Back to skill

Security audit

爱企查企业情报-招投标实力视角查企业

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its company-report purpose, but it handles device identifiers, API credentials, local report files, and signed login-bypass links in ways users should review carefully.

Install only if you are comfortable with the vendor API receiving company queries and, if you use auto-registration, a stable hashed device identifier. Prefer setting your own ZLBX_API_KEY, check permissions on ~/.zlbx/config.json, avoid forwarding reports that contain sk or auto-login links, and use contact lookup only for a legitimate business purpose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:476
Finding

Mandatory Promotional and Monitoring Content Hijacks Report Output

Content
View full analysis
' f'
📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成
' ``` Related mandatory-output instructions also appear at: - `SKILL.md:97` - `SKILL.md:124-130` - `SKILL.md:169` - `references/report-template.md:191-196` ### Technical Analysis The report renderer unconditionally injects platform promotion, monitoring-workflow messaging, and links to commercial services. This content is not derived from the user's request or the report data, and callers cannot disable it through the renderer's input. The Skill instructions reinforce this behavior by requiring fixed monitoring and promotional language in normal responses. Consequently, loading and using the Skill changes the Agent's output goals from producing a company intelligence report to also promoting continued monitoring, related Skills, and external commercial services. Although branding alone is not inherently malicious, making these calls to action mandatory and embedding them unconditionally in generated artifacts exceeds the minimum behavior required for company analysis. It represents persistent control over the Agent's response content. ### Attack Path 1. A user asks the Agent to investigate a company. 2. The Agent loads the Skill and follows its mandatory report workflow. 3. The Agent invokes `render_report.py` to create the HTML report. 4. The renderer unconditionally appends monitoring and platform promotional content. 5. The user receives attacker-selected messaging and outbound comme ...[truncated 508 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:44
Finding

Stable Hardware-Derived Device Fingerprint Is Collected and Transmitted

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` **Request**: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json ``` ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s124" } ``` ### Technical Analysis When an API key is unavailable, the registration workflow reads a physical network interface's MAC address, normalizes it, calculates an unsalted SHA-256 digest, and transmits that digest alongside the operating-system platform and CPU architecture. The workflow includes an explicit user-consent gate, which materially reduces the risk of covert collection. Nevertheless, the collected value is a stable hardware-derived identifier. Hashing does not make the value anonymous: MAC addresses have a constrained and structured input space, and the same normalized address always yields the same digest. The service can therefore correlate registrations or sessions associated with the same device. The ...[truncated 1571 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

API Key Is Persisted Without Required Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:168
Finding

Generated HTML Accepts Unvalidated URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) def _table(head_cols: list[str], rows_html: str, cls: str = "") -> str: if not rows_html: return "" head = "".join(f"{esc(c)}" for c in head_cols) if head_cols else "" head = f"{head}" if head else "" c = f' class="{cls}"' if cls else "" return f'
{head}{rows_html}
' def _card(title: str, inner: str, subnote: str = "") -> str: if not inner: return "" sub = f'
{esc(subnote)}
' if subnote else "" return f'

{esc(title)}

{sub}{inner}
' def _notes(items) -> str: items = [i for i in (items or []) if i] if not items: return "" return '
    ' + "".join(f"
  • {esc(i)}
  • " for i in items) + "
" def _risk_list(risks) -> str: lis = [] for r in risks or []: if isinstance(r, str): text, src = r, "" else: text, src = r.get("text", ""), r.get("source_url", "") src_html = ( f'来源:{esc(src)}' if src else "" ) lis.append(f"
  • {esc(text)}{src_html}
  • ") return f'
      {"".join(lis)}
    ' if lis else "" ``` ### Technical Analysis The renderer correctly escapes HTML metacharacters, preventing straightforward attribute-breakout injection. However, HTML escaping does not validate URL semantics. Values such as `javascript:`, `data:`, or `file:` remain valid attribute values after escaping. The report accepts links from API responses, citations, company records, and pu ...[truncated 1516 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    Findings (26)

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Description-Behavior Mismatch

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The file instructs the agent to perform account bootstrapping, device-feature collection, remote registration, and credential handling, which are materially unrelated to the declared purpose of a company-intelligence/reporting skill. This unnecessary expansion of capability increases attack surface and can cause the agent to collect and transmit host-derived identifiers and persist secrets without a strong functional justification tied to the user’s requested analysis task.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The prose says user consent must be obtained before any collection or registration, but the pseudocode proceeds directly from missing key detection to feature collection and POSTing to the registration endpoint with no consent gate. In practice, implementation often follows executable examples, so this inconsistency can lead to silent collection/transmission of host-derived identifiers without user authorization.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    High
    Category
    Not specified by scanner
    Confidence
    97% confidence
    Finding

    The skill directs collection of device fingerprint elements (platform, architecture, MAC-derived hash) and persistence of an API key under the user home directory even though those actions are not justified by the analytics role of the skill. Even hashed MAC data is still a stable device identifier for tracking/account linkage, and local credential persistence increases the risk of unintended reuse, leakage, or abuse by other processes or later prompts.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The template explicitly requires preserving and sharing full URLs containing an sk login-bypass parameter in user-visible output and exported reports. If that parameter grants authenticated or bearer-style access, exposing it can leak access tokens, enable unauthorized viewing, and allow link forwarding beyond the intended recipient.

    Content

    No source excerpt is available for this finding.

