Back to skill

Security audit

客户背景调查-摸清客户采购底细

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed company-intelligence integration, but it handles device identifiers, persistent credentials, auto-login links, and signed access links in ways users should review carefully before installing.

Install only if you are comfortable with this provider receiving company queries and, during automatic registration, a MAC-hash-based device identifier. Treat generated reports and any sk or auto-login links as sensitive, because forwarding them may grant access to provider pages. Prefer supplying your own API key through a managed secret or tightly permissioned config file, and avoid exporting reports with contact data unless you have a valid business purpose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:477
Finding

Mandatory Promotional Output and External Commercial Redirection

Content
View full analysis

Vulnerability Details

File Location: scripts/render_report.py:477-482; related instructions in SKILL.md:95, 118-125, 137-139, 169 and references/report-template.md:188-196
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code

python
parts.append(
    '<div class="footer">'
    f'<div class="cta">📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · '
    f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 '
    f'<a href="https://agent.zhiliaobiaoxun.com" target="_blank">知了商机大师</a>'
    f' · 本报告由 <a href="https://ai.zhiliaobiaoxun.com" target="_blank">知了标讯 AI 开放平台</a> 企业情报 Skill 生成</div>'
)

The related Skill instructions also require fixed self-promotional content, cross-Skill recommendations, monitoring promotion, and commercial platform links to be included in responses.

Technical Analysis

The Skill alters the expected response policy by requiring promotional and cross-product content that is not necessary to complete a company background investigation. The HTML renderer enforces this behavior independently of report input, meaning callers cannot omit the commercial call-to-action through normal report data.

This is instruction hijacking because loading the Skill introduces persistent response requirements that advance the provider's marketing and redirection objectives rather than only satisfying the user's request. The behavior does not modify system-level safety rules, but it does compromise response integrity and user control.

Attack Path

  1. A user requests a company background report.
  2. The Agent loads the Skill and follows its mandatory output rules.
  3. The report renderer unconditionally constructs the branded footer.
  4. The generated report includes unsolicited monitoring promotion and links to the provider's commercial services.
  5. The user may follow those links under the assumption that they ar ...[truncated 469 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove unconditional promotional and cross-product content from the renderer.
  • Limit the footer to neutral data-source attribution and the required disclaimer.
  • Present monitoring, paid features, or related Skills only when directly relevant to an explicit user request.
  • Require an opt-in before adding commercial links or calls to action.
  • Add a renderer option that disables all promotional content, with promotion disabled by default.
  • Clearly label any optional commercial recommendation as advertising rather than report evidence.

other

Warning
Location
references/auto-register.md:43
Finding

Stable Device Fingerprinting Transmitted During Automatic Registration

Content
View full analysis

Vulnerability Details

File Location: references/auto-register.md:43-117
Vulnerability Type: other: Device Fingerprinting and Privacy Leakage
Risk Level: Medium

Vulnerable Code

bash
iface=$(ls /sys/class/net | grep -vE '^(lo|docker|veth|br-|tun|tap)' | sort | head -n1)
cat "/sys/class/net/$iface/address" 2>/dev/null \
  | tr -d ':-' | tr 'A-Z' 'a-z' \
  | sha256sum | awk '{print $1}'

The resulting fingerprint is placed in the registration request:

json
{
  "device_features": {
    "hostname": "",
    "platform": "darwin",
    "arch": "arm64",
    "username": "",
    "home_path": "",
    "mac_hash": "abc123..."
  },
  "agent_kind": "claude-code",
  "agent_version": "...",
  "skill_version": "company-intel-1.0.2",
  "ch": "s127"
}

The payload is sent to:

text
POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register

Technical Analysis

The registration workflow enumerates a physical network interface, reads its MAC address, normalizes it, hashes it with SHA-256, and transmits the result together with the operating-system platform and CPU architecture.

