Back to skill

Security audit

Temu欧洲站-退货退款

Security checks for vulnerabilities and agentic risk

Overview

This Temu returns skill has a plausible purpose, but it needs review because it includes broad proxy access and weak handling of sensitive merchant data and credentials.

Install only after reviewing whether broad Temu proxying is acceptable for your account. Use the fixed returns/refunds scripts rather than generic proxy scripts where possible, keep LinkFox and Temu tokens out of chat logs and shell history, secure or avoid plaintext token storage, review saved response files for sensitive customer/business data, and verify the actual billing/credit behavior before running repeated calls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:27
Finding

Temu access tokens are stored in plaintext without restrictive file permissions

Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The data written by this function contains the complete Temu credential: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token database defaults to `~/.linkfox/temu-access-tokens.json`. The code creates the parent directory and token file without explicitly enforcing private permissions. Consequently, the resulting permissions depend on the process umask and any pre-existing directory or file. The complete reusable Temu access token is stored as plaintext JSON. There are also no checks for: - File or directory ownership. - Symbolic links. - Files writable or readable by other users. - Atomic replacement of the credential file. - Encryption through an operating-system credential service. If `TEMU_TOKEN_STORE_PATH` points to an unsafe location, the same code will write credentials there without validating the target. ### Attack Path 1. A user invokes `save_temu_access_token.py` to store a Temu access token. 2. `_save_store()` creates or overwrites the configured JSON file using normal process permissions. 3. A permissive umask, unsafe custom path, pre-existing file, or shared parent directory makes the file accessible to another local account or process. 4. The attacker reads the plaintext `accessToken` value. 5. The attacker reuses the token through ...[truncated 684 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/get_temu_access_token.py:52
Finding

Credential-management workflows expose full tokens through standard output and command-line arguments

Content
View full analysis
None: print(json.dumps(obj, ensure_ascii=False, indent=2)) ``` The login parser accepts a phone number and SMS verification code as positional command-line arguments: ```python p = sub.add_parser("login", help="SMS verification login and API key retrieval") p.add_argument("phone") p.add_argument("code", help="SMS verification code") ``` The documented invocation is effectively: ```text python scripts/onboarding.py login ``` ### Technical Analysis Full credentials printed to standard output can be captured by: - Agent conversation transcripts. - Terminal scrollback. - Shell redirection. - CI or automation logs. - Host telemetry and command-output collection. - Parent processes invoking the script. Passing a phone number and on ...[truncated 1496 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:176
Finding

Complete returns and refunds responses may be written to unsafe locations with permissive permissions

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root ``` The complete response is then written without explicit private permissions: ```python out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf-8") as f: f.write(serialized) print(f"Saved full response: {out} ({len(serialized)} bytes)") except OSError as e: print(f"Failed to save to {out}: {e}", file=sys.stderr) ``` ### Technical Analysis The implementation always serializes and persists the full gateway response. Returns and refunds responses may contain: - Customer names and addresses. - Order and after-sales identifiers. - Return warehouse addresses. - Tracking information. - Refund and t ...[truncated 1903 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:162
Finding

