T05 · Unauthorized Access and Privilege Escalation
- Location
references/access-token.md:34- Finding
Authorization guide requires Temu permissions beyond the Skill's declared scope
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real Temu returns/refunds gateway integration, but it asks users to grant and store broad commerce credentials and includes generic proxy, billing, and persistence behavior that goes beyond a tightly scoped returns tool.
Review this before installing. Use a dedicated least-privilege Temu token if possible, avoid granting all or sensitive permissions unless you truly need them, do not store broad access tokens on shared machines, and expect full API responses to be saved locally. Be especially careful with return addresses, labels, refund/order identifiers, payment onboarding, and any use of the generic proxy or file-download scripts.
references/access-token.md:34Authorization guide requires Temu permissions beyond the Skill's declared scope
scripts/_temu_token_store.py:29Temu access tokens are stored in plaintext without enforced owner-only permissions and can be printed in full
scripts/_temu_common.py:184Complete returns and refunds responses are automatically persisted with unsafe fallback paths and no enforced access permissions
The POST target URL is derived from environment-controlled base URLs, so anyone who can influence LINKFOX_LOGIN_API_URL or LINKFOX_AGENT_USER_API_URL can redirect login and token-generation traffic to an attacker-controlled endpoint. Because these requests carry SMS-login credentials, access tokens, refresh tokens, and API-token operations, this becomes an SSRF/exfiltration issue rather than a harmless configurability feature. In the context of a Temu returns/refunds skill, this is more dangerous because the file is unrelated onboarding/account code handling sensitive credentials outside the advertised scope.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway request URL is built from environment-controlled configuration and then sent with the Authorization API key header via urlopen. An attacker who can set LINKFOX_AGENT_API_URL or LINKFOX_TOOL_GATEWAY can cause authenticated requests, order creation, and account queries to be sent to an arbitrary server, leaking the API key and enabling unintended outbound access. This is especially concerning here because the code also includes billing/order functions unrelated to the Temu aftersales skill, expanding the blast radius beyond the stated skill purpose.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
Auth guide generation and token-purpose/site guidance are not inherently unsafe, but they materially differ from the declared aftersales processing behavior and can facilitate broader credential workflows than users expect. The risk here is deceptive capability framing rather than the guide content itself.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
This file implements SMS login, API key issuance, plan listing, order purchase, and payment QR generation, which are operationally unrelated to a Temu global returns/refunds integration. Such scope divergence is a strong supply-chain risk signal because it introduces credential collection and monetization behavior into a skill that users would reasonably expect to only process aftersales APIs. The mismatch makes the package materially more dangerous in context, not less.
The code contains billing and payment-order capabilities, including package enumeration, order creation, payment URL/QR handling, and order-status queries. In a skill advertised for Temu aftersales processing, these capabilities are unjustified and create a path for unauthorized purchases, financial abuse, or user deception if invoked by an agent or attacker. The off-purpose financial functionality significantly increases risk because it handles money movement adjacent to credentialed API access.
The file implements a generic Temu signed file download capability, while the skill manifest describes only returns/refunds aftersales operations. This mismatch expands the skill's effective privilege and can enable retrieval of arbitrary signed resources unrelated to the declared business purpose, undermining least-privilege and user/operator expectations.
This file implements a generic Temu proxy that accepts an arbitrary API "type" and forwards caller-supplied parameters, which exceeds the declared returns/refunds-only scope of the skill. In an agent context, this creates a scope-expansion vulnerability: a user or prompt can invoke unrelated Temu operations through this skill, potentially reaching sensitive or privileged APIs under the provided access token.
The skill advertises and instructs use of capabilities that include environment-variable access, filesystem writes, and outbound network requests, but it does not declare any explicit tool scope or allowed-tools boundary. In an agent setting, missing permission scoping increases the blast radius of accidental or adversarial use because the agent may exercise more capabilities than users expect.
The trigger terms include broad, ambiguous keywords such as return, refund, and related mixed-language phrases without clear contextual boundaries. Overbroad triggers can cause the skill to activate in unrelated conversations, increasing the chance that secrets, tokens, or local files are accessed or written unexpectedly.
The skill instructs the agent to always persist full API responses locally and optionally print them in full to stdout. Those responses may contain access tokens, customer data, addresses, return labels, refund details, or other sensitive aftersales information, creating clear risks of credential leakage, data over-retention, and exposure in logs or shared workspaces.
The documentation explicitly recommends saving a Temu access token to a local file path and provides example commands that persist the credential, but it does not clearly warn that this creates a long-lived secret on disk that may be readable by other local users, backups, shell history, or malware. In a skill centered on e-commerce refunds and aftersales APIs, these tokens can authorize sensitive business actions and data access, so normalizing casual local storage increases the chance of credential leakage and account misuse.
This document exposes that the API returns personally identifiable return-contact data such as recipient name, phone numbers, email, and full address, but it provides no privacy warning, data-minimization guidance, or handling restrictions. In a support or agent workflow, that omission can lead to over-collection, unnecessary display, logging, or sharing of sensitive contact information during return processing.
The document instructs users to copy a Temu access token from the seller backend and optionally save it to a local store, but it provides no warning that the token is a sensitive credential or any guidance on secure storage, masking, rotation, or least-privilege handling. In the context of an API skill that uses the token to access return/refund and aftersales operations, mishandling could expose account access and enable unauthorized API actions or data access.
All user-facing instructions in this skill are in Chinese, and the workflow tells the agent to relay setup guidance directly to users with no indication that another language can be used. The stated policy flags language or locale constraints when they are imposed without user opt-in or clear justification.
The onboarding flow instructs operators to collect or supply a user's phone number to a registration script, but provides no privacy notice, consent guidance, retention limits, or warnings about handling personal data. In a support/onboarding context this increases the risk of unnecessary collection, mishandling, or disclosure of sensitive personal information.
No suspicious patterns detected.