Back to skill

Security audit

建筑工程商机雷达-基建项目早期发现

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised construction lead search, but it needs Review because it can create accounts, fingerprint the device, store API credentials, write reports, and expose signed access links.

Review this before installing. Prefer providing your own ZLBX_API_KEY to avoid automatic registration, check permissions on ~/.zlbx/config.json if a key is stored, and avoid forwarding generated reports or chat output that contains sk or auto-login links. Expect queries, device-registration data if you consent, and generated report files to interact with Zhiliaobiaoxun services.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:303
Finding

Mandatory Commercial Content Hijacks Agent Responses and Generated Reports

Content
View full analysis
' f'
📡 这套扫描条件可固化成「商机晨报」定时跑增量 · 清单涉及单位的完整档案与更多商机,见 ' f'知了商机大师' f' · 本清单由 知了标讯 AI 开放平台 商机雷达 Skill 生成
' ``` Related mandatory instructions also appear in: - `SKILL.md:69-83` - `SKILL.md:108-114` - `SKILL.md:155` - `references/report-template.md:77-81` ### Technical Analysis The Skill requires normal search responses and generated reports to include branded promotional messaging, subscription conversion text, and links to related commercial services. This content is not necessary to perform the declared project-opportunity search and report-generation functionality. The behavior is persistent rather than contextual: the report template requires a subscription prompt, the installation introduction is fixed, and the HTML generator unconditionally adds commercial links. This alters the Agent's output goals from answering the user's request to promoting the Skill provider's services. Because these requirements are embedded in the Skill instructions and renderer, users may interpret the resulting recommendations as neutral Agent advice rather than provider-controlled advertising. ### Attack Path 1. A user loads the Skill and requests a normal project-opportunity search. 2. The Agent follows the Skill's mandatory reporting workflow. 3. The Skill instructions require subscription and platform promotion to be appended. 4. The HTML renderer independently inserts links to the provider's commercial services. 5. The user receives provider-controlled promotional content even when it was not requested or required. ### Impact Assessment The issue does ...[truncated 472 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:98
Finding

Stable MAC-Derived Device Fingerprint Is Transmitted for Trial Registration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Plaintext API Key Persistence Lacks Mandatory File-Permission and Symlink Protections

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:143
Finding

Unvalidated API-Controlled URL Schemes Are Rendered as Active HTML Links

Content
View full analysis
{esc(text)}' if url else esc(text) ``` The function is used for API-derived URLs in project entries and citations. The Skill additionally mandates preserving API-returned URLs without modification in `SKILL.md:73` and `references/report-template.md:57`. ### Technical Analysis The renderer HTML-escapes the URL, which prevents quotation-mark injection and attribute breakout. However, escaping does not validate the URL scheme or destination. If an upstream API response is compromised, malformed, or contains attacker-controlled data, values using schemes such as `javascript:`, `data:`, or other unsafe protocols can be inserted directly into an `href`. The requirement to reproduce returned URLs unchanged discourages the renderer from applying appropriate scheme and hostname validation. The links also use `target="_blank"` without explicitly adding `rel="noopener noreferrer"`. Modern browsers frequently mitigate opener access automatically, but relying on browser defaults is weaker than declaring the isolation policy. ### Attack Path 1. A malicious upstream record or compromised API response supplies an unsafe URL in a project or citation item. 2. The Agent copies the returned URL into the report JSON as required. 3. `_link` escapes special characters but performs no URL parsing or allowlist validation. 4. The renderer writes the value into an active HTML `href`. 5. The user opens the generated local HTML report and clicks the entry. 6. The browser processes the attacker-selected scheme or navigates to an attacker-controlled destination. ### Impact Assessment The renderer itself does not automatically execute the link; user interaction is required. The resulting privileges depend on ...[truncated 447 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (20)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger condition is intentionally broad: it says the skill must be used even when the user does not mention construction, as long as the request vaguely relates to project leads, infrastructure opportunities, or early discovery. Overbroad routing can cause the agent to invoke this skill for unrelated business-intelligence requests, leading to unnecessary external API calls, possible account consumption, and disclosure of user queries to a third-party service without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document defines an auto-registration, credential persistence, and recharge workflow that goes well beyond the skill’s stated purpose of discovering construction project opportunities. Even if framed as convenience, it authorizes account creation, local credential storage, and billing-related flows inside a domain skill, expanding the skill’s privilege and data-handling surface in ways users would not reasonably expect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to collect device fingerprinting inputs (platform, CPU architecture, MAC-derived hash) and transmit them to an external service to create or recover trial-linked accounts. That behavior is not justified by a construction-opportunity search use case, and it materially increases privacy and tracking risk by binding device characteristics to service access.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires exposing full API-returned URLs containing sk login-bypass parameters to end users. If those parameters function as bearer-style access tokens, copying them into reports can leak authenticated access through chat transcripts, forwarded documents, browser history, logs, or downstream HTML exports.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 64)May include surrounding context.

