Back to skill

Security audit

智能投标文件写作

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its bid-document purpose, but it needs review because it tries to control assistant responses with mandatory referral-style output and stores local project metadata outside its declared write area.

Review this skill before installing. It will upload confidential tender and bid files to the vendor's server and use your API-key account for paid operations, so only use it for files you are authorized to disclose. Be aware that it embeds a channel-tagged platform URL, tries to prescribe assistant output, can write files to user-chosen paths, and stores project metadata under ~/.zcm unless configured otherwise.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:64
Finding

Mandatory Referral Output and Agent Instruction-Priority Override

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/zcm_lib/http_client.py:40
Finding

Single-Domain Network Restriction Is Not Enforced Across HTTP Redirects

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/zcm_lib/jobs.py:45
Finding

Arbitrary Writable-Path Overwrite Through Unrestricted Output Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/zcm_lib/storage.py:62
Finding

Undeclared Persistent Project Metadata Stored in the User Home Directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (28)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
**升级 skill 必须保留配置**:如果当前已安装目录存在 `config.json`,升级时不得删除、覆盖或替换该文件;只能更新 `SKILL.md`、`scripts/`、`references/` 等 skill 内容文件。本地生成目录 `biaoshu-bailian-files/` 也必须保留。

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generation workflow states '提交生成后不做字数不足示警' and the pricing section says '生成前不做余额不足示警,也不做余额拦截' (L103, L135), implying no pre-run balance warning or blocking. But the permissions/data section later states '提交前脚本会预检可用字数' (L161), which suggests a pre-submit balance check. These statements describe materially different behavior around billing-related execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly supports uploading tender documents or providing remote file URLs, but it gives no warning about sensitive, confidential, or regulated content that may be contained in bid materials. In this workflow context, tender files commonly include proprietary pricing, legal terms, supplier data, and contact information, so omission of privacy guidance can lead users to expose sensitive data to the platform or to third-party URLs without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire file presents API usage instructions exclusively in Chinese, and there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that uploaded files and task results are retained on the vendor's servers and may persist for about 7 days, but it does not pair that behavior with an explicit privacy warning, consent requirement, or guidance on handling sensitive bid materials. In a procurement/bidding context, files may contain confidential business, pricing, or personal data, so silent server-side retention increases the risk of unintended disclosure, regulatory noncompliance, or user surprise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill guidance is written exclusively in Chinese and provides no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown explicitly instructs the assistant to present risk levels directly in Chinese, rather than preserving user language preference or offering a choice. This creates a locale/language policy issue because the skill imposes a specific language on outputs without documented opt-in or a justified region-only constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code hard-codes Chinese report titles and labels such as "招标文件智能解读报告" and "项目句柄", indicating the skill outputs reports in a specific language by default. Under the policy, forcing a specific language without user opt-in or a documented justified locale scope is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated HTML sets lang='zh-CN', which forces a specific language/locale in the output. The file also contains extensive Chinese-only UI text throughout the generated report, with no option for user locale selection or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code emits user-facing validation messages in Chinese, which enforces a specific language on all users of the skill. The file does not indicate that the skill is China-specific or provide any opt-in or fallback language behavior, so it violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The batch-size validation path also forces Chinese-language output for users. Repeated hard-coded locale-specific messaging indicates the skill does not offer language choice or clearly justify the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This user-visible error string is emitted in Chinese regardless of user preference or environment. Without documented locale scope or opt-in, this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The error message string is hard-coded in Chinese ("请求失败 HTTP ...") with no indication that users can select their preferred language or locale. This is a natural-language policy concern because it imposes a specific language on all users regardless of preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits multiple natural-language status and error messages in Chinese, beginning here and continuing throughout the file. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation because users are not given any locale choice or justification for a Chinese-only experience.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/zcm_lib/parser.py (reported line 13)May include surrounding context.

python
contract_snapshot,
    funcs,
    description,
    include_skillhub_auth=False,
    allow_remote_files=False,
    include_feedback=False,
):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code formats progress messages using Chinese-only output such as '分钟', '小时', and later constructs full Chinese status lines. The rule applies to all file types and flags language-policy violations when a skill forces a specific language without user opt-in or documented locale justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function builds complete progress lines entirely in Chinese, including defaults like '处理中', '任务已提交,正在排队', and '我会继续后台监听,完成后交付成品链接', with no apparent user choice of language. This is a natural-language policy concern because it imposes a specific language on all users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module hardcodes Chinese translations for risk and priority values and uses Chinese-only user-facing messages elsewhere in the file. This creates a locale policy concern because the skill appears to enforce a specific language without user opt-in or an explicit documented justification in this file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The MCP permission declaration says 'No credential collection inside chat' and later repeatedly emphasizes that the API key must not be pasted into the conversation. However, the same document also instructs the assistant to explain in detail how to obtain and configure the API key, including the exact JSON format and file location. This is not direct secret collection, but the wording creates a mild contradiction between 'no credential collection' and active credential setup guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file presents all user-facing instructions exclusively in Chinese and does not offer an explicit language choice or note that the skill is region/language-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file’s natural-language description is written entirely in Chinese and describes rendering bid results into a report, with no indication that users can choose another language or locale. Under the policy criteria, language-specific behavior without documented user opt-in can be a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code emits a Chinese-only error message, which is a natural-language locale constraint. Under the policy, forcing a specific language without user opt-in is a violation unless the locale restriction is explicitly documented and justified, which is not shown here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command-line interface presents its description and help text only in Chinese, which forces a specific language for users. The file does not provide a language selection mechanism or indicate that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The user-facing module description is written entirely in Chinese and does not indicate any language selection or opt-in. Under the policy for natural-language constraints, this can be a locale/language policy issue when the skill presents itself in a fixed language without user choice or justification.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/zcm.py (reported line 10)May include surrounding context.

python
from zcm_lib import cli as _cli

globals().update({name: getattr(_cli, name) for name in dir(_cli) if not name.startswith("__")})


if __name__ == "__main__":

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/zcm_lib/reporting.py:59