Hashing does not make a MAC address anonymous. MAC addresses have limited entropy and a predictable format, so a hash remains a stable pseudonymous identifier and can be correlated across registrations. The documented consent gate reduces the risk of collection without notice, but the hardware-derived identifier is not required for the Skill's declared company-research functionality. It supports the service provider's trial-account deduplication rather than the user's requested task.

Attack Path

  1. The Skill fails to find an API key in the environment or local configuration.
  2. The Skill asks the user to approve automatic trial registration.
  3. After approval, the Agent enumerates local network interfaces.
  4. It selects a physical interface and reads its hardware addres ...[truncated 680 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the MAC-derived value with a cryptographically random installation identifier generated locally.
  • Do not inspect physical network interfaces or hardware addresses.
  • Store any random installation identifier separately from account credentials and document its retention purpose.
  • Make automatic registration an optional, clearly separated feature rather than part of the core research workflow.
  • Provide a manual registration method that does not collect a hardware fingerprint.
  • Define retention, deletion, and correlation policies for any transmitted device identifier.
  • If abuse prevention requires an identifier, use a privacy-preserving server challenge or rate-limiting mechanism that cannot track a physical device across installations.

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:170
Finding

Plaintext API Key Persistence Without Mandatory File Permission Controls

Content
View full analysis

Vulnerability Details

File Location: references/auto-register.md:170-186
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code

json
{
  "api_key": "zlbx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
  "source": "auto",
  "registered_at": "2026-05-10T10:30:00Z"
}

The persistence instructions state that the directory should be created and existing configuration should be merged, but they do not require restrictive permissions:

text
- Create ~/.zlbx when the directory does not exist.
- Merge with an existing file rather than overwriting it.
- Persist source: "auto" for later workflow decisions.

Technical Analysis

The workflow stores a reusable API key in plaintext at ~/.zlbx/config.json. It does not mandate directory mode 0700, file mode 0600, atomic file creation, ownership checks, symlink rejection, or secure replacement of an existing file.

Consequently, effective access depends on the host's umask and pre-existing filesystem state. On a permissively configured multi-user system, another local user or process may be able to read the key. If an attacker can pre-create the path as a symbolic link, an unsafe implementation of the documented merge operation may also disclose or overwrite unintended files.

Attack Path

  1. Automatic registration returns a valid API key.
  2. The Agent creates ~/.zlbx and writes config.json using default filesystem permissions.
  3. A permissive umask or unsafe pre-existing path makes the file readable or replaceable by another local principal.
  4. A local attacker reads the plaintext key or redirects the write through a symbolic link.
  5. The attacker reuses the key against the external API, consuming quota or accessing account-scoped functionality.

Impact Assessment

Exploitation requires local filesystem access under another user or compromised process context. A successful attacker can obt ...[truncated 262 chars]

Remediation
View remediation

Remediation Suggestions

  • Create ~/.zlbx with mode 0700.
  • Create the credential file atomically with mode 0600, independent of the process umask.
  • Reject symbolic links and non-regular files before reading or replacing the configuration.
  • Verify that the directory and file are owned by the current user.
  • Write to a securely created temporary file in the same directory, flush and synchronize it, and then atomically rename it.
  • Preserve restrictive permissions when merging existing configuration.
  • Prefer the operating system's credential store or keychain instead of a plaintext JSON file.
  • Never include the API key in logs, command-line arguments, exceptions, or user-facing output.

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:200
Finding

Auto-Login Bearer SID Exposed in Conversation and URL Query String

Content
View full analysis

Vulnerability Details

File Location: references/auto-register.md:200-218
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code

text
POST https://ai.zhiliaobiaoxun.com/web-api/auth/generate-device-sid
Header: X-API-Key: <current_api_key>
Body: empty

The returned SID is inserted into a user-visible URL:

text
https://ai.zhiliaobiaoxun.com/auto-login?sid=<sid>

The workflow requires the complete URL to be printed directly into the conversation and states that it remains valid for one hour.

