Back to skill

Security audit

企查猫企业情报-企业全景一次看清

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real company-intelligence skill, but it needs review because it stores credentials locally, sends a hardware-derived device identifier during signup, and creates shareable reports with sensitive access links.

Install only if you are comfortable using the Zhiliaobiaoxun service for company research. Prefer setting your own ZLBX_API_KEY instead of auto-registration. If you approve auto-registration, the skill will send a stable MAC-derived hash plus platform and CPU architecture to the provider and store an API key in ~/.zlbx/config.json. Treat generated HTML reports as sensitive because they may contain signed sk links and contact details; share them only with intended recipients.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:97
Finding

Mandatory Promotional Content Overrides User-Controlled Report Output

Content
View full analysis
知了标讯' '全网招中标大数据 · zhiliaobiaoxun.com' ) parts.append( '
' f'
📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成
' ) ``` ### Technical Analysis The Skill requires the agent to include fixed branding, examples, conversion messages, and links to related commercial services. These directives are independent of the user's requested company analysis and are expressed as mandatory output requirements. The HTML renderer reinforces the instructions by unconditionally inserting branding and promotional links into every generated report. This exceeds the minimum behavior needed to retrieve company information and render an analysis report. It reduces user control over the agent's response and introd ...[truncated 993 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:56
Finding

Stable Hardware-Derived Device Fingerprint Is Sent to a Remote Registration Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting value is included in this registration request: ```json POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s116" } ``` ### Technical Analysis The registration workflow deterministically hashes a normalized hardware MAC address and transmits the hash, operating-system platform, and CPU architecture to a third-party service. SHA-256 does not make a MAC address anonymous. MAC addresses have a constrained format and can be tested by enumeration, while the deterministic output remains a stable identifier for correlation across sessions. The stated consent gate is a meaningful safeguard because collection and transmission are prohibited until the user agrees. Nevertheless, hardware-derived tracking is not required for the core function of company analysis and therefore exceeds the minimum privileges necessary for that function. There is also an internal documentation inconsistency: the sample request uses channel value `s116`, while the subsequent instruction at line 129 says to use `s105`. This does not itself expose privileges, but it weakens the reliability and auditability of the registration process. ### Attack Path 1. The Skill finds ...[truncated 1082 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

API Key Persistence Lacks Restrictive Permissions and Safe File-Creation Requirements

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:80
Finding

Generated HTML Allows Attribute Injection and Unsafe URL Schemes

Content
View full analysis
str: return _esc(str(s if s is not None else "")) ``` ```python def _link(text, url): return f'{esc(text)}' if url else esc(text) ``` ```python src_html = ( f'来源:{esc(src)}' if src else "" ) ``` ```python if prof.get("url"): inner += ( f'
公司完整档案(业务词云/联系人/合作图谱免登录直达):' f'{esc(prof["url"])}
' ) ``` ### Technical Analysis `xml.sax.saxutils.escape()` escapes `&`, `<`, and `>` by default, but it does not escape quotation marks unless an additional entity mapping is supplied. The renderer inserts values into double-quoted `href` attributes. A value containing a quotation mark can therefore terminate the attribute and inject additional attributes or markup. The renderer also does not validate URL schemes. A value using `javascript:`, `data:`, or another unsafe scheme can be placed into a clickable link. Because several URL fields originate from API responses, public web-search results, or report JSON, a compromised upstream source or attacker-controlled report input can deliver a malicious value. Using `target="_blank"` without `rel="noopener noreferrer"` also permits opener-based manipulation in browsers that do not implicitly isolate new tabs. ### Attack Path One possible attribute-injection path is: 1. An attacker controls or compromises an upstream URL value. 2. The value is set to content such as `" onmouseover="a ...[truncated 1204 chars]
Remediation
View remediation
str: return escape(str(value if value is not None else ""), quote=False) def esc_attr(value) -> str: return escape(str(value if value is not None else ""), quote=True) ``` 2. Use the attribute-specific escaping function for every `href`, `src`, class, and other attribute value. 3. Parse URLs with `urllib.parse.urlsplit`. 4. Allow only explicitly approved schemes, preferably `https`. 5. For platform links, enforce an exact hostname allowlist. 6. Reject control characters, embedded credentials, malformed ports, and protocol-relative URLs. 7. Render rejected URLs as inert text rather than clickable links. 8. Add `rel="noopener noreferrer"` to all links using `target="_blank"`. 9. Add a restrictive Content Security Policy to generated HTML, accounting for the currently embedded script only through a hash or nonce. 10. Add automated tests for quotation marks, `javascript:` URLs, `data:` URLs, malformed Unicode hosts, and event-handler injection payloads. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file instructs the agent to perform account provisioning, device-based registration, credential storage, and recharge/login handling, all of which are outside the declared purpose of a company-intelligence analysis skill. Expanding a read-oriented analysis skill into credential lifecycle management materially increases attack surface by enabling local data access, persistent secret handling, and outbound authentication flows unrelated to the user’s requested analysis task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to inspect environment variables and local config files for API keys, and later to write persistent credentials into the user’s home directory. For a company-analysis skill, accessing and modifying local credential stores exceeds expected scope and creates risk of unintended secret exposure, clobbering user configuration, and silent persistence of authentication material.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill collects device fingerprint components (platform, CPU architecture, MAC-derived hash) and transmits them for account provisioning, even though that collection is not necessary for enterprise-intelligence analysis. Even with hashing, MAC-derived identifiers are persistent device identifiers and create privacy and tracking risk, especially when embedded in an unrelated skill where users may not expect host-level collection.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

