Back to skill

Security audit

建筑工程投标决策-施工项目投标评估

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed construction bid-analysis tool, but it also handles device fingerprinting, credential persistence, signed access links, and account recharge flows in ways users should review carefully before installing.

Install only if you are comfortable with this provider's service model: it may contact zhiliaobiaoxun.com APIs, consume account credits, create or read ~/.zlbx/config.json, collect a hashed MAC-derived device identifier if you accept automatic registration, save HTML reports under your home directory, and show signed/provider links in reports. Prefer supplying your own API key through a trusted secret mechanism, avoid sharing generated reports that contain sk or auto-login links, and review local file permissions for stored credentials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:284
Finding

Mandatory Promotional Content Hijacks Agent and Report Output

Content
View full analysis
\U0001f4ca \u62a5\u544a\u6d89\u53ca\u4f01\u4e1a\u7684\u5b8c\u6574\u6863\u6848\u4e0e\u66f4\u591a\u5546\u673a\uff0c\u89c1 \u77e5\u4e86\u5546\u673a\u5927\u5e08' f' \u00b7 \u672c\u62a5\u544a\u7531 \u77e5\u4e86\u6807\u8baf AI \u5f00\u653e\u5e73\u53f0 \u6295\u6807\u51b3\u7b56\u5206\u6790 Skill \u751f\u6210' ``` Equivalent behavior: the renderer unconditionally adds a call to view complete company profiles and additional opportunities on a publisher-controlled service, together with publisher branding. The associated Skill instructions also require the Agent to: - Include prescribed material when introducing the Skill. - Recommend one of the publisher's related products after completing a report. - Use report links as a traffic-acquisition channel. - Append promotional guidance outside the requested report body. ### Technical Analysis The promotional content is not necessary to retrieve tender data, analyze a project, estimate competition, calculate pricing references, or render an HTML report. Nevertheless, the Skill instructions make such content mandatory, and the renderer inserts it unconditionally. This changes the Agent's output policy for the publisher's commercial benefit. The user cannot obtain a normal HTML report through the documented renderer without receiving the advertising block. Recommendations may consequently appear to be neutral Agent advice even though they are mandated b ...[truncated 1369 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:66
Finding

Persistent Hardware-Derived Identifier Is Collected and Sent During Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The collected value is then placed into the registration request: ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "bid-decision-1.0.5", "ch": "s75" } ``` The documented destination is: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register ``` Equivalent collection procedures are documented for macOS and Windows. ### Technical Analysis A physical network adapter's MAC address is a stable hardware identifier. Applying unsalted SHA-256 makes the identifier pseudonymous, but does not make it anonymous. MAC addresses have a constrained and structured input space, so a hash can be correlated across requests and may be tested against candidate MAC addresses. The Skill requires user consent before running collection commands or sending the registration request. Therefore, this is not covert exfiltration. However, the consent prompt describes the hash as a non-identity device characteristic, which understates its persistence and correlation properties. Physical interface enumeration and hardware-derived fingerprinting are not necessary for the declared tender-analysis functionality. They support the provider's free-trial deduplication rather than the user's analysis task and therefore exceed the core feature's minimum privilege requir ...[truncated 1225 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

Reusable API Key Is Persisted Without Required Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:138
Finding

Generated HTML Accepts Unvalidated URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` The primary tender URL is also embedded directly: ```python bid_link = f'' if d.get("bid_url") else "" ``` The `_link` helper is used for citation, profile, and competitor URLs. The omitted anchor text in the second snippet is presentation-only and does not affect the vulnerable URL handling. ### Technical Analysis XML/HTML escaping protects the quoted attribute from character-based breakout, but it does not validate the URI scheme or destination. Values such as `javascript:`, unsafe `data:` URLs, deceptive external domains, or URLs containing unexpected credentials can remain valid `href` values after escaping. The report-generation instructions require URLs from API responses to be copied unchanged. This extends trust from the local renderer to remote API data without an independent security boundary. The links also use `target="_blank"` without `rel="noopener noreferrer"`. In browser environments where implicit opener isolation is not applied, the opened page may access `window.opener` and navigate the original report tab. ### Attack Path 1. A compromised API response, malformed upstream record, or crafted input JSON supplies a malicious URL. 2. The renderer passes the value through `esc`, which escapes markup characters but does not inspect the URI scheme. 3. The resulting URL is inserted into an anchor in the local HTML report. 4. The user opens the report and clicks the trusted-looking link. 5. The browser processes the dangerous scheme or navigates to an attacker-controlled site. ...[truncated 736 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (24)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation rule is overly broad: it requires use of this skill even when the user does not mention construction, as long as the request resembles engineering-project bidding evaluation. That can cause the agent to route unrelated or ambiguous procurement requests into a skill that performs external data access, account registration prompts, and report generation, violating least surprise and potentially triggering unnecessary data handling or costs.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements a full account lifecycle outside the skill’s stated purpose of construction tender analysis: local API-key discovery, device-feature collection, remote account creation, config persistence, and recharge login generation. This materially expands the skill’s privileges and data handling surface, creating opportunities for unnecessary credential handling and user tracking unrelated to the promised analytical function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to collect stable device identifiers such as platform, architecture, and especially a hashed MAC-derived value, then transmit them for account provisioning. Even with hashing, this is device fingerprinting, and in the context of a tender-analysis assistant it is not necessary for core functionality, making the collection disproportionately risky and privacy-invasive.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to keep sk intact because removing it triggers a login wall strongly suggests the URL embeds a live access credential or private access token. Embedding such tokens in report bodies, JSON, HTML exports, and chat responses can turn the model into a secret-disclosure channel, enabling unauthorized access and broad token reuse through copied links, logs, analytics, or report sharing.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 71)May include surrounding context.

