Back to skill

Security audit

Temu欧洲站-税务

Security checks for vulnerabilities and agentic risk

Overview

The skill performs Temu EU tax gateway work, but it also includes broad proxying, credential handling, payment onboarding, and automatic storage of sensitive results that need review before installation.

Install only if you trust LinkFox with the relevant Temu and LinkFox credentials, can keep the workspace private, and are comfortable with local plaintext token/response files. Avoid the generic proxy scripts unless you explicitly need them, verify endpoint override environment variables are unset or trusted, and treat onboarding payment commands as purchase actions requiring deliberate user approval.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_temu_token_store.py:10
Finding

Temu Access Tokens Are Stored in Plaintext Without Restrictive Filesystem Permissions

Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") def save_token( store_key: str, site: str, management_type: str, access_token: str, token_purpose: str = "default", label: str | None = None, ) -> dict: data = _load_store() store = _find_store(data, store_key) if store is None: store = {"storeKey": store_key, "label": label or store_key, "tokens": []} data["stores"].append(store) elif label: store["label"] = label key = _token_key(site, management_type, token_purpose) entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ... _save_store(data) ``` ### Technical Analysis The token store writes Temu access tokens directly into a plaintext JSON file. Neither the parent directory nor the file is explicitly created with owner-only permissions. Their effective permissions therefore depend on the current process umask and any pre-existing filesystem object. The implementation also uses a normal `open(path, "w")` operation without checking whether the destination is a regular file owned by the current user. It does not reject symbolic links, use exclusive creation, or perform an atomic temporary-file replacement. A ...[truncated 1397 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_temu_access_token.py:51
Finding

Credential Retrieval Commands Expose Complete Temu Access Tokens Through Standard Output

Content
View full analysis
= 2: try: params = json.loads(sys.argv[1]) mask = params.get("mask", True) except json.JSONDecodeError as e: print(f"Invalid parameter format: {e}", file=sys.stderr) sys.exit(1) print(json.dumps(list_stores(mask=mask), indent=2, ensure_ascii=False)) ``` From `scripts/_temu_token_store.py`: ```python def list_stores(mask: bool = True) -> dict: data = _load_store() stores = [] for store in data.get("stores", []): tokens = [] for item in store.get("tokens", []): token = item.get("accessToken", "") if mask and token: shown = token[:6] + "..." + token[-4:] if len(token) > 12 else "***" else: shown = token tokens.append( { "site": item.get("site"), "managementType": item.get("managementType"), "tokenPurpose": item.get("tokenPurpose", "default"), "accessToken": shown, "updatedAt": item.get("updatedAt"), } ) ``` ### Technical Analysis `get_temu_access_token.py` always ser ...[truncated 1372 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:15
Finding

Environment-Controlled Endpoint Overrides Can Redirect Authentication Credentials

Content
View full analysis
dict: return { "Authorization": linkfox_token, "Token": linkfox_token, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/1.0", } def call_temu_api( url: str, body: dict, timeout: int = 150, linkfox_params=None, ) -> dict: linkfox_token = get_linkfox_token(linkfox_params) data = json.dumps(body, ensure_ascii=False).encode("utf-8") req = Request( url, data=data, headers=build_gateway_headers(linkfox_token), method="POST", ) try: with urlopen(req, timeout=timeout) as response: return json.loads(response.read().decode("utf-8")) ``` From `scripts/onboarding.py`: ```python def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` ```python def _headers(source: str, origin_host: str, *, access_token: str = "", user_id: str = "", group_id: str = "") -> dict: h = { "Accept": "application/json, text/plain, */*", "Content-Type": "a ...[truncated 3262 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_temu_common.py:176
Finding