Technical Analysis

The SID is generated using an authenticated API call and then used as an auto-login credential. It therefore has bearer-token characteristics: possession of the URL may be sufficient to exercise the associated login flow.

Placing the SID in a query string and printing it in the conversation broadens its exposure. It may be retained in Agent transcripts, terminal output, observability systems, browser history, bookmarks, screenshots, proxy logs, or copied chat exports. Query-string credentials can also leak through referrer handling if the destination page loads or navigates to other resources without an appropriately restrictive referrer policy.

Attack Path

  1. The account reaches its quota limit.
  2. The Agent sends the current API key to the SID-generation endpoint.
  3. The service returns an auto-login SID.
  4. The Agent embeds the SID in a URL and prints it into the conversation.
  5. A party with access to the transcript, logs, screen, clipboard, browser history, or network metadata obtains the URL before expiry.
  6. The party opens the URL and attempts to use the auto-login capability associated with the SID.

Impact Assessment

The exact account actions available after auto-login are not established by the audited files, so broader account takeover cannot be asserted. However, leakage may grant an unautho ...[truncated 175 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not print auto-login bearer tokens into conversation history.
  • Avoid placing credentials in URL query parameters.
  • Use a short-lived, single-use authorization code delivered through a trusted local browser handoff.
  • Bind the code to the initiating session and invalidate it immediately after first use.
  • Reduce the validity period substantially below one hour.
  • Apply Referrer-Policy: no-referrer, Cache-Control: no-store, and equivalent protections on the redemption endpoint.
  • Redact SID values from application, proxy, analytics, and Agent logs.
  • Provide a manual authenticated recharge URL when a secure browser handoff is unavailable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description centers on company background checks, but the content introduces additional operational behaviors such as local file output, HTML rendering/export, API key acquisition flows, and optional registration logic that are not cleanly bounded in the declared capability model. This mismatch reduces transparency and can cause an agent to exercise broader capabilities than a user would infer from the description, especially around local persistence and account-related actions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file embeds a full auto-registration and account-management workflow inside a skill whose declared purpose is client background investigation. That scope mismatch is dangerous because it authorizes unrelated collection of host attributes, credential issuance, and persistence behaviors that users would not reasonably expect from this skill, increasing the chance of covert data handling and privilege expansion.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document directs the agent to collect device fingerprint material (platform, CPU architecture, MAC-derived hash) and create remote accounts, which is unnecessary for producing customer background reports. Even with hashing and stated minimization, this still transmits stable device-linked identifiers to an external service, creating privacy, tracking, and unauthorized account-provisioning risk outside the user's apparent task.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires preserving and redistributing full URLs containing sk login-bypass parameters in report output and generated artifacts, without warning users that these links are access-bearing secrets. Embedding such tokens in shareable reports can leak authenticated access to company pages or deeper content if the report is forwarded, stored, or indexed.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file instructs the agent to expose raw API-returned links with sk parameters in both the conversation and exported HTML/JSON artifacts. Because these parameters function as login-bypass or bearer-style access tokens, their disclosure materially increases the risk of unauthorized access through report sharing, local file leakage, browser history, logs, and downstream systems that ingest the artifact.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is a direct secret-disclosure issue: the skill says to record the returned url '(带 sk)' and output the company-page link unchanged. Secret-bearing links commonly function as authenticated URLs; disclosing them in generated reports can leak credentials to users, downstream systems, chat logs, exports, or third parties who receive the report. The skill context makes this more dangerous because report sharing is a core use case, so leaked links are likely to propagate.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow requires attaching announcement links '原样带 sk', which again instructs verbatim disclosure of secret-bearing URLs in report output. Because announcement links may be copied into emails, CRMs, or bid-review documents, any embedded token can be redistributed far beyond the original authorized user, resulting in unauthorized access and difficult-to-contain credential leakage.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The upgrade/contact guidance tells the agent to point users to a company-page URL '带 sk 原样输出', creating another explicit pathway to leak access-bearing links. Combining secret-bearing URLs with contact-discovery features increases abuse potential, since a recipient may gain both access to protected records and sensitive personal contact data. This is not mitigated by the business context; if anything, the background-check and lead-generation workflow raises the chance of broad internal sharing.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

