Back to skill

Security audit

Temu全球站-促销

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches a Temu promotion integration, but it also handles credentials, payments, broad API proxying, and persistent local storage in ways users should review carefully.

Install only if you are comfortable giving this skill LinkFox and Temu seller credentials, writing tokens and full API results to local disk, and using a broad proxy that is not limited to promotion APIs. Review endpoint environment variables, avoid shared workspaces for outputs, protect or delete the token store, and require explicit confirmation before billing, payment, or promotion-deactivation actions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:8
Finding

Reusable Temu Access Tokens Stored in Plaintext Without Restrictive File Permissions

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store writes reusable Temu access tokens directly to a plaintext JSON file. Neither the parent directory nor the token file is created with an explicit restrictive permission mode. The effective permissions therefore depend on the process umask and any pre-existing path permissions. On a multi-user system or permissively configured environment, another local user or process may be able to read the credential file. The implementation also does not verify whether an environment-provided `TEMU_TOKEN_STORE_PATH` points to a secure, user-owned location. Because the stored value is an actual bearer-style access token rather than a non-sensitive identifier, possession may be sufficient to make authorized Temu API calls within the token's granted scopes. ### Attack Path 1. A user invokes `save_temu_access_token.py` with a valid Temu access token. 2. `_save_store()` creates or overwrites the JSON token store using ordinary default permissions. 3. The resulting file is readable by another local principal due to the process umask, inherited director ...[truncated 756 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:176
Finding

Complete API Responses Persisted to Potentially Shared Locations Without Access Controls

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root ``` ```python def emit_result(result, slug=SLUG, inline=False): """Store the full response under the LinkFox session data directory.""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf-8") as f: f.write(serialized) print(f"Saved full response: {out} ({len(serialized)} ...[truncated 2169 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/temu_proxy.py:33
Finding

Unrestricted Generic Temu API Proxy Exceeds the Promotion Skill's Least-Privilege Scope

Content
View full analysis
dict: site = validate_site(require_text(params, "site")) management_type = validate_management_type( require_text(params, "managementType") ) access_token = resolve_access_token(params) api_type = require_text(params, "type") body = { "site": site, "managementType": management_type, "accessToken": access_token, "type": api_type, } if "params" in params and params["params"] is not None: if not isinstance(params["params"], dict): print("Error: 'params' must be a JSON object.", file=sys.stderr) sys.exit(1) body["params"] = params["params"] return body ``` ### Technical Analysis The Skill is declared as a Temu Global promotion integration with six documented promotion API operations. However, `temu_proxy.py` accepts an arbitrary caller-controlled `type` and forwards it to the gateway without checking that it belongs to the supported promotion API set. The script validates the site and management type, but it does not constrain the actual operation. Consequently, the effective authorization boundary is determined only by the Temu token and gateway. A broadly scoped token can therefore be used for non-promotion operations through a Skill that is presented as promotion-specific. The generic capability is mentioned in the documentation, so this is not a hidden backdoor. It nevertheless exceeds the minimum privilege required for the declared promotion functionality and expands the impact of prompt injection, erroneous tool calls, or malicious parameters. ### Attack Path 1. A valid LinkFox API key and Temu token are available to the Skill. 2. An attacker influences the tool arguments, or a ...[truncated 934 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/temu_file_download.py:30
Finding

