Back to skill

Security audit

水滴信用企业尽调-合作前的轻尽调

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised company due-diligence work, but it also creates accounts, fingerprints the device, stores API keys locally, and generates shareable reports with sensitive signed links.

Review before installing. Use a preconfigured ZLBX_API_KEY if possible to avoid automatic registration, treat generated HTML reports and sk-bearing links as sensitive, and be aware that the skill may store an API key under ~/.zlbx/config.json and save reports under ~/zlbx-company-intel-files/.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:474
Finding

Mandatory Promotional Content Hijacks Report Output

Content
View full analysis
' f'
📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成
' f'
数据说明:{esc(n.get("source", "知了标讯全网招中标数据"))} · 数据边界:{boundary} · 数据缺口:{esc(gaps)}{cost}
' '
免责声明:本报告基于公开招中标数据与公开互联网信息自动生成,仅供一般性参考,' '不构成合作、投资或商业决策建议,亦不构成对任何单位或个人行为、资信状况的认定。' '数据可能存在不完整或滞后,请结合实际情况独立判断并自行承担决策结果。
' ) ``` Related mandatory-output instructions also appear in: - `SKILL.md:127-134` - `SKILL.md:151-164` - `references/report-template.md:183-196` ### Technical Analysis The report renderer unconditionally inserts commercial calls to action and links to the operator's other services. This content is independent of the user's request, report findings, or any explicit decision by the user to receive promotional recommendations. The Skill instructions reinforce this behavior by requiring fixed self-introduction content, monitoring promotion, cross-product recommendations, and platform links. This alters the Agent's normal response objectives when the Skill is loaded and gives the Skill control over content that is not necessary to conduct company due diligence. Unlike ordinary attribution, the injected footer encourages additional use of the operator's products and directs users to commercial services. Because the generated report is presented as trusted analytical output, the promotion may appear to be part of the Agent's independent conclusion. ### Attack Path 1. A user requests a company due-diligence report. 2. The Agent load ...[truncated 1047 chars]
Remediation
View remediation

other

Error
Location
references/auto-register.md:53
Finding

Persistent Device Fingerprint Is Collected and Transmitted During Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s115" } ``` ### Technical Analysis When no API key is available, the documented registration workflow identifies a physical network interface, reads its MAC address, normalizes it, computes a SHA-256 hash, and transmits the resulting value with the operating-system type, CPU architecture, Agent type, Agent version, and Skill version. Hashing a MAC address does not make it anonymous. MAC addresses have limited entropy and predictable formatting, and the resulting hash remains a stable pseudonymous device identifier. The server explicitly uses it to recognize repeated registrations from the same device. It can therefore correlate activity across registration attempts and potentially across products sharing the same account system. The behavior is not necessary for the core company due-diligence function. It supports trial-account deduplication, which is an operator-side commercial control rather than a technical requirement for generating a report. The workflow does contain an important mitigating control: it requires explicit user consent before collecting device characteristics and permits users to avoid the process by supplying an API key. However, desc ...[truncated 1696 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/auto-register.md:207
Finding

API Credential Is Persisted Without Enforced Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_report.py:168
Finding

Generated HTML Accepts Unvalidated URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` ```python def _risk_list(risks) -> str: lis = [] for r in risks or []: if isinstance(r, str): text, src = r, "" else: text, src = r.get("text", ""), r.get("source_url", "") src_html = ( f'来源:{esc(src)}' if src else "" ) lis.append(f"
  • {esc(text)}{src_html}
  • ") return f'
      {"".join(lis)}
    ' if lis else "" ``` The same direct `href` construction is used for company, contact, citation, bid, and competitor links elsewhere in the renderer. ### Technical Analysis The `esc()` function performs XML character escaping, which protects against breaking out of the quoted HTML attribute. It does not validate the semantic meaning of the URL. Consequently, an input such as a `javascript:` URI remains a valid clickable `href`. URL values can originate from API responses, web-search citations, or caller-controlled report JSON. A compromised source or crafted input can therefore insert a dangerous scheme without needing to bypass HTML escaping. External links also use `target="_blank"` without `rel="noopener noreferrer"`. In browser environments where the new page receives an opener reference, a hostile destination may manipulate the original report tab through reverse tabnabbing. ### Attack Path 1. A malicious or compromised source supplies a URL with a dangerous scheme, such as `javascript:`. 2. The URL is included in the report JSON as a citation, risk source, company link, bid link, or contact link. 3. The renderer passes the URL through character escaping ...[truncated 1032 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    • Rogue AgentSelf-Modification, Session Persistence
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    Findings (22)

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Context-Inappropriate Capability

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The file instructs the agent to collect device fingerprints (platform, architecture, MAC-derived hash) and automatically create an external account when no API key is present. That behavior is unrelated to a due-diligence/reporting skill’s stated business purpose and introduces undisclosed-to-core-task data collection, identity/provisioning, and external service enrollment risk. Even with a consent prompt and claimed minimization, it expands the skill into device-based tracking and account creation.

    Content

    No source excerpt is available for this finding.

    Obfuscated Code

    High
    Category
    Supply Chain
    Confidence
    50% confidence
    Finding

    Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

    Content

    Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

    python
    # 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
    _LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
    ...[truncated 27 chars]
    

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    93% confidence
    Finding

    The skill explicitly instructs the agent to write HTML reports to a local directory and references a rendering script, but it does not declare any tool/file-write scope restrictions. Undeclared write capability weakens least-privilege guarantees: if this skill is triggered unexpectedly or combined with prompt injection elsewhere, it could cause unreviewed file creation on the host filesystem.

