Back to skill

Security audit

快标书标书智能写作

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent bid-document purpose, but it needs Review because it suppresses operational transparency and contains overbroad local file-write paths.

Review before installing. Use it only if you are comfortable sending tender and bid documents to biaoshu.zhiliaobiaoxun.com under your API-key account, storing that key in the skill directory, and carefully choosing output paths so reports or downloaded documents do not overwrite unrelated local files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:142
Finding

Mandatory response-policy override and referral-oriented output control

Content
View full analysis
-o <路径>.docx` 下载并告知绝对路径。标书查重未请求报告时只总结 JSON 核心结论,不编造本地报告路径。 - **凭证保护**:不得在回复中复述/输出 Api Key,也不得转发任何**携带 Key 的链接**(如平台 402 返回的 `?bind_key=` 充值/绑定链接——会经会话记录、截图、链接预览泄露);涉及充值/账户操作只给不含参数的官网普通链接。 ``` The same document requires channel-tagged links to be reproduced verbatim: ```markdown - **链接铁律**:凡向用户展示百炼®标书平台地址(注册、查看结果、充值、绑定等),一律**原样输出完整 URL**(如 https://biaoshu.zhiliaobiaoxun.com/?ch=c666 ),不要用「百炼®标书平台」「官网」这类超链接文字代替或省略。 ``` ### Technical Analysis The Skill declares its own response rules to have the highest priority and to override the rest of its instructions. It then imposes mandatory response templates, prohibits disclosure of operational commands in all circu ...[truncated 1766 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/report_lib/generator.py:13
Finding

Unrestricted output paths and basename traversal permit arbitrary file overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/zcm_lib/files.py:36
Finding

Non-streaming multipart encoder allows memory-exhaustion denial of service

Content
View full analysis
max_mb * 1024 * 1024: _die(f"{label}总大小超过上限:{total / 1024 / 1024:.1f} MB > {max_mb} MB。请压缩或减少文件后重试。") def encode_multipart(fields, files): """Build a multipart/form-data request body from fields and local files.""" boundary = "----zcm" + uuid.uuid4().hex crlf = b"\r\n" buf = bytearray() for name, value in (fields or {}).items(): buf += b"--" + boundary.encode() + crlf buf += f'Content-Disposition: form-data; name="{name}"'.encode() + crlf + crlf buf += str(value).encode("utf-8") + crlf for field_name, filepath in files: if not os.path.isfile(filepath): _die(f"文件不存在:{filepath}") fname = os.path.basename(filepath) ctype = mimetypes.guess_type(fname)[0] or "application/octet-stream" with open(filepath, "rb") as f: content = f.read() buf += b"--" + boundary.encode() + crlf buf += ( f'Content-Disposition: form-data; name="{field_name}"; filename="{fname}"' ).encode("utf-8") + crlf buf += f"Content-Type: {ctype}".encode() + crlf + crlf buf += content + crlf buf += b"--" + boundary.encode() + b"--" + crlf return bytes(buf), f"multipart/form-data; boundary={boundary}" ``` The permitted limits are large: ```python MAX_TENDER_MB = 50 MAX_BID_MB = 1024 MAX_DUP_TOTAL_MB = ...[truncated 2093 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (31)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
**升级 skill 必须保留配置**:如果当前已安装目录存在 `config.json`,升级时不得删除、覆盖或替换该文件;只能更新 `SKILL.md`、`scripts/`、`references/` 等 skill 内容文件。本地生成目录 `biaoshu-bailian-files/` 也必须保留。