Signed-File Download Helper Forwards Arbitrary URLs Without Validation

Content
View full analysis
dict: site = validate_site(require_text(params, "site")) management_type = validate_management_type( require_text(params, "managementType") ) access_token = resolve_access_token(params) url = require_text(params, "url") return { "site": site, "managementType": management_type, "accessToken": access_token, "url": url, } ``` The Global helper has the same behavior: ```python body = { "site": site, "managementType": management_type, "accessToken": resolve_access_token(params), "url": require_text(params, "url"), } return call_temu_api(FILE_DOWNLOAD_URL, body, timeout=timeout, linkfox_params=params) ``` ### Technical Analysis The file-download helper checks only that `url` is non-empty. It does not parse the URL, require HTTPS, restrict the hostname to documented Temu download domains, reject embedded credentials, or block loopback, private, link-local, and metadata-service destinations. The URL is sent to the remote LinkFox `/temu/fileDownload` endpoint. If the gateway independently validates destinations, exploitation may be prevented. If it performs a server-side fetch without equivalent restrictions, the helper can become an input channel for server-side request forgery. Because the gateway implementation was not part of the audited project, this finding identifies a client-side control gap and a conditional remote risk rather than proving that the LinkFox gateway is exploitable. ### Attack Path 1. An attacker controls or influences the `url` argument passed to the file-download script. 2. The script accepts the value because it is non-empty. 3. The URL is sent to `/temu/fileDownload` together with valid ...[truncated 823 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (49)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The POST target URL is derived from environment-controlled base URLs and the request may include sensitive headers such as authorization, uid, and tid. If an attacker can influence those environment variables, they can redirect login or token-generation traffic to an attacker-controlled host and capture SMS login tokens, API keys, or user metadata. In the context of a Temu promotion skill, this is more dangerous because the file performs credential onboarding and key provisioning unrelated to the declared purpose, increasing the chance that secrets are handled in a less scrutinized path.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The gateway request URL is also built from environment-controlled base configuration and is used with an Authorization header carrying the API key. An attacker who can tamper with the environment can force requests to an arbitrary endpoint, exfiltrating the API key and potentially manipulating account, package, or order operations. Because this skill is supposed to expose Temu promotion APIs, embedding a payment/account gateway client behind mutable endpoints materially broadens the attack surface.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill exposes a generic proxy for arbitrary Temu API types rather than a narrowly promotion-scoped interface. In context, that is dangerous because a user invoking a 'promotion' skill could unintentionally grant access to non-promotion domains, enabling lateral access to broader platform operations than advertised.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements SMS login, API key retrieval, subscription plan browsing, order creation, and payment QR rendering, which are unrelated to the declared Temu global promotion functionality. This kind of scope deviation is dangerous because it introduces credential collection and billing flows into a skill that users would not expect to handle onboarding or purchases, creating opportunity for phishing-like abuse and secret overcollection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code can create orders, query payment state, and render payment QR codes to local storage despite the skill being described as a Temu promotion API wrapper. Billing functionality in an unrelated skill creates a strong trust-boundary violation and could be abused to trick users into making payments or to process unauthorized purchases through the agent's credentials.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents capabilities involving environment variables, local file writes, and outbound network access, but does not declare any explicit tool scope such as allowed-tools or permissions. That creates an authorization gap where the agent may invoke broader capabilities than users or reviewers expect, reducing containment if the skill is misused or modified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger conditions are broad and ambiguous, causing the skill to activate on common promotion-related requests that may not require this networked, file-writing integration. Over-broad activation increases the chance of unnecessary secret handling, unintended API calls, or use of the wrong skill for a user’s task.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Contradictory billing/points-consumption instructions can mislead operators into taking repeated actions under false assumptions about cost, which is an integrity and consent problem. In security terms, inconsistent transactional guidance can facilitate unapproved spending or make users ignore warnings around paid operations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates saving full API responses to project-local files and sometimes printing complete JSON to stdout. Because these responses can contain access tokens, signed URLs, business data, or other sensitive fields, this behavior creates a direct data exposure path through local artifacts, logs, terminal history, and agent context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document recommends storing a Temu access token locally and even provides a default filesystem path, but it does not clearly warn that this token is a sensitive credential equivalent to account/API access. In a skill focused on e-commerce operations, these tokens can enable business actions against a seller account, so insecure local storage increases the risk of credential theft from shared machines, backups, logs, or overly permissive file permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document explicitly exposes an operation type 30 that deactivates promotion activity goods, but it does not warn that this is a destructive state-changing action or recommend confirmation before use. In an agent skill context, missing such guardrails can cause an automated workflow or user to unintentionally remove items from active promotions, leading to revenue loss or business disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to copy an access token from the seller backend and optionally save it locally, but does not state that the token is a sensitive credential or provide any storage/handling safeguards. In an authorization-flow document for a commerce integration, this omission can lead users to expose long-lived tokens in plaintext files, logs, screenshots, or insecure local stores, enabling unauthorized API access to shop data and operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file prescribes user-facing guidance entirely in Chinese, including prompts to ask the user and messages to relay, with no indication that language should match user preference. This creates a locale/language policy issue because it imposes a specific language without explicit user choice or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The onboarding flow explicitly asks the user to provide a phone number and then submits it to a registration script, but the instructions do not disclose that personal data will be transmitted to an external service or explain how it will be used, stored, or protected. In an agent context, this creates a privacy and consent gap that could lead to unauthorized collection or mishandling of personally identifiable information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.