    Content

    No source excerpt is available for this finding.

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The activation criteria are intentionally broad: any request about whether a company is '靠谱' or has '真实业务' should invoke this skill, even if the user does not mention due diligence. Overbroad routing increases the chance the skill activates on general business questions, leading to unnecessary external data access, possible auto-registration flows, local report generation, and billing-impacting actions without sufficiently specific user intent.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    81% confidence
    Finding

    This markdown file is entirely written as a Chinese-only quick reference, and the title at L01 frames it as the operative tool guide. Under the stated policy, forcing a specific language or locale without offering user choice or documenting a justified region-specific constraint is a natural-language policy violation.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    Medium
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The file's own guidance is internally inconsistent: one section shows "ch": "s115" in the request body, while a later note says the field must be fixed to "s105". Because comments/instructions directly disagree about what the code should send, this is intent-code divergence within the skill documentation.

    Content

    No source excerpt is available for this finding.

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    89% confidence
    Finding

    The document explicitly directs the agent to POST collected device features to an external domain during auto-registration. External transmission of host-derived identifiers is sensitive in this context because the skill is presented as a company due-diligence tool, not as an onboarding/account-provisioning tool; this makes the exfiltration of local environment data more dangerous and harder for users to expect.

    Content

    Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    60% confidence
    Finding

    Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

    Content

    Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    > 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
    

    Description-Behavior Mismatch

    Medium
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    Line L129 states the ch field must be fixed to "s105", while the concrete request example at L115 and the pseudocode at L242 use "s115". This is an active contradiction in behavior guidance that can cause the agent to send a different channel code than the documentation claims is required.

    Content

    No source excerpt is available for this finding.

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    91% confidence
    Finding

    The instructions tell the agent to persist a newly obtained API key under ~/.zlbx/config.json, merge it into existing config, and immediately reuse it for subsequent calls. Persisting authentication material and altering local session state is a meaningful capability escalation for a due-diligence skill, especially when tied to auto-created external accounts; it creates durable side effects on the user’s machine and may affect future sessions without a dedicated setup workflow.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    91% confidence
    Finding

    The instructions tell the agent to persist a newly obtained API key under ~/.zlbx/config.json, merge it into existing config, and immediately reuse it for subsequent calls. Persisting authentication material and altering local session state is a meaningful capability escalation for a due-diligence skill, especially when tied to auto-created external accounts; it creates durable side effects on the user’s machine and may affect future sessions without a dedicated setup workflow.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The quota exhaustion flow generates auto-login recharge links and guides users through binding a phone number and topping up balances. This is account-management and billing functionality, not due-diligence analysis, and it broadens the blast radius of the skill into authentication and monetization flows that can influence user actions outside the claimed scope.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The template explicitly requires company and announcement URLs to be shown with the raw sk parameter intact and frames them as shareable login-bypass links. If sk is an access token, session surrogate, or bearer-like grant, disclosing it to end users and embedding it in generated reports can leak authenticated access, enable unauthorized reuse, and cause downstream propagation through chat logs, exports, browser history, and third-party sharing.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    The default behavior silently writes a JSON intermediate file and produces an HTML report without any user-facing notice about local file creation, persistence, or possible retention of sensitive diligence results. In a business-intelligence context, these reports may contain nonpublic analysis, contact details, and external links, so undisclosed artifact creation increases privacy, compliance, and data-governance risk.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    90% confidence
    Finding

    The document title and all operational instructions are written as a Chinese-only execution manual, with no indication that users may choose another language or locale. This can violate a language/locale policy when a skill effectively forces one language without user opt-in.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The workflow includes a contact-lookup step that retrieves project contacts and phone numbers, and explicitly frames it as a conversion/upsell hook rather than a strictly necessary due-diligence function. In a due-diligence skill, exposing or monetizing contact discovery broadens the skill into lead generation and outreach enablement, increasing privacy, purpose-limitation, and misuse risk beyond the stated enterprise background-check scope.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    Natural-language strings throughout the module, including the docstring, rendered HTML labels, and metadata, are fixed in Simplified Chinese, and the HTML tag is explicitly set to zh-CN. There is no opt-in, language selection, or documentation that this skill is intentionally limited to a Chinese-only regional/compliance context.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Low
    Category
    Not specified by scanner
    Confidence
    88% confidence
    Finding

    The template instructs the skill to generate a local HTML artifact by default and disclose its absolute filesystem path to the user. While not usually a direct compromise by itself, revealing host paths exposes internal environment details and couples the skill to local artifact persistence that may unintentionally retain sensitive company due-diligence data on disk.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    Low
    Category
    Not specified by scanner
    Confidence
    88% confidence
    Finding

    The documentation says contact lookup is 'not a selling point' while simultaneously calling it a 'conversion hook,' which is a policy-signaling inconsistency. That contradiction suggests the feature is being positioned to drive upsell or lead capture despite the stated due-diligence purpose, weakening trust boundaries and making downstream misuse more likely.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Low
    Category
    Not specified by scanner
    Confidence
    78% confidence
    Finding

    This code writes a self-contained HTML file containing company intelligence data, contact details, and links described in the docstring as potentially carrying direct-access tokens ("带 sk"). Although file output is the skill's main purpose, there is no runtime notice, comment near the write path, or other user disclosure reminding users that the saved file may contain sensitive content suitable for forwarding or offline sharing.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.