    Ssd 3

    High
    Category
    Not specified by scanner
    Confidence
    99% confidence
    Finding

    This is a direct secret-disclosure pattern: the skill mandates exposing raw API-returned links that include sk login-bypass parameters in both the chat response and generated artifacts. In a company-intelligence skill, reports may be forwarded or stored widely, so embedding reusable access-bearing links can unintentionally grant third parties access to protected resources and makes downstream leakage more likely.

    Content

    No source excerpt is available for this finding.

    Obfuscated Code

    High
    Category
    Supply Chain
    Confidence
    50% confidence
    Finding

    Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

    Content

    Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

    python
    # 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
    _LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
    ...[truncated 27 chars]
    

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    92% confidence
    Finding

    The skill explicitly writes reports to the local filesystem (~/zlbx-company-intel-files/) but does not declare any tool scope or allowed-tools restriction. That creates a permissions mismatch: the runtime may grant broader file-write capability than users expect, increasing the risk of unintended file creation or overwrite if the skill is triggered in the wrong context or later modified.

    Content

    No source excerpt is available for this finding.

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The activation rule says the skill must be used whenever a user wants to 'understand a company's real business and strength,' even if they do not mention intelligence explicitly. This is overly broad and can hijack ordinary company-related conversations, causing unnecessary external API calls, data sharing of user queries, local report generation, and possible billing/registration flows without sufficiently specific user intent.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The skill instructs agents to output signed company/announcement URLs verbatim and explicitly forbids modification, but it does not require user consent, minimization, or warn that these URLs may embed authentication or access-granting parameters (sk). If these links are shared into chats, logs, tickets, or downstream tools, they can unintentionally extend access to third parties and expose viewing activity or sensitive procurement data.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    This section operationalizes retrieval and display of project contact phone numbers, including potentially full numbers for paid accounts, while only instructing the agent to preserve the returned format. It lacks safeguards such as purpose limitation, consent/authorization checks, rate limits on person-level data exposure, or a user-facing privacy warning, creating a clear risk of doxxing, unsolicited contact, and misuse of personal data.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The request example and multiple user-facing URLs use ch=s124, and the pseudocode also posts "ch": "s124". But L129 states the ch field must be fixed to "s105". This is not merely incomplete documentation; it gives contradictory instructions about what the code should send.

    Content

    No source excerpt is available for this finding.

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    93% confidence
    Finding

    This section explicitly instructs the agent to serialize collected device features and send them to an external service as part of automatic registration. External transmission of host-derived identifiers is sensitive here because it is not essential to the declared company-intelligence task and can occur in an auth/bootstrap side flow that users may not expect.

    Content

    Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    90% confidence
    Finding

    The curl-based guidance is another concrete instruction path for sending device-derived data to a remote endpoint. Multiple documented transport methods make misuse more likely by encouraging implementation of outbound registration behavior across environments, magnifying privacy and data-handling risk beyond the skill’s stated purpose.

    Content

    Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    > 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
    

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    94% confidence
    Finding

    This duplicate finding points to the same credential-persistence behavior: writing the API key plus metadata to a stable config path and using it automatically in the current session. In the context of a non-auth skill, this is dangerous because it normalizes secret storage and reuse outside the user’s direct awareness, increasing the chance of credential leakage and unauthorized downstream access.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    94% confidence
    Finding

    This duplicate finding points to the same credential-persistence behavior: writing the API key plus metadata to a stable config path and using it automatically in the current session. In the context of a non-auth skill, this is dangerous because it normalizes secret storage and reuse outside the user’s direct awareness, increasing the chance of credential leakage and unauthorized downstream access.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The document instructs the agent to output fixed Chinese text to the user, and similar mandatory Chinese phrasing appears elsewhere in the file. This imposes a specific language on users without indicating that the user can choose their preferred language, which is a natural-language locale policy concern.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    84% confidence
    Finding

    The file is written as a fixed Chinese report template and instructs the report to be output in a specific format, but it does not offer any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless clearly justified as region-specific.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    88% confidence
    Finding

    The template directs the agent to create a local HTML report file by default and then disclose its absolute filesystem path to the user. Writing files and revealing local paths is not necessary to fulfill the core reporting function, and it expands the skill's side effects and information disclosure surface beyond the user's likely expectation.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The skill silently performs an additional export step that writes a local HTML file even when the user only asked for an in-chat report. This violates least surprise and can expose local environment details or persist potentially sensitive report contents without informed user consent.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The workflow is written to operate and report in Chinese by default, with no indication that the agent should respect the user's preferred language or ask for one. This can cause unsafe or ineffective handling when users do not read Chinese, especially for risk, compliance, or contact-disclosure sections where misunderstanding the output could lead to bad decisions or accidental data exposure.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    This Python file’s natural-language docstring and all generated user-facing report text are fixed in Chinese, and the HTML root is later explicitly set to zh-CN. The policy requires flagging language or locale constraints when they are imposed without user opt-in or an offered alternative.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The skill’s stated purpose is to generate enterprise intelligence and strength-profile reports from bidding data. This renderer adds promotional CTAs for ongoing competitor monitoring, deeper multi-company analysis, and more business-opportunity details, which are not necessary to render or present the requested report and extend into adjacent product workflows.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The rendered document sets and emits fixed Chinese UI text throughout the page. Because no language-selection mechanism or documented user opt-in is present, this is a natural-language locale policy violation under the stated rule.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.