Back to skill

Security audit

投标报价策略沙盘 Bid Pricing Strategy Sandbox

Security checks for vulnerabilities and agentic risk

Overview

This is a static, local bid-pricing calculator skill with disclosed manual steps and no hidden install or runtime privileges found.

Installers should treat the calculator as an aid, not a decision authority: verify the extracted scoring formula against the original bid/procurement document, confirm assumptions before using the generated config, and ask for output in a language they can fully review.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill is entirely written in Chinese and mandates Chinese-language outputs without offering a language-selection step or confirming the user's preferred language. This can cause users or downstream agents to misunderstand scoring logic, confirmation steps, or disclaimers, which is particularly risky here because the skill guides bid-pricing decisions based on parsed procurement rules.

Static analysis

No suspicious patterns detected.