Back to skill

Security audit

招标文件智能解读

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed cloud integration for tender and bid document workflows, with sensitive file handling and account billing risks that are described and scoped to its stated purpose.

Before installing, users should be comfortable uploading commercially sensitive tender and bid files to biaoshu.zhiliaobiaoxun.com, storing an API key locally, and using an account where bid generation may consume available words. Confirm uploads and generation steps deliberately, and reset or remove the API key if access is no longer needed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
76% confidence
Finding
The trigger conditions are broad enough to activate on ordinary bidding-related conversation, which can cause the agent to solicit or process sensitive tender and bid documents more readily than a user may expect. In this context, accidental activation is more serious because the skill uploads commercially sensitive files to a third-party cloud service and may initiate billable operations tied to the user's API key.

Static analysis

No suspicious patterns detected.