Back to skill

Security audit

Temu美国站-退货退款

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed LinkFox Temu returns/refunds connector, but it handles merchant credentials and sensitive commerce data with overly broad proxy powers and weak local storage boundaries.

Install only if you trust LinkFox with Temu merchant credentials and are comfortable with local plaintext token storage, default saving of complete API responses, and the presence of generic proxy/payment helpers. Before use, clear untrusted endpoint override environment variables, avoid passing tokens on command lines when possible, restrict permissions on ~/.linkfox and saved response directories, and use the specific returns/refunds scripts rather than the arbitrary proxy helpers.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:15
Finding

Credential Disclosure Through Unrestricted API Endpoint Overrides

Content
View full analysis
dict: """Call the Temu gateway; a LinkFox user token is required.""" linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) try: with urlopen(req, timeout=timeout) as response: return json.loads(response.read().decode("utf-8")) ``` ```python def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` ```python def _http_post(url: str, body: dict, headers: dict, timeout: int = 30) -> dict: try: _require_requests() except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() ``` ```python def _headers(source: str, origin_host: str, *, access_token: str = "", user_id: str = "", group_id: str = "") -> dict: h = { "Accept": "application/json, text/plain, */*", "Content-Type": "application/json;charset=UTF-8", "Origi ...[truncated 2402 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:10
Finding

Temu Access Tokens Stored and Disclosed in Plaintext

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ```python print( json.dumps( { "found": True, "storeKey": store_key, "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": token, }, indent=2, ensure_ascii=False, ) ) ``` The listing command also advertises an option that disables masking: ```python """ List locally saved Temu accessTokens (masked). Usage: python list_temu_access_tokens.py python list_temu_access_tokens.py '{"mask": false}' """ ``` ### Technical Analysis The token store writes reusable Temu access tokens directly into a JSON file. File creation uses the process's default umask and does not explicitly enforce owner-only permissions, verify file ownership, protect against unsafe path targets, or encrypt stored values. The dedicated getter prints the complete token to standard output. The list command additionally supports disabling masking. Standard output may be retained ...[truncated 1635 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_common.py:177
Finding

Unsafe Persistence and Path Construction for Sensitive API Responses

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root ``` ```python def _lf_session_id(ts: float) -> str: env = os.environ.get("SESSION_ID") if env: return env.strip() if "_auto" not in _LF_SESSION_CACHE: _LF_SESSION_CACHE["_auto"] = ( _lf_time.strftime("%H%M%S", _lf_time.localtime(ts)) + "-" + _lf_secrets.token_hex(3) ) return _LF_SESSION_CACHE["_auto"] ``` ```python def emit_result(result, slug=SLUG, inline=False): """Persist the full response under linkfox///data/-.json.""" serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.m ...[truncated 3010 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:162
Finding

