linkfox-temu-manage-product-eu

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill interacts with subdomains of linkfox.com (e.g., tool-gateway, api, agent-api) to proxy requests to Temu's OpenAPI and perform user authentication. These are official vendor resources and are used for their intended purpose.
  • [DATA_EXFILTRATION]: Merchant shop data and access tokens are transmitted to the LinkFox gateway. This is documented as the skill's primary function and occurs over secure vendor-controlled channels.
  • [CREDENTIALS_UNSAFE]: The skill manages merchant access tokens locally within the ~/.linkfox/ directory. The scripts include mechanisms to store, list (masked by default), and retrieve these tokens for API calls, following standard practices for local CLI tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured data from external API responses. While this constitutes an ingestion surface, the data is handled as JSON and primarily serves to inform the agent's product management tasks rather than influencing its core behavioral constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:03 AM
Security Audit — agent-trust-hub — linkfox-temu-manage-product-eu