Onboarding guidance recommends installation of unpinned third-party packages

Content
View full analysis
dict: try: import qrcode except ImportError: # The emitted error directs the user to install qrcode and pillow. return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: # The raised error directs the user to install requests. raise RuntimeError(...) ``` ### Technical Analysis The recommended pip commands do not specify: - Exact package versions. - Cryptographic hashes. - A trusted package index. - A locked dependency manifest. - A controlled virtual environment. As a result, the installed code can change after the Skill has been reviewed. Pip configuration may also redirect resolution to an untrusted or compromised index. Python packages may execute code during installation and will execute code when imported by the onboarding script. No evidence was found that these package names are intentionally malicious. The risk is the mutable and unauthenticated dependency installation procedure rather than a confirmed malicious dependency. ### Attack Path 1. A user invokes an onboarding feature on a system missing `requests`, `qrcode`, or `pillow`. 2. The script emits an installation instruction. 3. The user runs the unpinned pip command. 4. Pip resolves packages using the current index and local configuration. 5. A compromised release, compromised index, or dependency-substitution condition supplies malicious code. 6. The malicious package ex ...[truncated 499 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (66)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The POST target URL is derived from environment-controlled base URLs, and this function is used on authentication flows that transmit SMS-login data, access tokens, refresh tokens, and API-token generation requests. If an attacker can influence environment variables, they can redirect these requests to an attacker-controlled endpoint and exfiltrate credentials and session material; in this skill, that risk is amplified because the script explicitly handles login and API-key issuance.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway request URL is built from environment-controlled base configuration and then used with an Authorization header carrying the agent API key. An attacker who can set the environment can redirect order, account, and package requests to their own server and capture the bearer credential or manipulate downstream behavior; because this file is unrelated to the declared Temu returns skill, the unexpected credential-handling makes the exposure more concerning.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A generic proxy that accepts arbitrary type values can invoke unrelated Temu APIs beyond returns/refunds, defeating the declared functional boundary. In an agent environment, that effectively turns the skill into a broad API tunneling mechanism, increasing the risk of unauthorized actions and access to unrelated data domains.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements LinkFox onboarding, login, API-key retrieval, subscription discovery, order creation, and payment handling, which are unrelated to a Temu EU returns/refunds integration. Such scope divergence is dangerous because it introduces hidden credential-collection and monetization behavior under the cover of a different skill, increasing the likelihood of deceptive data harvesting or unauthorized account actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code can create purchase orders and render payment QR codes, functionality with no clear justification for a Temu EU aftersales API connector. In the context of a mismatched skill, embedded payment flows create a strong risk of unauthorized charges, social engineering, or monetization behavior concealed inside an unrelated integration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script exposes a signed file download path through an EU returns/refunds skill even though file download is outside the manifest's declared aftersales scope. That scope mismatch is dangerous because it can give callers an unexpected capability to retrieve arbitrary signed URLs or sensitive artifacts via the LinkFox gateway, weakening least-privilege and making data exfiltration or unauthorized document access more likely if the skill is broadly routable.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly describes and implements a generic Temu proxy that accepts arbitrary API type values and forwards them via a common proxy endpoint, which exceeds the skill’s declared EU returns/refunds-only scope. In an agent setting, this scope mismatch is dangerous because users and downstream policy may trust the manifest boundaries while the code can invoke unrelated Temu APIs, enabling unauthorized or unintended actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The request builder accepts a user-supplied site value validated only by a generic site validator, and the usage example even references "cn", despite the skill being advertised as a Temu Europe capability. This makes the skill materially broader than represented and could route requests to non-EU regions, undermining regional restrictions, governance expectations, and least-privilege assumptions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares network, environment-variable, and file-write behaviors but provides no explicit tool scope or permission boundaries. In an agent setting, this increases the chance of overbroad execution, unintended external transmission, or local persistence of sensitive data without clear restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes sending data to an external LinkFox gateway without a clear user-facing warning that order and aftersales information will leave the local environment. In a privacy-sensitive commerce context, silent off-device transmission can expose customer, order, and refund data to third-party infrastructure unexpectedly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L035 明确写明“本工具会消耗积分”,并要求失败或空结果不得连续试探以避免额外成本;但 L121-L123 的“积分消耗规则”又写“ 不消耗积分”。这不是单纯信息缺失,而是同一技能文档对调用计费属性给出相互冲突的意图说明,可能误导使用者的调用决策。

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Always saving complete API responses and sometimes printing full JSON to stdout can leak authentication material and sensitive aftersales data into logs, terminal history, CI artifacts, chat transcripts, or shared directories. Because the workflow is framed as routine guidance, users may not realize the extent of plaintext exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs unconditional writing of full API responses to the working directory, which may include access tokens, personal order data, return/refund records, shipping details, or other sensitive aftersales content. Persisting full responses by default greatly increases accidental disclosure risk through source trees, shared workspaces, backups, or later tool reads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document recommends saving long-lived Temu access tokens to a predictable local file path and shows commands that persist raw credentials, but it does not warn that these tokens are sensitive secrets or describe required file-permission and encryption safeguards. If a workstation, home directory, backup, shell history, or shared environment is exposed, an attacker could recover the token and use it to access Temu business APIs through the gateway.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.