Back to skill

Security audit

Bid Management

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only bid-management skill whose sensitive document handling is aligned with its stated procurement workflow purpose.

Before installing, treat uploaded tender documents and generated bid files as confidential business data. Use the skill for explicit bid-preparation tasks, and confirm recipients, channel, and redactions before asking an agent to package or send files through enterprise messaging.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: bid-management
description: >
  投标全流程管理。输入招标文件,自动输出标书CheckList+投标总体计划+投标文件目录结构+单一来源说明(如需)。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger keywords in the description are broad enough to activate on ordinary discussion of bidding topics, which can cause the skill to engage outside the user's intended scope. In a business workflow skill that processes procurement documents, overbroad activation increases the chance of unintended handling of sensitive tender data or generation of outputs the user did not request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises packaging outputs as Excel and sending them through enterprise messaging without any warning, consent check, or data-handling constraints. Because tender materials commonly contain confidential commercial, pricing, and procurement information, this creates a realistic risk of unintended transmission of sensitive data to external channels or the wrong recipients.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description is overly broad and does not clearly bound the skill’s intended use, which can cause the agent to invoke it in inappropriate contexts. In an agent ecosystem, ambiguous routing can expose unrelated user data or trigger procurement-oriented workflows when they were not explicitly requested.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger section provides positive examples but does not define boundaries for when the skill should not activate, making activation behavior ambiguous. This can lead to accidental invocation during general discussion of tenders, causing unnecessary document analysis or disclosure-oriented workflow steps.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The description appears to assume a specific language/locale without indicating that language choice is user-controlled. This can cause the agent to select the skill for users whose language does not match, leading to incorrect output, misunderstanding of procurement content, or mishandling of sensitive bid materials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.