Back to skill

Security audit

废标风险检查-控标信号与限制条款识别

Security checks for vulnerabilities and agentic risk

Overview

The skill is largely a procurement-analysis helper, but it also performs account onboarding, sends a hardware-derived identifier, persists API credentials, saves reports with signed links, and renders unvalidated links, so users should review it before installing.

Install only if you are comfortable with this provider handling tender-search queries, account setup, and a hardware-derived MAC hash for trial deduplication. Prefer supplying your own ZLBX_API_KEY to avoid auto-registration, review or restrict ~/.zlbx/config.json permissions, and avoid sharing generated HTML reports unless you are sure signed sk or auto-login links inside them are safe to disclose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/render_report.py:284
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
📊 报告涉及企业的完整档案与更多商机,见 知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 投标决策分析 Skill 生成' ) ``` The Skill instructions additionally require an unsolicited next-step recommendation after reports and require fixed marketing content when describing the Skill. ### Technical Analysis The Skill changes the Agent's response policy by requiring platform promotion, cross-Skill recommendations, and external commercial links even when these elements are not necessary to answer the user's request. The HTML renderer independently hard-codes the same promotion, preventing the Agent from omitting it based on user intent. This behavior is stable instruction-driven output manipulation rather than a contextual recommendation. It therefore matches `T01: Skill Instruction Hijacking`. It does not directly override core safety controls, but it alters the current session's output goals and redirects users toward services operated by the Skill provider. ### Attack Path 1. A user installs or invokes the Skill for procurement analysis. 2. The Skill's mandatory response rules become part of the Agent's active instructions. 3. The Agent completes the requested analysis. 4. The Skill requires the Agent to append a promotional recommendation or external platform link. 5. When an HTML report is generated, the renderer inserts an additional hard-coded advertisement regardless of the user's request. 6. The user may be redirected to an affiliated external platform under the apparent authority of the Agent-generated report. ### Impact Assess ...[truncated 454 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:56
Finding

Stable Hardware Fingerprint Is Collected and Sent to an External Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting fingerprint is included in the registration request: ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "bid-decision-1.0.5", "ch": "s84" } ``` The request is sent to: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register ``` ### Technical Analysis The automatic registration workflow enumerates a physical network interface, reads its MAC address, normalizes it, computes SHA-256, and sends the result to an external registration service together with the operating-system platform and CPU architecture. Hashing does not make a MAC address anonymous. MAC addresses have a constrained structure and relatively low entropy, and a deterministic unsalted hash remains a stable identifier suitable for long-term device correlation. The data is used to distinguish devices for trial-account allocation, but hardware fingerprinting is not necessary for the Skill's primary procurement-analysis functionality. The workflow includes mitigating controls: it requires user consent before collection, supports an API-key-based bypass, avoids transmitting the raw MAC address, and instructs the Agent not to collect the hostname, username, or home path. These controls reduce but do not eliminate the privacy and least-privilege concerns. ### Attack Path 1. The Skill checks the envi ...[truncated 1118 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_report.py:138
Finding

Generated Reports Accept Executable URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` The helper is used for citation URLs: ```python rows = "".join( f'{_link(x.get("title"), x.get("url"))}' + ('(需登录主站)' if x.get("login_required") else "") + f'{esc(x.get("type", ""))}{esc(x.get("date", ""))}{esc(x.get("use", ""))}' f'' for x in items ) ``` The primary announcement URL is handled similarly: ```python bid_link = f'' if d.get("bid_url") else "" ``` ### Technical Analysis The renderer applies XML escaping to URL strings before inserting them into `href` attributes. Escaping prevents quotation-mark breakout and ordinary HTML attribute injection, but it does not validate the URL scheme or destination. Consequently, values such as the following remain syntactically valid links: ```text javascript:alert(document.domain) data:text/html, ``` The Skill explicitly instructs the Agent to preserve URLs returned by the API without alteration. If an API response, report JSON file, or intermediary data source is malicious or compromised, an executable URL can reach the generated HTML unchanged. The use of `target="_blank"` without `rel="noopener noreferrer"` also permits opener-related risks in browser implementations where implicit isolation is unavailable or inconsistent. ### Attack Path 1. An attacker controls or compromises an API record, intermediary response, or input report JSON. 2. The attacker places a `javascript:`, `data:`, or other unsa ...[truncated 1246 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

