Back to skill

Security audit

Temu美国站-促销管理

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed LinkFox/Temu promotion helper, but it also exposes broad Temu proxying, local credential storage, and persistent response logging that go beyond a narrowly scoped US promotion tool.

Install only if you are comfortable giving this skill LinkFox and Temu merchant credentials, using broad gateway proxy scripts, and storing tokens plus full API responses on disk. Prefer using only the six promotion-specific scripts, avoid the generic proxy/file-download paths unless necessary, keep the workspace private, and delete or protect the local LinkFox/Temu output and token files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:28
Finding

Temu Access Tokens Are Stored in Plaintext Without Restrictive File Permissions

Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The data written by this function includes the complete Temu access token: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store defaults to `~/.linkfox/temu-access-tokens.json`. Tokens are serialized directly into a plaintext JSON document. The code creates the parent directory and output file without explicitly applying owner-only permissions. The resulting permissions therefore depend on the process umask and any pre-existing directory or file permissions. In an environment with a permissive umask, shared home directory, container volume, or inherited group-readable file, another local account or process may read the complete Temu access token. The file is also opened through an ordinary path without symlink checks or atomic replacement. If a less-trusted local actor can modify the token-store directory or configured `TEMU_TOKEN_STORE_PATH`, that actor may be able to redirect writes to another filesystem target. ### Attack Path 1. A user invokes `save_temu_access_token.py`, causing a Temu token to be stored in the JSON file. 2. The host's umask or pre-existing filesystem permissions allow another local user or process to read the file. 3. The attacker opens `~/.linkfox/temu-access-tokens.json` and extracts the plaintext `accessToken`. 4. The attacker uses that token with compa ...[truncated 932 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:308
Finding

Complete API Responses Are Persisted Without Restrictive Permissions or Retention Controls

Content
View full analysis
//data/-.json;大响应只打印摘要。无缓存。""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf-8") as f: f.write(serialized) print(f"Saved full response: {out} ({len(serialized)} bytes)") except OSError as e: print(f"Failed to save to {out}: {e}", file=sys.stderr) _lf_update_meta(session_dir, skill=slug, file_rel=os.path.relpath(out, session_dir), ts=ts) if inline or len(serialized.encode("utf-8")) <= LF_SMALL_THRESHOLD: print(serialized) else: _lf_summarize(result) ``` ### Technical Analysis Every API response is serialized in full and written to a predictable `linkfox///data/` hierarchy. The code does not: - Apply owner-only permissions to the directories or response files. - Redact secrets or sensitive merchant fields before persistence. - Define a retention period or automated cleanup mechanism. - Ask the user to opt into persistence. - Prevent the output hierarchy from being included in backups, synchronization systems, or source-control commits. The stdout summarization applied to responses larger than 8 KB does not reduce the persistence risk because ...[truncated 1485 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:210
Finding

Unsanitized SESSION_ID Can Redirect Output Outside the Intended Session Directory

Content
View full analysis
str: env = os.environ.get("SESSION_ID") if env: return env.strip() if "_auto" not in _LF_SESSION_CACHE: _LF_SESSION_CACHE["_auto"] = ( _lf_time.strftime("%H%M%S", _lf_time.localtime(ts)) + "-" + _lf_secrets.token_hex(3) ) return _LF_SESSION_CACHE["_auto"] ``` It is subsequently inserted directly into a filesystem path: ```python sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) ``` The onboarding script independently implements the same pattern: ```python def session_dir() -> str: ts = time.time() sid = (os.environ.get("SESSION_ID") or "").strip() or ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3)) path = os.path.join(_linkfox_root(), time.strftime("%Y-%m-%d", time.localtime(ts)), sid) os.makedirs(path, exist_ok=True) return path ``` ### Technical Analysis `SESSION_ID` is treated as a trusted path component, but no validation rejects: - Absolute paths. - `..` traversal components. - Platform-specific directory separators. - Excessively long or malformed identifiers. With `os.path.join`, an absolute final component can discard preceding path components. Relative traversal components can also escape the intended date and root directories after path normalization. The API scripts create `_meta.json`, response files, and index entries beneath the resul ...[truncated 1849 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/_temu_common.py:176
Finding

