4. Generate a safe internal identifier when the supplied value is invalid.
  5. Apply the same validation in both _temu_common.py and onboarding.py.
  6. Add tests for absolute paths, traversal strings, Windows drive paths, UNC paths, and encoded separators.

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:184
Finding

Onboarding instructs installation of unpinned third-party packages

Content
View full analysis

Vulnerability Details

File Location: scripts/onboarding.py, lines 162–166 and 184–187
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: Medium

Vulnerable Code

When QR dependencies are unavailable, the script instructs installation using:

text
pip install qrcode pillow

When the HTTP dependency is unavailable, it instructs installation using:

text
pip install requests

The relevant control flow is:

python
try:
    import requests
except ImportError:
    requests = None
python
def _require_requests() -> None:
    if requests is None:
        raise RuntimeError(...)

Technical Analysis

The installation guidance does not specify package versions, cryptographic hashes, a lockfile, or a trusted package index. A future compromised release, dependency-chain compromise, malicious package-index configuration, or incompatible update could therefore execute code during installation or runtime.

The package names shown are established packages rather than apparent typosquatting names, so this is not evidence that the project intentionally introduces a malicious dependency. The weakness is the non-reproducible and unauthenticated dependency acquisition process.

Attack Path

  1. The user invokes an onboarding function without the required package installed.
  2. The script directs the user to run an unpinned pip install command.
  3. Package resolution occurs against the user's configured Python package index.
  4. A compromised release, malicious mirror, or dependency-chain package is downloaded.
  5. Installation-time or imported package code executes with the user's privileges.

Impact Assessment

Successful supply-chain compromise could execute arbitrary code under the account running the installation. That code could access the same files, environment variables, LinkFox API keys, and Temu token store available to the Skill process.

Remediation
View remediation

Remediation Suggestions

  1. Provide a reviewed dependency manifest with exact versions.
  2. Use hash-verified installation, such as a locked requirements file consumed with pip install --require-hashes.
  3. Document the expected trusted package index.
  4. Pin transitive dependencies through a reproducible lock process.
  5. Run dependency vulnerability and provenance checks in CI.
  6. Prefer bundling onboarding dependencies with the Skill's managed environment rather than directing users to install mutable packages interactively.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/temu_proxy.py:31
Finding

Generic API proxy and account-payment features exceed the minimum EU promotion scope

Content
View full analysis

Vulnerability Details

File Location: scripts/temu_proxy.py, lines 31–49; broader account and payment operations are implemented in scripts/onboarding.py, lines 297–348 and 365–489
Vulnerability Type: Excessive capability and insufficient API operation restriction
Risk Level: High

Vulnerable Code

The generic proxy accepts an arbitrary Temu API type:

python
def build_request(params: dict) -> dict:
    site = validate_site(require_text(params, "site"))
    management_type = validate_management_type(
        require_text(params, "managementType")
    )
    access_token = resolve_access_token(params)
    api_type = require_text(params, "type")

    body = {
        "site": site,
        "managementType": management_type,
        "accessToken": access_token,
        "type": api_type,
    }
    if "params" in params and params["params"] is not None:
        if not isinstance(params["params"], dict):
            print("Error: 'params' must be a JSON object.", file=sys.stderr)
            sys.exit(1)
        body["params"] = params["params"]
    return body

The onboarding module also implements package purchasing and account-token generation:

python
def create_order(plan_id: str, method: str) -> dict:
    if method not in PAY_METHOD_MAP:
        raise ValueError(...)
    user = fetch_user_info()
    is_team = bool(user.get("isTeamUser"))
    member_id = _jwt_uid().get("uid", "")
python
def _get_or_generate_api_token(access_token: str, user_id: str, group_id: str) -> dict:
    hdr = _headers("agent-linkfox-web", "ai.linkfox.com",
                   access_token=access_token, user_id=user_id, group_id=group_id)
    for path, source in (("/group/getApiToken", "existing"),
                         ("/group/generateApiToken", "generated")):
        resp = _http_post(f"{_agent_user_base()}{path}", {"id": group_id}, hdr)

