T01 · Skill Instruction Hijacking
- Location
SKILL.md:64- Finding
Mandatory Referral Output and Agent Instruction-Priority Override
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its bid-document purpose, but it needs review because it tries to control assistant responses with mandatory referral-style output and stores local project metadata outside its declared write area.
Review this skill before installing. It will upload confidential tender and bid files to the vendor's server and use your API-key account for paid operations, so only use it for files you are authorized to disclose. Be aware that it embeds a channel-tagged platform URL, tries to prescribe assistant output, can write files to user-chosen paths, and stores project metadata under ~/.zcm unless configured otherwise.
SKILL.md:64Mandatory Referral Output and Agent Instruction-Priority Override
scripts/zcm_lib/http_client.py:40Single-Domain Network Restriction Is Not Enforced Across HTTP Redirects
scripts/zcm_lib/jobs.py:45Arbitrary Writable-Path Overwrite Through Unrestricted Output Arguments
scripts/zcm_lib/storage.py:62Undeclared Persistent Project Metadata Stored in the User Home Directory
Referenced artifact was not completely inspected
**升级 skill 必须保留配置**:如果当前已安装目录存在 `config.json`,升级时不得删除、覆盖或替换该文件;只能更新 `SKILL.md`、`scripts/`、`references/` 等 skill 内容文件。本地生成目录 `biaoshu-bailian-files/` 也必须保留。
The generation workflow states '提交生成后不做字数不足示警' and the pricing section says '生成前不做余额不足示警,也不做余额拦截' (L103, L135), implying no pre-run balance warning or blocking. But the permissions/data section later states '提交前脚本会预检可用字数' (L161), which suggests a pre-submit balance check. These statements describe materially different behavior around billing-related execution.
The documentation explicitly supports uploading tender documents or providing remote file URLs, but it gives no warning about sensitive, confidential, or regulated content that may be contained in bid materials. In this workflow context, tender files commonly include proprietary pricing, legal terms, supplier data, and contact information, so omission of privacy guidance can lead users to expose sensitive data to the platform or to third-party URLs without informed consent.
The entire file presents API usage instructions exclusively in Chinese, and there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
The documentation states that uploaded files and task results are retained on the vendor's servers and may persist for about 7 days, but it does not pair that behavior with an explicit privacy warning, consent requirement, or guidance on handling sensitive bid materials. In a procurement/bidding context, files may contain confidential business, pricing, or personal data, so silent server-side retention increases the risk of unintended disclosure, regulatory noncompliance, or user surprise.
The entire skill guidance is written exclusively in Chinese and provides no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.
The markdown explicitly instructs the assistant to present risk levels directly in Chinese, rather than preserving user language preference or offering a choice. This creates a locale/language policy issue because the skill imposes a specific language on outputs without documented opt-in or a justified region-only constraint.
This code hard-codes Chinese report titles and labels such as "招标文件智能解读报告" and "项目句柄", indicating the skill outputs reports in a specific language by default. Under the policy, forcing a specific language without user opt-in or a documented justified locale scope is a natural-language policy violation.
The generated HTML sets lang='zh-CN', which forces a specific language/locale in the output. The file also contains extensive Chinese-only UI text throughout the generated report, with no option for user locale selection or explanation that the skill is intentionally region-specific.
This code emits user-facing validation messages in Chinese, which enforces a specific language on all users of the skill. The file does not indicate that the skill is China-specific or provide any opt-in or fallback language behavior, so it violates the language/locale policy criterion.
The batch-size validation path also forces Chinese-language output for users. Repeated hard-coded locale-specific messaging indicates the skill does not offer language choice or clearly justify the locale restriction.
This user-visible error string is emitted in Chinese regardless of user preference or environment. Without documented locale scope or opt-in, this is a natural-language policy violation under the language/locale rule.
The error message string is hard-coded in Chinese ("请求失败 HTTP ...") with no indication that users can select their preferred language or locale. This is a natural-language policy concern because it imposes a specific language on all users regardless of preference.
This code emits multiple natural-language status and error messages in Chinese, beginning here and continuing throughout the file. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation because users are not given any locale choice or justification for a Chinese-only experience.
Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.
contract_snapshot,
funcs,
description,
include_skillhub_auth=False,
allow_remote_files=False,
include_feedback=False,
):
This code formats progress messages using Chinese-only output such as '分钟', '小时', and later constructs full Chinese status lines. The rule applies to all file types and flags language-policy violations when a skill forces a specific language without user opt-in or documented locale justification.
The function builds complete progress lines entirely in Chinese, including defaults like '处理中', '任务已提交,正在排队', and '我会继续后台监听,完成后交付成品链接', with no apparent user choice of language. This is a natural-language policy concern because it imposes a specific language on all users without opt-in.
The module hardcodes Chinese translations for risk and priority values and uses Chinese-only user-facing messages elsewhere in the file. This creates a locale policy concern because the skill appears to enforce a specific language without user opt-in or an explicit documented justification in this file.
The MCP permission declaration says 'No credential collection inside chat' and later repeatedly emphasizes that the API key must not be pasted into the conversation. However, the same document also instructs the assistant to explain in detail how to obtain and configure the API key, including the exact JSON format and file location. This is not direct secret collection, but the wording creates a mild contradiction between 'no credential collection' and active credential setup guidance.
The file presents all user-facing instructions exclusively in Chinese and does not offer an explicit language choice or note that the skill is region/language-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly justified.
The file’s natural-language description is written entirely in Chinese and describes rendering bid results into a report, with no indication that users can choose another language or locale. Under the policy criteria, language-specific behavior without documented user opt-in can be a locale/language policy concern.
This code emits a Chinese-only error message, which is a natural-language locale constraint. Under the policy, forcing a specific language without user opt-in is a violation unless the locale restriction is explicitly documented and justified, which is not shown here.
The command-line interface presents its description and help text only in Chinese, which forces a specific language for users. The file does not provide a language selection mechanism or indicate that the tool is intentionally region-specific.
The user-facing module description is written entirely in Chinese and does not indicate any language selection or opt-in. Under the policy for natural-language constraints, this can be a locale/language policy issue when the skill presents itself in a fixed language without user choice or justification.
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.
from zcm_lib import cli as _cli
globals().update({name: getattr(_cli, name) for name in dir(_cli) if not name.startswith("__")})
if __name__ == "__main__":
Detected: suspicious.dynamic_code_execution