Sensitive API Responses May Fall Back to the Shared Temporary Directory Contrary to Documentation

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root fallback = os.path.abspath(candidates[-1]) _LF_SESSION_CACHE["_root"] = fallback return fallback ``` `SKILL.md:39` states that output must not be written to `/tmp` and that the script should fail if the current location is not writable. The implementation instead tries the home directory and then the system temporary directory. ### Technical Analysis When earlier candidate paths cannot be used, the implementation selects `/linkfox`. On Unix-like systems this commonly resolves beneath `/tmp`, which directly contradicts the documented guarantee. Although the `linkfox` subdirectory may be created with permissions affected by the current umask, shared temporary roots introduce additional risks: - Other local users may discover retained data if permissions are permissive. - A pre-existing directory m ...[truncated 1507 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (52)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The POST destination is derived from environment-configurable base URLs, so whoever controls the runtime environment can redirect login and token-issuance traffic to an attacker-controlled endpoint. Because these requests carry phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys, this becomes a credential-exfiltration and SSRF-style risk rather than a harmless configurability feature.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway request uses a URL built from environment-controlled base configuration and sends the Authorization API key header to that host. If an attacker can influence environment variables, they can redirect these calls to capture API keys or force requests to arbitrary internal/external services, creating both secret leakage and SSRF risk.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A file-download action driven by arbitrary URL-like input exceeds the stated promotion/coupon/flash-sale scope and can become a data exfiltration path. In an agent setting, even indirect download capabilities should be treated as sensitive because they may retrieve and persist user-inaccessible resources.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file implements SMS login, API-key issuance, subscription ordering, and payment flows that are unrelated to a Temu US promotion integration. In the context of this skill, the code materially expands capability into account onboarding and monetization, increasing the chance of credential harvesting, unauthorized account linking, and deceptive billing behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The billing features let the skill enumerate plans, create orders, and render payment QR codes, which is not justified by the stated business purpose of a Temu promotion API wrapper. Hidden payment capability inside an unrelated skill is especially dangerous because it can induce users to purchase services or expose transaction metadata under misleading context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code accepts any caller-supplied type value and forwards it to the backend proxy without enforcing a promotion-only allowlist. In this skill context, that means a user can potentially reach unrelated Temu APIs such as product, pricing, or other privileged operations, bypassing the intended separation between skills and violating least privilege.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares capabilities that include environment access, file writes, and network access, but does not declare an explicit tool scope or allowlist. That makes the effective privilege boundary unclear and increases the chance the skill can perform sensitive actions beyond what users expect, especially because it handles tokens and writes data to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description is written to trigger on Chinese terms and presents the skill as a Chinese-language interface for a US promotion API, but it does not state that users may choose another language. Under the policy, language or locale constraints should not be imposed without explicit opt-in or a clearly documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation says only six promotion interfaces are integrated, yet it also advertises generic gateway and token-management capabilities. This discrepancy obscures the true attack surface and can lead to overly broad trust in a skill that does more than its headline suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that full API responses are always written to local files, but does not warn that those responses may contain sensitive business records, identifiers, or tokens. Persistent unredacted logging increases the risk of later disclosure through filesystem access, backups, source-control mistakes, or agent context ingestion.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Persistent logging of full API responses into session-scoped local files creates a concrete data-retention and leakage risk, especially since the skill also handles tokens and promotion/business data. In an agent environment, these files may be accessible to later tasks, other tools, or operators, amplifying the exposure window.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Local persistence and retrieval of Temu access tokens is a real secret-management risk because it introduces credential storage, discovery, and possible leakage on disk. In the context of an API skill, this is more dangerous because the same tool can both access secrets and use them for network operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Generic cross-site gateway forwarding exceeds the claimed Temu US promotion scope and can enable access to unrelated APIs or regions. In context, this makes the skill more dangerous because the declared specialization may cause reviewers to overlook its broader proxy power.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly instructs users to persist a Temu access token to a local JSON file and even shows how to pass the raw token on the command line, but it does not warn that the token is a sensitive secret. Local disk storage and shell arguments can expose tokens through weak filesystem permissions, backups, shell history, process listings, or shared workstation access, enabling unauthorized API use against the seller account.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.