Back to skill

Security audit

智能投标文件编写工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is largely coherent for cloud bid-document processing, but it over-controls assistant output and has under-scoped local persistence and file-write behavior that users should review first.

Install only if you are comfortable uploading confidential tender and bid documents to the vendor service under your API key, with account billing and temporary server retention. Keep the API key in the skill-local config file rather than passing it on the command line, review or clear ~/.zcm/projects.json if you do not want project metadata retained, and avoid user-supplied output paths that could overwrite important files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:142
Finding

Agent Instruction and Output Hijacking Through Mandatory Priority Rules and Promotional Content

Content
View full analysis
本报告由「百炼®标书」skill 自动生成" f"百炼®标书 · {esc(self.title)}") js = ("") return (f"" f"
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/zcm_lib/storage.py:62
Finding

Persistent Metadata Written Outside the Declared Filesystem Boundary

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/zcm_lib/jobs.py:45
Finding

Unrestricted Output Paths Permit Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/zcm_lib/parser.py:30
Finding

API Key Can Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (29)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
**升级 skill 必须保留配置**:如果当前已安装目录存在 `config.json`,升级时不得删除、覆盖或替换该文件;只能更新 `SKILL.md`、`scripts/`、`references/` 等 skill 内容文件。本地生成目录 `biaoshu-bailian-files/` 也必须保留。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document title and all operational instructions are written exclusively in Chinese, which effectively imposes a language constraint on skill operators or users. The file does not indicate that Chinese is optional, user-selected, or required for a documented region-specific compliance reason.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The API documentation instructs users to upload tender/bid documents by file or remote URL but does not warn that these materials may contain confidential commercial, pricing, legal, or personally identifiable information. It also does not state how remote URLs are fetched or restricted, which can lead to unsafe handling expectations and increase the risk of sensitive data exposure or misuse through unintended third-party access paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The entire skill description, parameters, and operational guidance are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language or China-specific deployment context. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document explicitly states that uploaded files and task results are retained on the vendor's servers and expire only after about 7 days, but it does not pair that statement with a clear user-facing warning, consent requirement, or data-handling guidance. In a bid/tender workflow, uploaded documents may contain sensitive commercial, pricing, identity, or compliance data, so silent retention increases privacy, confidentiality, and regulatory risk if users are unaware of persistence.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction says the script output and reports have '已自动转中文' and should be presented directly in Chinese. This imposes a language choice on users without offering a language/locale option or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generated HTML hard-codes lang='zh-CN', which forces a specific language/locale for all rendered reports. Under the policy, locale constraints should either be optional for users or clearly justified as region-specific; this file contains no such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file emits natural-language messages in Chinese for size-limit failures, which forces a specific language on users. Under the policy, locale-specific language is a violation unless the skill offers user choice or clearly documents and justifies the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This batch-size error is also presented only in Chinese, creating the same forced-language behavior. No language selection, fallback, or justification is visible in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code terminates with a Chinese-only error when a file path is missing. This is a natural-language policy issue because it imposes a locale without opt-in or documented restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing error text is emitted only in Chinese (for example, '请求失败 HTTP'), which forces a specific language without any visible opt-in or locale selection mechanism. This is a natural-language policy concern because the file imposes a language choice on all users rather than adapting to user preference or documented locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits user-visible status and error text exclusively in Chinese, including terminal failure and timeout messages. Because the file provides no opt-in, fallback, or documented region-specific justification, it violates the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The functions printing download guidance, save instructions, and result-handling messages all use Chinese-only text. This imposes a fixed language on users across normal operation paths without presenting a choice or indicating that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The progress monitor prints startup, retry, queueing, completion, failure, and timeout messages solely in Chinese. Since these are primary user-facing communications and no language selection or justification is present, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/zcm_lib/parser.py (reported line 13)May include surrounding context.

python
contract_snapshot,
    funcs,
    description,
    include_skillhub_auth=False,
    allow_remote_files=False,
    include_feedback=False,
):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The version string and command help text in this parser are written in Chinese, indicating the CLI is effectively localized to a single language. The file does not expose any user opt-in, locale selection, or documentation that this skill is intentionally region-specific, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This helper formats user-facing duration text exclusively in Chinese (for example, 分、秒、小时、天) with no indication that the language is configurable or chosen by the user. The file continues this pattern in other returned status strings, which creates a natural-language locale policy concern for users expecting language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function constructs all progress/status output in Chinese, including stage descriptions, queue/completion states, and delivery messaging, without any visible mechanism for language choice. Under the stated policy, forcing a specific language without user opt-in is a reportable natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits user-facing log messages only in Chinese, including the platform reminder and balance/report status messages. The file provides no visible mechanism for user language selection or documented locale scoping, which violates the language/locale policy criterion for natural-language policy issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This function writes credential data to a local config.json file, which is a safety-relevant file write involving sensitive information. While the docstring describes the behavior for developers, there is no confirmation prompt, logging, or other user-facing disclosure in the code indicating that credentials will be stored on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation tells the skill to retrieve and present a short-lived download URL for generated bid documents but does not warn that the link itself is sensitive and should be treated like a credential. In this workflow, generated bid packages are likely confidential, so accidental sharing, logging, or display in insecure contexts could expose proprietary tender content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

L69 明确要求必须使用固定的中文措辞“当前为部分结果/语义审查未完整完成”,属于语言输出约束。文档未说明这是区域合规要求,也未给用户或调用方提供语言/本地化选择,因此构成自然语言层面的语言政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document title and all operational instructions are written in Chinese, which imposes a specific language on the skill behavior. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The exception message is written only in Chinese, and the CLI description/help strings in this file are also Chinese-only, which indicates a fixed language choice in user-facing text. The policy requires avoiding forced language or locale without user opt-in unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code creates the output directory and writes HTML/DOCX report files, but it does not display any confirmation prompt or explicit user-facing warning that files will be created or potentially overwritten at the target path. For a code file, file-write operations should have some disclosure unless the behavior is clearly warned elsewhere in code or documentation visible here.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/zcm_lib/reporting.py:59