Unpinned Runtime Dependency Installation Guidance

Content
View full analysis
dict: try: import qrcode except ImportError: err = "Missing qrcode dependency; run: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError("Missing requests dependency; run: pip install requests") ``` ### Technical Analysis The onboarding script directs users to install `qrcode`, `pillow`, and `requests` without version constraints, hashes, a lockfile, or an approved package-index configuration. This does not prove that the named packages are malicious. The risk is that the code executed by future installations can change after the Skill has been reviewed. Installation behavior also depends on the user's configured Python package index, where dependency confusion, mirror compromise, or malicious package replacement may occur. ### Attack Path 1. A user runs an onboarding command on a system where one of the optional packages is absent. 2. The script emits an unpinned `pip install` instruction. 3. The user executes the suggested command. 4. `pip` resolves packages and transitive dependencies from the active package index without integrity pins. 5. A compromised release, index, mirror, or dependency is installed. 6. Package installation hooks or later imports execute the malicious component with the user's privileges. ### Impact Assessment A compromised dependency can execute arbitrary Python code with the privileges of the user running the installation or onboarding script. This can expose local Temu token files, LinkFox environment credentials, saved API responses, and other files ...[truncated 151 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (65)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The code builds request destinations from environment-controlled base URLs and then sends authentication material, SMS login data, refresh tokens, and API-token management requests to those endpoints via requests.post. If an attacker can influence environment variables in the skill runtime, they can redirect these calls to attacker-controlled servers and exfiltrate credentials or induce SSRF-like outbound access.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway helper constructs outbound urllib requests from environment-derived base URLs and includes the agent API key in the Authorization header. An attacker who controls LINKFOX_AGENT_API_URL or related variables can redirect billing, account, and order traffic to a malicious endpoint, leaking credentials and sensitive account metadata while also enabling unintended outbound network access.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A skill described as a US returns/refunds proxy but capable of forwarding arbitrary Temu API types across sites is over-privileged relative to its stated purpose. That allows invocation of unrelated domains and actions through a trusted-looking wrapper, potentially enabling unauthorized data access or unintended operations beyond returns/refunds.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script emits the raw access token to stdout in JSON, which can be captured by logs, wrappers, process monitors, terminal history, or downstream tools. In an agent or gateway environment, this materially increases the chance of credential disclosure and subsequent unauthorized API access using the bearer token.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file implements a LinkFox onboarding and commerce CLI rather than Temu US returns/refunds functionality described by the skill metadata. Such scope mismatch is dangerous because users or higher-level agents may invoke the skill expecting aftersales operations but instead trigger account bootstrap, credential issuance, and payment-related behavior that is unrelated and potentially sensitive.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code can create orders for LinkFox plans and render payment QR codes, which is unrelated to a Temu returns/refunds integration. In this context, that capability increases the risk of unauthorized purchases, misleading users into paying for unrelated services, or giving a compromised skill a monetization path wholly outside the advertised business function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script exposes a generic signed-file download capability via /temu/fileDownload, but the skill is described as a US returns/refunds integration. That mismatch materially expands the skill's effective permissions and data-access surface, creating a risk of unauthorized retrieval of signed resources, sensitive documents, or cross-workflow data unrelated to returns/refunds. In this context, a broad download primitive is especially dangerous because signed URLs often grant direct access to protected files without further authorization checks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script accepts an arbitrary Temu API type and forwards it through a generic proxy, even though the skill is declared as limited to US returns/refunds workflows. This creates a scope-bypass capability: anyone invoking the skill can potentially reach unrelated Temu APIs with supplied credentials, expanding the attack surface and violating least privilege.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises capabilities that rely on environment variables, network access, and local file writes, but it does not declare a restrictive tool scope such as permissions or allowed-tools. In an agent setting, missing scope boundaries increases the chance the skill can access broader resources than intended, especially because it handles credentials and writes response data locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written to trigger on Chinese and English terms for a US-market skill, but the file otherwise presents the skill entirely in Chinese and does not state that the user can choose output language. This creates a natural-language policy concern because the skill appears to impose a specific language/locale presentation without explicit opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs saving complete API responses by default into session-linked local files, and those responses may contain access tokens, personal return/refund data, addresses, labels, or case details. Persistent local storage significantly increases exposure through accidental commits, shared workspaces, local compromise, or later reuse by unrelated tasks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L035 明确写明“本工具会消耗积分”,并要求失败或空结果时不要自动连续试探;但 L121-L123 又声明“ 不消耗积分”。这不是单纯信息不完整,而是同一文档内对调用成本与使用约束给出了直接矛盾的意图说明。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explicitly recommends storing a live Temu access token in a local JSON file and shows commands that persist the secret, but it does not warn users to restrict file permissions, avoid committing the file, or use an OS secret store. Because this skill handles ecommerce returns/refunds APIs, the token likely grants sensitive operational access; compromise of the local token store could allow unauthorized API calls, refund abuse, or exposure of aftersales data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explicitly demonstrates passing a live accessToken as a command-line argument in a JSON string. On many systems, command-line arguments can be exposed via shell history, process listings, audit logs, or CI job logs, which can leak credentials that authorize returns/refunds API actions for a Temu US store.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.