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

L161 states that bid-document generation will pre-check available quota before submission, but L135 explicitly says generation should not warn about insufficient balance before starting and should not block for balance. Those instructions describe materially different behavior around billing/authorization flow and could mislead users or reviewers about what the skill actually does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The instruction '展示给用户时统一说“可用字数”' mandates a specific Chinese phrasing for user-facing output. This is a locale/language constraint presented without any user opt-in or documented justification for restricting language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file presents all operational instructions exclusively in Chinese, but does not state that the skill is China-region-specific or that the user can choose another language. Under the policy, forcing a specific language without opt-in or justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This is a markdown file, so SQP-2 applies to omissions or deficiencies in warnings about behaviours affecting user data, privacy, or system integrity. Line L23 says generation-related actions consume available quota and also states '生成前不做余额不足示警,也不做余额拦截', which indicates the skill description lacks a protective user warning before a charge-affecting action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown instructs the assistant to present risk levels directly in Chinese, which imposes a specific language on user-facing output. The file does not offer an opt-in or alternative locale choice, so this is a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code hard-codes Chinese report titles and labels such as "招标文件智能解读报告", "项目句柄", and other Chinese UI text, indicating the skill outputs reports in a fixed language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale restriction is explicitly justified, which is not shown here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The compliance renderer emits fixed Chinese report names and labels including "合规审查报告" and "审查对象", which constrains the skill to a single language. The file does not indicate any user choice or explicit documented justification for this locale-specific behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This renderer constructs report content using fixed Chinese strings such as "标书查重报告", "任务编号", and "投标文件". That creates a mandatory language choice in the skill behavior, which violates the policy unless the locale restriction is explicitly offered as a choice or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The rendered HTML sets lang='zh-CN', which forces a specific language/locale in generated output. The file also contains extensive fixed Chinese UI text, but there is no indication that users can choose another language or that this locale restriction is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function constructs user-facing messages exclusively in Chinese (e.g. "预计/本次需要约" and "当前可用") with no indication that the language is configurable or user-selected. This can violate language/locale policy requirements when a skill is expected to respect user language preferences or offer opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits user-visible error text in Chinese, which effectively forces a specific language for users encountering size-validation failures. The file does not provide any opt-in, fallback, or documented justification that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The total-size validation path returns an error only in Chinese, which is a natural-language locale constraint applied to all users of this helper. Without a documented regional scope or configurable localization, this conflicts with the policy against forcing a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The error message literal 请求失败 HTTP ... is hard-coded in Chinese, which imposes a specific language on all users. This is a natural-language locale policy issue because the file provides no user choice, fallback, or documented justification for the forced language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-visible status, timeout, and error messages in Chinese only, and the same pattern continues throughout the file. The policy scope applies to all file types, and there is no indication of user opt-in or locale selection, so the file hardcodes a specific language for user-facing interactions.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/zcm_lib/parser.py (reported line 13)May include surrounding context.

python
contract_snapshot,
    funcs,
    description,
    include_skillhub_auth=False,
    allow_remote_files=False,
    include_feedback=False,
):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI version string is hard-coded in Chinese, which imposes a specific language on all users when invoking --version. There is no visible opt-in, locale selection, or justification that this parser is intended only for a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code formats durations using Chinese terms such as "分", "分钟", "天", and "小时", which forces a specific language in user-visible output. The policy requires either user opt-in or a documented, justified locale constraint, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function returns multiple user-visible status strings in Chinese, including size fallbacks and progress updates like "未知大小", "任务已提交,正在排队", and "进度更新". There is no indication of user language selection or a documented locale restriction, so this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file hard-codes Chinese translations for result enums and emits Chinese-only user-facing messages, which imposes a specific language on all users. The provided rules treat forced language/locale behavior as a policy violation unless the skill offers a choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

L054 frames the skill as not using shell-wide privileges beyond its local client and as bounded to the declared network domain, but the same file later embeds externally hosted image resources from raw.githubusercontent.com at L092 and L116. That creates a documentation-level contradiction about external network use, even though it is only for rendered documentation assets rather than core skill execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file instructs the skill to accept uploaded bidding documents or remote file URLs and later provide download links for generated documents. Because these documents may contain sensitive business information, the description should include a user-facing warning or disclosure about transmitting and processing document contents through the platform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing natural-language instructions exclusively in Chinese, and it does not provide any opt-in, alternative language, or explanation that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Line L69 explicitly says that when semantic review is incomplete, the system must truthfully state that the current result is partial and must not present it as a complete review. However, the documented example response at L46-L48 shows status information in a way that could be read as a completed review while relying on partial_summary or semantic-review-related fields to clarify incompleteness, creating documentation-level tension about intended result interpretation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language comment explicitly documents that exported report artifacts currently ship with zh-CN labels. Under the locale policy rule, this is a language/locale constraint, and the file does not indicate a user choice or opt-in mechanism within this implementation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/zcm_lib/reporting.py:59