Technical Analysis

The declared core function is EU promotion management using six documented promotio ...[truncated 1911 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the generic multi-site proxy from this promotion-specific Skill.
  2. If a proxy is required, allowlist only the six documented promotion API types.
  3. Enforce site="eu" and the intended management model unless a separately authorized workflow explicitly requires alternatives.
  4. Separate account registration, API-key generation, billing, purchasing, and payment operations into a distinct Skill.
  5. Require explicit user confirmation before registration, token generation, order creation, or any financial operation.
  6. Apply authorization checks per operation instead of relying solely on the upstream token scope.
  7. Log the selected operation without logging credentials and present a clear summary before executing mutation or payment requests.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (50)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The code sends authentication material and other sensitive request data to a URL whose base is taken from environment variables without any allowlist or origin validation. In a skill/runtime environment where env can be influenced, this enables server-side request forgery and credential exfiltration to attacker-controlled endpoints through requests.post.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The gateway request target is constructed from environment-derived base URLs and then used in urlopen together with the API key in the Authorization header. If an attacker can set or influence those environment variables, the CLI can be coerced into sending secrets and business actions to an attacker-controlled server or unintended internal network target.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents a generic proxy script for arbitrary Temu API types rather than only the specific promotion endpoints it claims to cover. That effectively turns a business-specific connector into a broad API forwarding primitive, enabling access to non-promotion functionality and undermining least privilege.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script accepts user-controlled JSON that can set "mask": false, causing locally stored Temu access tokens to be printed in cleartext. A promotion-focused skill has no justified need to disclose bearer credentials, and any party able to invoke this utility could obtain reusable secrets for unauthorized API access, account abuse, or lateral movement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements LinkFox account onboarding, login, API key acquisition, package listing, ordering, and payment support, which is materially unrelated to a Temu EU promotion API skill. Such scope drift is dangerous because it introduces sensitive identity, billing, and credential-management capabilities users would not reasonably expect from the declared skill purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill can list purchasable plans, create orders, and render payment QR codes, giving it billing and transaction capability outside its declared promotion-management scope. In context, this makes the skill more dangerous because a user invoking a promotion API skill could be steered into unintended purchases or account charges.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code performs SMS login, token exchange, user/team discovery, and API key generation for LinkFox accounts, which goes well beyond a Temu promotion integration. In this context, the mismatch increases risk because the skill collects credentials and provisions long-lived access in a place where users expect only partner promotion API operations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and documents capabilities that use environment variables, local file writes, and outbound network access, but it does not declare any corresponding tool scope or permission boundaries. This weakens reviewability and increases the chance that an agent can invoke sensitive capabilities without explicit least-privilege constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are very broad, covering multiple overlapping promotion and product-inventory concepts without clear boundaries. Over-broad activation increases the risk that the skill is invoked in contexts where its network, token, and file-handling capabilities are unnecessary, leading to unintended data access or external requests.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs default persistent logging of complete API responses into local session-organized files, and those responses may contain access tokens, account identifiers, business data, or other sensitive content. Persisting full responses by default materially increases the risk of secret leakage, cross-task exposure, long-term retention, and accidental inclusion in future prompts or logs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states both that use of the tool consumes points and later that it does not consume points. Contradictory billing/cost guidance can cause an agent or operator to perform repeated calls under false assumptions, potentially leading to unwanted charges, quota exhaustion, or unsafe retry behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation recommends persisting Temu access tokens locally in a JSON file and shows commands that insert raw tokens, but it does not explicitly warn that these are sensitive credentials or describe file-permission, encryption, rotation, and logging risks. If stored insecurely, the tokens could be read by other local users, leaked via backups or shell history, and then used to access Temu business APIs through the gateway.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents bg.promotion.activity.goods.update with actions including price changes, quantity changes, delisting, and adding SKU, which can materially affect user data and business state. The surrounding documentation explains how to call the API but does not include a warning about these potentially disruptive operations or advise users to verify targets before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation includes operateType = 30 to deactivate activity goods but does not clearly warn that this is a destructive state-changing operation requiring explicit user confirmation. In an agent skill context, ambiguous docs increase the risk that an LLM or integrator performs unintended deactivation of promotional listings, causing business disruption or revenue loss.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.