T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:27- Finding
Temu access tokens are stored in plaintext without restrictive file permissions
- Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The data written by this function contains the complete Temu credential: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token database defaults to `~/.linkfox/temu-access-tokens.json`. The code creates the parent directory and token file without explicitly enforcing private permissions. Consequently, the resulting permissions depend on the process umask and any pre-existing directory or file. The complete reusable Temu access token is stored as plaintext JSON. There are also no checks for: - File or directory ownership. - Symbolic links. - Files writable or readable by other users. - Atomic replacement of the credential file. - Encryption through an operating-system credential service. If `TEMU_TOKEN_STORE_PATH` points to an unsafe location, the same code will write credentials there without validating the target. ### Attack Path 1. A user invokes `save_temu_access_token.py` to store a Temu access token. 2. `_save_store()` creates or overwrites the configured JSON file using normal process permissions. 3. A permissive umask, unsafe custom path, pre-existing file, or shared parent directory makes the file accessible to another local account or process. 4. The attacker reads the plaintext `accessToken` value. 5. The attacker reuses the token through ...[truncated 684 chars]- Remediation
View remediation
