Back to skill

Security audit

个人数字资产盘点管家

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language digital-asset inventory assistant with an optional, user-authorized zengzhi.life workflow; the main risks are privacy and account/API-key handling, not hidden malicious behavior.

Install only if you are comfortable sharing asset descriptions, evidence screenshots/files, and account-linked data with zengzhi.life when using platform mode. Do not provide an API key or registration credentials unless you intend the agent to create drafts/reports there, and personally review anything before publishing, listing, signing, or confirming transactions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/zengzhi-api.md (reported line 65)May include surrounding context.

md
## "只认本人"端点清单(Agent 调用一律 403,不要代点)

`POST /report/pages/{id}/publish`(公开展示/上架)· `POST /api/v1/listings`(挂牌)· `POST /api/v1/listings/{id}/off`(下线)· `POST /api/v1/listings/{id}/intent`(提交购买意向——含"用途合规"承诺,须主人本人勾)· `POST|DELETE /api/v1/deeds/sell`(卖方委托书)· `POST|DELETE /api/v1/deeds/buy`(买方寻购委托书)· `POST /deals/{id}/confirm`(确认对方成交)· `POST /report/orders/{id}/ownership/confirm`(保存权属三句)· `DELETE /report/orders/{id}`(删单)· `DELETE /report/pages/{id}/comments/{comment_id}`(隐藏评论)

完整清单以 `GET /agent/meta → human_only_endpoints` 为准。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/zengzhi-api.md (reported line 65)May include surrounding context.

md
## "只认本人"端点清单(Agent 调用一律 403,不要代点)

`POST /report/pages/{id}/publish`(公开展示/上架)· `POST /api/v1/listings`(挂牌)· `POST /api/v1/listings/{id}/off`(下线)· `POST /api/v1/listings/{id}/intent`(提交购买意向——含"用途合规"承诺,须主人本人勾)· `POST|DELETE /api/v1/deeds/sell`(卖方委托书)· `POST|DELETE /api/v1/deeds/buy`(买方寻购委托书)· `POST /deals/{id}/confirm`(确认对方成交)· `POST /report/orders/{id}/ownership/confirm`(保存权属三句)· `DELETE /report/orders/{id}`(删单)· `DELETE /report/pages/{id}/comments/{comment_id}`(隐藏评论)

完整清单以 `GET /agent/meta → human_only_endpoints` 为准。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/zengzhi-api.md (reported line 65)May include surrounding context.

md
## "只认本人"端点清单(Agent 调用一律 403,不要代点)

`POST /report/pages/{id}/publish`(公开展示/上架)· `POST /api/v1/listings`(挂牌)· `POST /api/v1/listings/{id}/off`(下线)· `POST /api/v1/listings/{id}/intent`(提交购买意向——含"用途合规"承诺,须主人本人勾)· `POST|DELETE /api/v1/deeds/sell`(卖方委托书)· `POST|DELETE /api/v1/deeds/buy`(买方寻购委托书)· `POST /deals/{id}/confirm`(确认对方成交)· `POST /report/orders/{id}/ownership/confirm`(保存权属三句)· `DELETE /report/orders/{id}`(删单)· `DELETE /report/pages/{id}/comments/{comment_id}`(隐藏评论)

完整清单以 `GET /agent/meta → human_only_endpoints` 为准。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/zengzhi-api.md (reported line 65)May include surrounding context.

md
## "只认本人"端点清单(Agent 调用一律 403,不要代点)

`POST /report/pages/{id}/publish`(公开展示/上架)· `POST /api/v1/listings`(挂牌)· `POST /api/v1/listings/{id}/off`(下线)· `POST /api/v1/listings/{id}/intent`(提交购买意向——含"用途合规"承诺,须主人本人勾)· `POST|DELETE /api/v1/deeds/sell`(卖方委托书)· `POST|DELETE /api/v1/deeds/buy`(买方寻购委托书)· `POST /deals/{id}/confirm`(确认对方成交)· `POST /report/orders/{id}/ownership/confirm`(保存权属三句)· `DELETE /report/orders/{id}`(删单)· `DELETE /report/pages/{id}/comments/{comment_id}`(隐藏评论)

完整清单以 `GET /agent/meta → human_only_endpoints` 为准。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/zengzhi-api.md (reported line 65)May include surrounding context.

md
## "只认本人"端点清单(Agent 调用一律 403,不要代点)