python
# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to write HTML reports to a local directory and disclose the absolute file path, but it declares no tool scope or permissions boundary. That creates an unnecessary file-write capability without clear sandboxing, making it easier for the skill to write artifacts to disk in ways the user may not fully expect or consent to.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L003 使用了“即使用户没有提到‘背调’,只要想在接触客户前了解它的采购习惯与供应商现状,都应使用本SKILL”这类宽泛条件,缺少更明确的触发边界或反例。虽然列出了一些相邻技能边界,但该表述本身仍可能覆盖大量普通公司信息查询请求,导致误触发。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation directs users to send requests to an external service using an X-API-Key header, but it does not clearly warn that credentials are being transmitted off-platform or provide handling guidance for secrets. In an agent skill context, this increases the risk of accidental credential exposure, unintended third-party data transfer, and misuse of privileged API access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The contact retrieval tool returns personal phone numbers and instructs the agent to display them as returned, but the documentation lacks an upfront privacy, consent, and lawful-use warning. In a customer intelligence skill, this makes the issue more dangerous because the workflow is explicitly geared toward pre-sales investigation and could facilitate bulk harvesting, misuse of personal data, or privacy-law violations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This section explicitly instructs posting collected device features to an external endpoint. In context, the transmission is not justified by the skill's stated business purpose, so it represents unauthorized data egress to a third party and increases privacy and compliance risk even if the payload is JSON-serialized correctly.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The documented use of curl or similar mechanisms to send payloads to a remote registration service confirms external exfiltration capability. Within a background-check skill, this is dangerous because it normalizes transmitting locally derived device identifiers and account data to an unrelated service path, expanding attack surface and violating least surprise.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file instructs persistent storage of API keys in the user's home directory and adds balance/recharge auto-login flows that are unrelated to client investigation. Persistent credential handling increases the blast radius of local compromise or unintended reuse, and the recharge/login flow broadens the skill from research into account lifecycle control.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a configuration directory and merging credentials for future automatic reuse. In context, that persistence materially increases risk because it turns a one-time hidden registration into durable account access across sessions without a clear boundary from the skill's investigative role.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a configuration directory and merging credentials for future automatic reuse. In context, that persistence materially increases risk because it turns a one-time hidden registration into durable account access across sessions without a clear boundary from the skill's investigative role.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prescribed user-facing text is explicitly written as mandatory output and requires the agent to present a Chinese message and link guidance to the user. This imposes a specific language on users without documenting a locale-specific justification or offering a choice, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file is written as a report template whose instructions prescribe output in Chinese and do not offer an alternative language or ask for user preference. This can violate language-choice policy when applied to users who have not opted into that locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template directs the agent to create a local HTML file by default after producing the Markdown report, but does not require explicit user consent or clearly warn that a filesystem write and artifact creation will occur. Automatic file generation can surprise users, create unintended data retention of sensitive business intelligence, and increase the chance that reports containing sensitive links or company data persist on disk beyond the chat session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly instructs the agent to output company-page URLs '原样输出' including an embedded sk parameter. If sk is a bearer-style access token, session key, or signed access grant, exposing it to end users can enable unauthorized reuse, link sharing, or access outside the intended trust boundary. In a customer-intelligence skill that systematically generates reports, this creates a repeatable secret-disclosure path rather than a one-off mistake.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow directs the agent to display returned contact phone numbers exactly as provided, including full numbers for some account tiers, and frames this as normal report output. These are personal contact details, and emitting them without explicit purpose limitation, minimization, consent checks, or handling warnings increases privacy, compliance, and misuse risk such as scraping or harassment. Because this skill is designed for pre-sales background checks, the data is especially likely to be used operationally and at scale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.