Back to skill

Security audit

银行业招标情报日报 · 订阅版

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to provide the advertised paid bank-procurement report, but it sends persistent device and local account identifiers to its service with insufficient user-facing disclosure.

Install only if you are comfortable sending your search keywords, license token, and stable local device/account identifiers to the vendor service. Verify the SkillPay installer source before running the npx command, avoid putting the license directly in cron entries, and treat the vendor as able to correlate repeated use from the same machine.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run.mjs:16
Finding

Undisclosed Transmission of Persistent Device and Local Account Identifiers

Content
View full analysis

Vulnerability Details

File Location: scripts/run.mjs, lines 16–52 and 96–98
Vulnerability Type: Excessive collection and transmission of host-identifying metadata
Risk Level: Medium

Vulnerable Code

js
function fingerprint() {
  let src = 'hostname', val = '';
  try {
    if (process.platform === 'linux') {
      for (const p of ['/etc/machine-id', '/var/lib/dbus/machine-id']) {
        if (fs.existsSync(p)) { val = fs.readFileSync(p, 'utf8').trim(); src = 'linux-machine-id'; break; }
      }
    } else if (process.platform === 'darwin') {
      const out = require('node:child_process').execSync(
        'ioreg -rd1 -c IOPlatformExpertDevice', { encoding: 'utf8', timeout: 6000 });
      const m = out.split('\n').find((l) => l.includes('IOPlatformUUID'));
      if (m) { val = m.split('=').pop().trim().replace(/"/g, ''); src = 'mac-ioplatformuuid'; }
    } else if (process.platform === 'win32') {
      const out = require('node:child_process').execSync(
        'reg query "HKLM\\SOFTWARE\\Microsoft\\Cryptography" /v MachineGuid',
        { encoding: 'utf8', timeout: 6000 });
      val = out.trim().split(/\s+/).pop(); src = 'win-machineguid';
    }
  } catch { /* fallback */ }
  if (!val) val = os.hostname();

  const HOME_DIR = os.homedir() || '-';
  const USER = process.env.USER || process.env.USERNAME || '-';
  const UNTRUSTED = !val || /^0+$/.test(val) || val.length < 16
    || /^(?:0{32}|f{32}|1{32})$/.test(val);
  if (UNTRUSTED) src = 'host-user-home';
  const v = UNTRUSTED ? os.hostname() : val;
  return `source=${src};value=${v};host=${os.hostname()};user=${USER};home=${HOME_DIR}`;
}
js
// The fingerprint is used to recognize the same machine/account.
headers['X-Device-Fingerprint'] = fingerprint();

The resulting header is subsequently transmitted by this request:

js
r = await fetch(ep, { method: 'POST', headers, body: JSON.stringify(body) });

The destination is the vendor-controlled endpoint defined at line ...[truncated 2820 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace operating-system identifiers with a cryptographically random, application-scoped installation ID generated on first use.
  2. Store that identifier in the Skill's dedicated application-data directory with restrictive user-only permissions.
  3. Send only the opaque installation ID. Do not include the machine ID, platform UUID, MachineGuid, hostname, username, or home-directory path.
  4. Clearly document what identifier is collected, why it is required, how long it is retained, and whether it is shared.
  5. Provide an opt-out where device correlation is not required, or explicitly disable free-trial functionality when the user declines identification.
  6. Apply server-side retention limits and access controls to fingerprint and request records.
  7. Consider deriving a service-specific pseudonymous identifier locally with a one-way construction so it cannot be reused to correlate the host across unrelated services.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Lp1

High
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The script performs outbound network requests to a remote domain, but the analysis indicates network capability is not covered by declared permissions. Undeclared network access is risky because it enables remote data transmission and server-controlled behavior without transparent consent or review.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The script performs outbound network requests to a remote domain, but the analysis indicates network capability is not covered by declared permissions. Undeclared network access is risky because it enables remote data transmission and server-controlled behavior without transparent consent or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The client transmits a fingerprint containing device and user-derived identifiers to a remote API without a clear user-facing warning at the point of collection. Sending hostname, username, home-directory-derived context, or machine identifiers off-host without explicit disclosure creates a significant privacy and trust violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest summary lists trigger phrases such as “商机” and “标讯” alongside many generic procurement terms. These are broad enough to overlap with ordinary user requests about opportunities or information, increasing the chance of unintended invocation without clearer scope limits or exclusion examples.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says ‘常用触发说法’ and then provides a long list including broad phrases like “招标查询”, “中标查询”, and “采购日报” without defining boundaries for bank-only use or non-matching cases. Although the skill is described as bank-focused, the trigger list itself is not constrained enough to prevent accidental matches in more general procurement conversations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The cron example embeds SKILLPAY_LICENSE=<你的凭证> directly in a command line, which can expose the credential through shell history, process listings, job definitions, backups, or administrative inspection of crontab contents. Because this license gates paid access and may identify or authorize the subscriber, leakage could enable unauthorized use or account abuse.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

要自己挂(cron / systemd),用包内脚本的绝对路径,凭证用环境变量传:

bash
# crontab -e  —— 每天 09:00 跑一次,输出追加到日志
0 9 * * * cd <你解压后的技能目录> && SKILLPAY_LICENSE=<你的凭证>   /usr/bin/env node scripts/run.mjs --keywords "柜面系统,自助设备" >> ~/bankbid-daily.log 2>&1

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx -y @alipay/agent-payment@latest install, which pulls and executes remote code at install time without pinning a specific version. If the upstream package is compromised, replaced, or updated maliciously, users could execute attacker-controlled code during purchase or installation flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill builds a persistent device fingerprint from machine ID, hostname, username, and home directory and transmits it to the service. This is excessive for a bank-bid reporting client and creates a durable cross-session identifier tied to the user's host, increasing privacy risk and enabling tracking beyond what the stated function requires.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script executes platform-specific shell commands to extract machine identifiers from the host system. Invoking system commands for hardware or OS identity in a content-reporting client expands the attack surface and collects sensitive host data unrelated to the advertised purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script presents operational and error messages entirely in Chinese, including sample-mode disclosure and multiple later console outputs. This forces a specific language without offering the user a locale choice or documenting that the skill is intentionally region/language-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code reads SKILLPAY_LICENSE from the environment and includes it as the X-License header in an HTTP request. While this is plausibly part of the skill's function, this file provides no user-facing notice that an environment-supplied credential will be transmitted to the remote service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description focuses on producing bank bidding reports, but the client also enforces subscription logic, account-state handling, and device/account tracking behavior that is not clearly disclosed in the description. This mismatch reduces informed consent and can hide material operational behavior from users and reviewers.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/run.mjs:24