API Key Persistence Does Not Require Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个分析型技能,重点在于对招标项目进行风险识别、数据分析和投标决策支持;而实际代码是一个纯展示层/报告生成器,用于把外部已经生成好的 JSON 结果输出成 HTML 页面。虽然输出页面标题和字段与“投标决策分析”相关,属于同一业务域,但该代码本身没有实现声明中的核心能力,也没有访问全网招中标数据或执行任何识别逻辑。因此其实际主功能与声明用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates use for broad, loosely defined intents such as whether a tender is 'worth bidding,' which can cause over-triggering. In practice this increases the chance of unnecessary external API calls, local file operations, and account-registration prompts in conversations where the user did not clearly request this skill, expanding both privacy and operational risk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to collect device fingerprinting attributes, including a hashed MAC-derived identifier, for automatic registration even though this is not necessary for analyzing bid documents or procurement risk. Hashing the MAC does not eliminate the privacy/security concern because it still creates a stable cross-session device identifier that can be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file defines a full account provisioning, recovery, and recharge workflow that is unrelated to the skill’s stated purpose of bid-risk analysis. Expanding a domain-specific analysis skill into credential acquisition and account-management behavior increases attack surface, enables unnecessary collection/use of local and remote account state, and can surprise users into authorizing actions beyond the expected scope.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template repeatedly instructs the agent to preserve and expose signed access URLs, including login-bypass parameters, in Markdown, JSON, and HTML outputs. This operationalizes distribution of sensitive bearer links across multiple formats, increasing the chance of replay, unauthorized access, downstream logging exposure, and broad sharing beyond the intended recipient.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 71)May include surrounding context.

python
THREAT_COLOR = {"高": "#c0392b", "中": "#b9770e", "低": "#0d9463"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents local file creation for HTML reports but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap: an agent runtime may grant broader filesystem capabilities than users expect, enabling unintended writes or abuse if the skill is invoked in other contexts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs automatic account registration using device-derived identifiers (including a MAC-based hash) when no API key is present. Even with consent language, this extends beyond the core bid-analysis function into identity/device tracking and external account creation, increasing privacy risk and creating an unnecessary data collection path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The fixed self-introduction content is entirely prescribed in Chinese and marked as mandatory output, with no indication that the user can choose another language. This creates a language/locale policy issue because the skill appears to enforce one language rather than offering opt-in or adapting to the user's preference.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow checks environment variables and local config files for API keys and later writes credential state to the user’s home directory, despite the skill being advertised as a bid-risk checker. Reading and mutating local credential/config state outside the declared purpose violates least surprise and broadens what the skill can do on the host.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This line documents sending collected device features to an external endpoint using JSON serialization. In context, the dangerous part is not the serialization advice itself but that the skill is exfiltrating host-derived identifiers to a third-party service as part of an off-purpose auto-registration flow.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The curl example reinforces an outbound request pattern for sending registration payloads to a remote service. Although the code snippet is instructional rather than exploit code, it still operationalizes external transmission of host-derived data unrelated to the stated procurement-analysis purpose.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding points to the same persistent credential-writing behavior: creating ~/.zlbx, merging config, and marking the source for later privileged flows. The persistence is risky because it enables the skill to alter host auth state permanently and unlock follow-on account actions beyond the expected analytical role.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding points to the same persistent credential-writing behavior: creating ~/.zlbx, merging config, and marking the source for later privileged flows. The persistence is risky because it enables the skill to alter host auth state permanently and unlock follow-on account actions beyond the expected analytical role.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Generating auto-login or recharge links is an account-management capability unrelated to tender-risk analysis. Embedding this flow in the skill normalizes off-purpose privileged actions and could be abused to steer users into unintended account operations or external sites during normal analytical use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template explicitly requires exposing API-returned URLs with intact sk login-bypass signatures and forbids removing them. Signed bearer-style links are sensitive access artifacts; propagating them into user-visible reports can leak privileged access, enable unintended sharing, and bypass normal authentication controls beyond the narrow purpose of bid-risk analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions cause report contents to be serialized to JSON, written to a temporary file, and rendered to a persistent HTML file by default, yet provide no user-facing warning about local file creation or data retention. Because the report may include company names, procurement history, and sensitive business assessments, silent persistence can violate user expectations and increase the risk of unintended disclosure on the host system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and the generated report content are entirely in Chinese, and the HTML is explicitly marked with lang='zh-CN'. The policy only allows fixed language or locale behavior when user choice is offered or the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest description focuses on producing risk reports from historical online tender and award data. Later documentation expands behavior to accept user-provided local tender documents as inputs, which is a broader operating mode than the manifest alone suggests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest frames the skill as producing risk assessment reports from web bidding history data, but does not mention generating and saving local HTML artifacts. Persisting shareable reports to disk is an additional capability beyond the narrowly described analytical assistant behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no indication that use of Chinese is optional or that the skill is intentionally limited to Chinese-speaking users. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill directs default generation of an HTML report on local disk and disclosure of the absolute file path, which creates an unnecessary data-export and persistence channel for potentially sensitive procurement analysis. While less severe than credential leakage, it expands the attack surface by storing analysis artifacts outside the chat flow without clear necessity for the skill's stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code creates an output directory and writes a rendered HTML report file, which is a file-modifying operation covered by the missing-warning rule for code files. Although the script's top docstring describes the output location, there is no runtime confirmation, user-facing notice before writing, or explicit warning about overwriting/creating files at execution time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.