Back to skill

Security audit

Temu全球站-退货退款

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Temu returns/refunds gateway integration, but it asks users to grant and store broad commerce credentials and includes generic proxy, billing, and persistence behavior that goes beyond a tightly scoped returns tool.

Review this before installing. Use a dedicated least-privilege Temu token if possible, avoid granting all or sensitive permissions unless you truly need them, do not store broad access tokens on shared machines, and expect full API responses to be saved locally. Be especially careful with return addresses, labels, refund/order identifiers, payment onboarding, and any use of the generic proxy or file-download scripts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/access-token.md:34
Finding

Authorization guide requires Temu permissions beyond the Skill's declared scope

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:29
Finding

Temu access tokens are stored in plaintext without enforced owner-only permissions and can be printed in full

Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` From `scripts/_temu_token_store.py:62-68`: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` From `scripts/get_temu_access_token.py:49-60`: ```python print( json.dumps( { "found": True, "storeKey": store_key, "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": token, }, indent=2, ensure_ascii=False, ) ) ``` ### Technical Analysis The token store writes the complete Temu access token to a plaintext JSON file. The code uses ordinary `os.makedirs()` and `open(..., "w")` operations without explicitly enforcing owner-only directory and file permissions. The actual permissions therefore depend on the process umask and any pre-existing path configuration. On a system with a permissive umask, shared home directory, custom `TEMU_TOKEN_STORE_PATH`, or incorrectly permissioned existing file, another local principal may be able to read the token. The retrieval utility additionally prints the complete token to stdout. Full credentials can consequently enter agent transcripts, terminal capture, CI logs, ...[truncated 1268 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:184
Finding

Complete returns and refunds responses are automatically persisted with unsafe fallback paths and no enforced access permissions

Content
View full analysis
//data/-.json;大响应只打印摘要。无缓存。""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf- ...[truncated 2389 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (56)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The POST target URL is derived from environment-controlled base URLs, so anyone who can influence LINKFOX_LOGIN_API_URL or LINKFOX_AGENT_USER_API_URL can redirect login and token-generation traffic to an attacker-controlled endpoint. Because these requests carry SMS-login credentials, access tokens, refresh tokens, and API-token operations, this becomes an SSRF/exfiltration issue rather than a harmless configurability feature. In the context of a Temu returns/refunds skill, this is more dangerous because the file is unrelated onboarding/account code handling sensitive credentials outside the advertised scope.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway request URL is built from environment-controlled configuration and then sent with the Authorization API key header via urlopen. An attacker who can set LINKFOX_AGENT_API_URL or LINKFOX_TOOL_GATEWAY can cause authenticated requests, order creation, and account queries to be sent to an arbitrary server, leaking the API key and enabling unintended outbound access. This is especially concerning here because the code also includes billing/order functions unrelated to the Temu aftersales skill, expanding the blast radius beyond the stated skill purpose.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements SMS login, API key issuance, plan listing, order purchase, and payment QR generation, which are operationally unrelated to a Temu global returns/refunds integration. Such scope divergence is a strong supply-chain risk signal because it introduces credential collection and monetization behavior into a skill that users would reasonably expect to only process aftersales APIs. The mismatch makes the package materially more dangerous in context, not less.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code contains billing and payment-order capabilities, including package enumeration, order creation, payment URL/QR handling, and order-status queries. In a skill advertised for Temu aftersales processing, these capabilities are unjustified and create a path for unauthorized purchases, financial abuse, or user deception if invoked by an agent or attacker. The off-purpose financial functionality significantly increases risk because it handles money movement adjacent to credentialed API access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements a generic Temu signed file download capability, while the skill manifest describes only returns/refunds aftersales operations. This mismatch expands the skill's effective privilege and can enable retrieval of arbitrary signed resources unrelated to the declared business purpose, undermining least-privilege and user/operator expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file implements a generic Temu proxy that accepts an arbitrary API "type" and forwards caller-supplied parameters, which exceeds the declared returns/refunds-only scope of the skill. In an agent context, this creates a scope-expansion vulnerability: a user or prompt can invoke unrelated Temu operations through this skill, potentially reaching sensitive or privileged APIs under the provided access token.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and instructs use of capabilities that include environment-variable access, filesystem writes, and outbound network requests, but it does not declare any explicit tool scope or allowed-tools boundary. In an agent setting, missing permission scoping increases the blast radius of accidental or adversarial use because the agent may exercise more capabilities than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger terms include broad, ambiguous keywords such as return, refund, and related mixed-language phrases without clear contextual boundaries. Overbroad triggers can cause the skill to activate in unrelated conversations, increasing the chance that secrets, tokens, or local files are accessed or written unexpectedly.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to always persist full API responses locally and optionally print them in full to stdout. Those responses may contain access tokens, customer data, addresses, return labels, refund details, or other sensitive aftersales information, creating clear risks of credential leakage, data over-retention, and exposure in logs or shared workspaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly recommends saving a Temu access token to a local file path and provides example commands that persist the credential, but it does not clearly warn that this creates a long-lived secret on disk that may be readable by other local users, backups, shell history, or malware. In a skill centered on e-commerce refunds and aftersales APIs, these tokens can authorize sensitive business actions and data access, so normalizing casual local storage increases the chance of credential leakage and account misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This document exposes that the API returns personally identifiable return-contact data such as recipient name, phone numbers, email, and full address, but it provides no privacy warning, data-minimization guidance, or handling restrictions. In a support or agent workflow, that omission can lead to over-collection, unnecessary display, logging, or sharing of sensitive contact information during return processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs users to copy a Temu access token from the seller backend and optionally save it to a local store, but it provides no warning that the token is a sensitive credential or any guidance on secure storage, masking, rotation, or least-privilege handling. In the context of an API skill that uses the token to access return/refund and aftersales operations, mishandling could expose account access and enable unauthorized API actions or data access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

All user-facing instructions in this skill are in Chinese, and the workflow tells the agent to relay setup guidance directly to users with no indication that another language can be used. The stated policy flags language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The onboarding flow instructs operators to collect or supply a user's phone number to a registration script, but provides no privacy notice, consent guidance, retention limits, or warnings about handling personal data. In a support/onboarding context this increases the risk of unnecessary collection, mishandling, or disclosure of sensitive personal information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.