python
ROUTE_COLOR = {"拟建": "#7c5cbf", "意向": "#0b7a6a", "临期": "#b9770e"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly performs local file writes by generating and saving HTML reports, but it does not declare any tool scope, permissions, or allowed-tools restrictions. That mismatch can let an agent use broader file-writing capability than reviewers or runtime policy expect, increasing the risk of unintended file creation or overwrite if the skill is invoked in the wrong context or manipulated by adversarial prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

文件整体以中文编写本身不是问题,但 L003 中“给一个工程领域/地区即输出按价值排序的商机清单”配合“必须使用此SKILL”的强制性描述,未给用户提供语言/locale 选择。对于通用技能,这会构成默认强制特定语言输出的自然语言政策风险。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions direct the agent to inspect an environment variable and a local config file for API keys, which introduces credential discovery behavior unrelated to the narrow end-user function advertised by the skill. While common in tooling, embedding this in a content-focused skill increases the chance of overbroad secret access and unexpected credential handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example request body shows "ch": "s102" and multiple surrounding instructions direct users to URLs with ch=s102, but line L129 states the ch field must be fixed to "s86". This is an active contradiction in the documentation that could cause the implementation to send a different channel value than intended.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This section explicitly instructs the agent to send collected device features to an external endpoint as JSON. External transmission is risky here because the transmitted data supports device fingerprinting and account creation, and the network call is embedded in a skill whose declared purpose does not require such data exfiltration.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The alternative curl -d @file guidance likewise operationalizes sending locally assembled payloads to an external service. In context, the danger is not the serialization advice itself but that the skill is directing outbound transfer of device-derived identifiers to support functions outside its stated domain.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This finding duplicates the same persistence behavior: creating ~/.zlbx, merging config, writing source: "auto", and continuing with the persisted key. The risk remains that the skill is establishing durable authentication state and follow-on account workflows beyond its declared purpose, which broadens the local attack surface and user surprise.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This finding duplicates the same persistence behavior: creating ~/.zlbx, merging config, writing source: "auto", and continuing with the persisted key. The risk remains that the skill is establishing durable authentication state and follow-on account workflows beyond its declared purpose, which broadens the local attack surface and user surprise.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document prescribes exact Chinese text for user communication, including the quota-exhausted message and follow-up trigger phrase, with no indication that the agent should match the user's preferred language or ask for consent. This creates a natural-language policy concern because it imposes a specific language on all users rather than offering a locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is written as a strict output template in Chinese and explicitly constrains how the response must be produced, but it does not provide any user opt-in or alternative language option. This can violate language/locale policy when the skill is used with users who have not chosen Chinese output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template instructs the agent to write a temporary JSON file and execute a local Python script by default, but gives no user-facing warning or consent step. Any skill that silently performs file writes and subprocess execution increases the attack surface, especially if report content or filenames are influenced by external data and the user is not clearly informed that local side effects will occur.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Requiring the agent to disclose the full absolute filesystem path of the generated HTML report reveals local environment details such as usernames, home directory structure, or storage conventions. While not always critical by itself, this information disclosure can aid reconnaissance and can expose sensitive workspace details in shared chats or logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire workflow is written as an instruction set in Chinese and includes fixed Chinese output phrases and templates such as the report wording and subscription messages. There is no indication that the user may choose another language or locale, so the skill appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.