Back to skill

Security audit

标袋云投标文件生成助手

Security checks across malware telemetry and agentic risk

Overview

This skill uses a disclosed third-party bid-document API to upload user-selected procurement files, generate reports/documents, and store an App Key locally.

Install only if you are comfortable sending tender and bid documents to biaoshu.zhiliaobiaoxun.com under your App Key account. Confirm before uploads, protect or rotate the App Key if it was pasted into chat, avoid custom ZCM_BASE values unless you trust the endpoint, and remember generated results may remain on the service for about 7 days.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding
The skill description emphasizes bid-document generation and compliance review, but the documented behavior also includes credential management, account/balance queries, remote job orchestration, downloading server-generated artifacts, and persistence of account-linked data. This mismatch can mislead users about the true scope of actions performed, especially around remote transmission, account effects, and billing-linked operations.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill states that tender and bid files will be uploaded to a remote server and may contain sensitive commercial, pricing, and personal information, but the warning is not enforced as a mandatory pre-transmission consent step in every usage flow. In this context, silent or insufficiently prominent data-transfer disclosure increases the risk of users unknowingly sending confidential procurement materials off-device.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.