Complete Tax Responses Can Fall Back to Insecure Temporary Storage

Content
View full analysis
str: cached = _LF_SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) candidates.append(os.path.join(_lf_tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _LF_SESSION_CACHE["_root"] = root return root fallback = os.path.abspath(candidates[-1]) _LF_SESSION_CACHE["_root"] = fallback return fallback ``` ```python def emit_result(result, slug=SLUG, inline=False): serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = _lf_time.time() date_str = _lf_time.strftime("%Y-%m-%d", _lf_time.localtime(ts)) sid = _lf_session_id(ts) root = _lf_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _lf_ensure_meta(root, session_dir, date_str, sid, ts) data_dir = os.path.join(session_dir, "data") os.makedirs(data_dir, exist_ok=True) out = os.path.join(data_dir, f"{slug}-{int(ts * 1_000_000)}.json") try: with open(out, "w", encoding="utf-8") as f: f.write(serialized) print(f" ...[truncated 1937 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (81)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The code allows network destinations to be controlled by environment variables via _login_base() and _agent_user_base(), then sends SMS login data, access tokens, refresh tokens, and API-token generation requests to those URLs. In a skill/onboarding context this creates a realistic SSRF and credential-exfiltration path if an attacker can influence the runtime environment, which is especially dangerous because the transmitted data is highly sensitive.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway request path builds outbound requests from environment-controlled base URLs and includes the API key in the Authorization header. If the environment is tampered with, requests can be redirected to attacker-controlled infrastructure, leaking credentials and enabling arbitrary outbound connections from the runtime.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation primarily generates token-authorization guidance rather than performing the advertised tax API actions, the skill is misleading and may route users into credential-handling flows they did not intend. While less severe than direct secret exfiltration, this still increases phishing-like confusion and permission creep within an automation environment.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file implements LinkFox account onboarding, SMS login, API-key issuance, package listing, ordering, and payment handling, which is materially unrelated to a skill declared as a Temu EU tax API forwarder. Such scope mismatch is dangerous because it can be used to collect credentials, mint platform tokens, and drive purchases under the guise of an unrelated business function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code can create purchase orders and render payment QR codes, introducing a monetization/payment capability that is not justified by the stated tax API purpose. In the context of a tax-integration skill, this is especially suspicious because it could induce unauthorized purchases or socially engineer users into paying for unrelated services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill performs SMS-based account login, retrieves access and refresh tokens, queries team/user information, and generates API tokens for LinkFox users despite claiming to be a Temu EU tax forwarder. This creates a direct credential and account-takeover surface that is far more dangerous given the mismatch between declared purpose and implemented behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script introduces a generic access-token persistence capability that is broader than the stated EU Tax proxy scope. In an agent skill, this kind of scope mismatch is dangerous because it enables storage and later reuse of credentials for unrelated Temu domains, increasing the chance of unauthorized API access, credential misuse, or hidden cross-skill pivoting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script exposes a generic signed file download path (/temu/fileDownload) that is broader than the declared scope of an EU tax-only skill. Because it accepts an arbitrary signed URL and access token and forwards them to the backend, it can be used to fetch resources outside the intended Temu EU tax APIs, creating a scope-expansion and potential data exfiltration path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script is implemented as a generic Temu proxy even though the skill metadata says it should only expose EU tax APIs. This scope mismatch is dangerous because an agent or user can invoke unintended Temu capabilities through the same skill, bypassing the policy boundary implied by the manifest and increasing the chance of unauthorized actions or data access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code accepts an arbitrary user-supplied type value and forwards it upstream without restricting it to the tax API family. In this skill context, that means the advertised EU tax tool can be repurposed as a general Temu API tunnel, potentially enabling access to unrelated business operations, sensitive data, or state-changing actions outside the user's expected consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises and documents capabilities that require environment access, file writes, and outbound network calls, but it does not declare a tool scope such as permissions or allowed-tools. That creates an authorization gap where the runtime may grant broader powers than reviewers or operators expect, increasing the chance of over-privileged execution and misuse of local files, secrets, or network access.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Always persisting complete API responses and sometimes printing them in full to stdout can expose access tokens, invoice contents, merchant data, and tax records in local files, terminal history, logs, and downstream tooling. Because the files are session-linked and written under the working directory, the data may be retained broadly and accessed by unrelated processes or collaborators.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly documents automatic saving of full API responses to local files without a prominent warning or consent flow, even though those responses may contain tax, invoice, merchant, and token-related data. Silent persistence of sensitive business and financial data increases the risk of local disclosure through repository sync, backups, shared workspaces, or other tools reading the same directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document recommends storing long-lived Temu access tokens on disk in a predictable local file path and shows commands for saving and later reusing them, but it does not explicitly warn that these are sensitive credentials or describe minimum storage protections. If the host is multi-user, compromised, backed up insecurely, or the file permissions are too broad, an attacker could recover the token and invoke Temu business APIs as the merchant.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.