python
THREAT_COLOR = {"高": "#c0392b", "中": "#b9770e", "低": "#0d9463"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill explicitly writes reports to a local directory and references HTML generation scripts, but it does not declare a corresponding tool scope or permission boundary. This creates an authorization gap: an agent may perform file writes without an explicit least-privilege contract, increasing the risk of unintended local file creation or overwrite if the skill is misinvoked or extended unsafely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'fixed output' self-introduction section requires a specific Chinese response format and sample utterances, with no indication that the user's preferred language can be chosen. This creates a language-policy issue because it forces one language without opt-in or a documented regional constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill probes local environment variables and a config file for credentials, then branches behavior based on what it finds. For a tender decision assistant, searching local credential stores and managing local auth state is unrelated to business functionality and increases the risk of unintended secret access, leakage, and persistence beyond user expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document prescribes exact Chinese text to present to users and later requires specific Chinese phrases such as the recharge-link request wording. This imposes a language/locale behavior on all users without documenting a choice, opt-in, or region-specific justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The document instructs the agent to transmit collected device features to an external service for auto-registration. External transmission of locally derived identifiers is security-relevant here because the transmitted data is unrelated to the skill’s stated tender-analysis purpose and is tied to credential issuance.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The skill persists an obtained API key into a user config directory and immediately reuses it for the current session. Persisting credentials from inside an analysis skill is risky because it creates durable auth state and enlarges the consequences of compromise, especially when the skill itself initiated the registration flow.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The skill persists an obtained API key into a user config directory and immediately reuses it for the current session. Persisting credentials from inside an analysis skill is risky because it creates durable auth state and enlarges the consequences of compromise, especially when the skill itself initiated the registration flow.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Generating auto-login recharge links and handling quota exhaustion introduces account-management behavior that is unrelated to tender analysis and can steer users into authentication or billing flows from within a content skill. This broadens the attack surface around session handling and creates phishing-like UX patterns if ever abused or spoofed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction explicitly requires the report to be output in Markdown in Chinese-language phrasing and does not provide any opt-in or alternative locale behavior. This is a natural-language locale policy issue because it forces a specific language regardless of user preference.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires preserving and exposing full signed URLs containing sk parameters and presenting them to users as clickable/shareable links. If sk functions as an access token or login-bypass signature as described, surfacing it in model output and derived reports can leak bearer-style access, enable unintended third-party access, and propagate sensitive tokens into chats, logs, exports, and downstream systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template instructs the agent to generate a temporary JSON file and invoke a local Python script to create an HTML report by default, then disclose the absolute filesystem path to the user. Even without direct shell injection shown here, default code/script execution and file creation increases attack surface, risks data persistence on disk, and may expose local path information or cause unintended handling of sensitive report contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The template says full-mode conversations should automatically generate an HTML file and local output path without a clear warning or explicit consent. Silent creation of persistent local artifacts can surprise users, leak sensitive business analysis into filesystem storage, and create retention/disclosure risks if the environment is shared or monitored.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents the workflow and output requirements entirely in Chinese from the title onward, with no indication that users may choose another language or locale. Per the policy rule, mandating a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script's natural-language interface and generated report content are fixed in Chinese, including usage text, labels, and the HTML lang attribute set to zh-CN. The policy requires avoiding forced language or locale unless the user is offered a choice or the constraint is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file uses Chinese throughout, including all headings and usage instructions, but does not state that the skill is Chinese-only or offer an alternative language option. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code creates an output directory and writes a rendered HTML file to the user's home directory by default. While the operation is part of the script's purpose, the code itself provides no runtime notice, confirmation, or inline warning that it will create files under ~/zlbx-bid-decision-files, which is a user-data-affecting write.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.