linkfox-temu-ads-us

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill manages sensitive Temu access tokens by storing them in a local JSON file (~/.linkfox/temu-access-tokens.json). This allows the agent to reuse credentials across sessions. Access to this file is limited to the skill's internal token management scripts.
  • [DATA_EXFILTRATION]: The skill performs network operations to tool-gateway.linkfox.com, api.linkfox.com, and agent-api.linkfox.com. These are official domains associated with the skill's vendor (linkfox-ai), used for proxying requests to Temu and managing user authentication.
  • [EXTERNAL_DOWNLOADS]: The onboarding.py script provides guidance for installing standard Python dependencies (requests, qrcode, pillow) required for the SMS login and QR code payment features. No automated execution of unverified remote scripts was found.
  • [COMMAND_EXECUTION]: The skill includes several Python scripts that are invoked via standard CLI patterns. These scripts are used for API interaction and local data management, with no evidence of dangerous shell command injection or arbitrary code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:03 AM
Security Audit — agent-trust-hub — linkfox-temu-ads-us