`POST /report/pages/{id}/publish`(公开展示/上架)· `POST /api/v1/listings`(挂牌)· `POST /api/v1/listings/{id}/off`(下线)· `POST /api/v1/listings/{id}/intent`(提交购买意向——含"用途合规"承诺,须主人本人勾)· `POST|DELETE /api/v1/deeds/sell`(卖方委托书)· `POST|DELETE /api/v1/deeds/buy`(买方寻购委托书)· `POST /deals/{id}/confirm`(确认对方成交)· `POST /report/orders/{id}/ownership/confirm`(保存权属三句)· `DELETE /report/orders/{id}`(删单)· `DELETE /report/pages/{id}/comments/{comment_id}`(隐藏评论)

完整清单以 `GET /agent/meta → human_only_endpoints` 为准。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/zengzhi-api.md (reported line 65)May include surrounding context.

md
## "只认本人"端点清单(Agent 调用一律 403,不要代点)

`POST /report/pages/{id}/publish`(公开展示/上架)· `POST /api/v1/listings`(挂牌)· `POST /api/v1/listings/{id}/off`(下线)· `POST /api/v1/listings/{id}/intent`(提交购买意向——含"用途合规"承诺,须主人本人勾)· `POST|DELETE /api/v1/deeds/sell`(卖方委托书)· `POST|DELETE /api/v1/deeds/buy`(买方寻购委托书)· `POST /deals/{id}/confirm`(确认对方成交)· `POST /report/orders/{id}/ownership/confirm`(保存权属三句)· `DELETE /report/orders/{id}`(删单)· `DELETE /report/pages/{id}/comments/{comment_id}`(隐藏评论)

完整清单以 `GET /agent/meta → human_only_endpoints` 为准。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/zengzhi-api.md (reported line 65)May include surrounding context.

md
## "只认本人"端点清单(Agent 调用一律 403,不要代点)

`POST /report/pages/{id}/publish`(公开展示/上架)· `POST /api/v1/listings`(挂牌)· `POST /api/v1/listings/{id}/off`(下线)· `POST /api/v1/listings/{id}/intent`(提交购买意向——含"用途合规"承诺,须主人本人勾)· `POST|DELETE /api/v1/deeds/sell`(卖方委托书)· `POST|DELETE /api/v1/deeds/buy`(买方寻购委托书)· `POST /deals/{id}/confirm`(确认对方成交)· `POST /report/orders/{id}/ownership/confirm`(保存权属三句)· `DELETE /report/orders/{id}`(删单)· `DELETE /report/pages/{id}/comments/{comment_id}`(隐藏评论)

完整清单以 `GET /agent/meta → human_only_endpoints` 为准。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/zengzhi-api.md (reported line 65)May include surrounding context.

md
## "只认本人"端点清单(Agent 调用一律 403,不要代点)

`POST /report/pages/{id}/publish`(公开展示/上架)· `POST /api/v1/listings`(挂牌)· `POST /api/v1/listings/{id}/off`(下线)· `POST /api/v1/listings/{id}/intent`(提交购买意向——含"用途合规"承诺,须主人本人勾)· `POST|DELETE /api/v1/deeds/sell`(卖方委托书)· `POST|DELETE /api/v1/deeds/buy`(买方寻购委托书)· `POST /deals/{id}/confirm`(确认对方成交)· `POST /report/orders/{id}/ownership/confirm`(保存权属三句)· `DELETE /report/orders/{id}`(删单)· `DELETE /report/pages/{id}/comments/{comment_id}`(隐藏评论)

完整清单以 `GET /agent/meta → human_only_endpoints` 为准。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad phrases such as asking what can become an asset, which can match ordinary discussion and invoke the skill unexpectedly. Overbroad invocation is dangerous here because the skill can progress into collecting sensitive personal history, works, evidence, and potentially using an external platform workflow if the conversation drifts into that mode.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes a platform-operation mode that uploads materials and interacts with an external service, but it does not clearly warn users up front that personal materials, account-linked data, and evidence files may be transmitted off-platform. In this context, the omission is more serious because the workflow encourages submission of screenshots, records, and other potentially sensitive supporting evidence.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly authorizes the agent to register accounts on behalf of users, which expands from asset inventory into identity- and account-creation flows on an external service. Even if the user later retrieves the activation code and API key from email, this creates risk of unauthorized account actions, mishandling of credentials, and collection/transmission of personal data beyond the minimum needed for the stated task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s headings, instructions, questions, and templates are entirely in Chinese, which implicitly constrains use to a specific language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale limitation is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.