python
# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly performs local file writes for HTML report export, but it does not declare any tool or permission scope limiting that capability. In an agent environment, undeclared write access weakens least-privilege controls and can allow unintended file creation or overwrite if the skill is invoked in broader contexts than expected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation rule says the skill must be used even when the user did not mention 'intelligence' and broadly covers any request to 'fully understand' a company. This can cause over-triggering, unnecessary external data disclosure, unexpected account consumption, and execution of file/network side effects for requests that may only need a simple answer or a different skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The document title and all operational guidance are written exclusively in Chinese, which effectively constrains use to a specific language/locale. Under the policy, forcing a language without explicit user opt-in or documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents a tool that retrieves project contact phone numbers, including potentially full numbers for paid accounts, even though the skill’s stated purpose is enterprise intelligence and reporting rather than direct outreach or contact harvesting. This creates a clear risk of privacy misuse, targeted solicitation, and unauthorized personal-data exposure, especially because the instructions normalize displaying returned phone data ‘as-is’.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill exposes a capability to retrieve and display project contact phone numbers but does not include a meaningful user-facing privacy warning about handling personal contact data. The existing note focuses on preserving returned formatting and monetization behavior, not on lawful use, consent, or privacy boundaries, which increases the likelihood of misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file provides prescribed user-facing prompts and responses entirely in Chinese, including text to relay verbatim to the user, but does not offer any user language selection or state that the skill is intentionally limited to Chinese-speaking users. This can violate language/locale policy when used in a broader multilingual environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This line documents making an outbound HTTP request that transmits locally collected device features to an external service. External transmission is sensitive here because the transmitted data originates from host inspection and is unrelated to the core company-intelligence function, so the skill context makes the transmission more dangerous than a normal API call for analysis results.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The curl -d @file example is another instruction path for sending collected local data off-host to the registration endpoint. While the serialization advice itself is technically sound, the underlying behavior remains risky because it operationalizes external transmission of device-derived identifiers in a skill whose stated purpose is business intelligence analysis.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Line L129 explicitly states that the ch field must be fixed to "s105", but the concrete request example at L115 and pseudocode at L242 use "s116". This is a direct contradiction in the file’s own guidance and could cause the agent to follow the wrong channel code.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

This duplicate finding refers to the same persistence behavior: creating ~/.zlbx, merging config, writing api_key, and carrying it forward for subsequent requests. In the context of an intelligence-reporting skill, covertly normalizing durable auth state is more dangerous because users would not reasonably expect persistent local account modification from a data-analysis assistant.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

This duplicate finding refers to the same persistence behavior: creating ~/.zlbx, merging config, writing api_key, and carrying it forward for subsequent requests. In the context of an intelligence-reporting skill, covertly normalizing durable auth state is more dangerous because users would not reasonably expect persistent local account modification from a data-analysis assistant.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown says the skill should react to phrases like “重新生成充值链接”, “充值链接过期了”, and “链接打不开” or similar expressions. These are broad conversational phrases and the document does not define exclusions or tighter context, which could cause unintended invocation outside the intended quota-recovery flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file title and content establish the report template in Chinese, and no language-choice mechanism or opt-in is offered anywhere in the template. This creates a natural-language policy issue because it effectively forces a specific language/locale for all users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template explicitly requires preserving and exposing full URLs containing sk免登录 parameters so recipients can access company and announcement pages without normal authentication barriers. If those sk values function as bearer-style access tokens, including them in generated reports or shareable HTML can leak privileged access to anyone who receives, forwards, logs, or indexes the content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template directs the agent to automatically write report data to a temporary JSON file and execute a local Python renderer, creating files as a default side effect. Even without direct command injection visible here, automatic code execution and file creation expands the attack surface, can expose sensitive data on disk, and may be unsafe in constrained or multi-tenant agent environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default export behavior writes a local HTML report and reveals the absolute filesystem path to the user without explicit warning or consent. This can disclose environment details, persist potentially sensitive enterprise intelligence on disk unexpectedly, and increase the chance of accidental sharing or retention beyond the chat session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and the document content prescribe a Chinese-language workflow, and later sections include mandatory wording requirements, but nowhere offer the user or operator a language/locale choice. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The sample invocation begins with "帮我背调一下…", which is natural conversational language and may overlap with ordinary requests unless the manifest explicitly constrains when it should match. On its own, this example does not define a precise trigger set or exclusions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The generated document hard-codes lang='zh-CN', which enforces a specific language/locale for all output regardless of user preference or input context. The file-level docstring and visible UI strings are also exclusively Chinese, with no documented locale choice or opt-in mechanism.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.