Back to skill

Security audit

临期续约商机-合同到期窗口挖掘

Security checks for vulnerabilities and agentic risk

Overview

The skill's main procurement-search function is coherent, but it expands into device fingerprinting, local credential persistence, and shareable reports with signed login links.

Review before installing. Prefer supplying your own ZLBX_API_KEY to avoid automatic registration and MAC-hash collection. Treat generated HTML reports, sk links, recharge links, and ~/.zlbx/config.json as sensitive, and avoid sharing reports unless you have checked that links and business data are safe to disclose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:82
Finding

Mandatory Promotional Content and External-Service Redirection

Content
View full analysis
' f'
📡 这套扫描条件可固化成「商机晨报」定时跑增量 · 清单涉及单位的完整档案与更多商机,见 ' f'知了商机大师' f' · 本清单由 知了标讯 AI 开放平台 商机雷达 Skill 生成
' ``` ### Technical Analysis The Skill does more than define the mechanics of finding expiring contracts and related opportunities. Its instructions require the Agent to add fixed subscription prompts, recommend other commercial Skills, and redirect users to vendor-operated platforms. The report renderer repeats this behavior independently by injecting promotional content into every generated HTML report. This constitutes instruction hijacking because loading the Skill modifies the Agent's output policy beyond what is necessary to satisfy the user's search request. The behavior is not merely descriptive metadata or an optional at ...[truncated 1667 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:56
Finding

Stable Hardware Fingerprint Transmitted During Automatic Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` `references/auto-register.md:98-116` instructs the Agent to transmit the resulting fingerprint to an external registration service: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "opportunity-radar-1.0.3", "ch": "s100" } ``` ### Technical Analysis A SHA-256 hash of a MAC address is still a stable, hardware-derived identifier. Hashing conceals the literal MAC value but does not prevent correlation because MAC addresses have a constrained, structured input space and the same normalized address produces the same hash on every registration attempt. The Skill discloses the behavior and requires consent before collection, which reduces the risk. Nevertheless, physical network-interface enumeration and transmission of a stable device fingerprint are not technically required to perform contract and procurement searches. They support the vendor's trial-account deduplication policy rather than the Skil ...[truncated 1628 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Persisted API Credential Lacks Required Filesystem Protections

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:143
Finding

Generated HTML Links Do Not Restrict URI Schemes or Destinations

Content
View full analysis
{esc(text)}' if url else esc(text) ``` The helper is used for citation links: ```python rows = "".join( f'{_link(x.get("title"), x.get("url"))}' + ('(需登录主站)' if x.get("login_required") else "") + f'{esc(x.get("type", ""))}{esc(x.get("date", ""))}{esc(x.get("use", ""))}' f'' for x in items ) ``` It is also used for report entries: ```python f'{_link(p.get("name"), p.get("url"))} —— {esc(p.get("reason", ""))}' ``` ```python f'{_link(x.get("name"), x.get("url"))}{esc(x.get("caller", ""))}
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description promises a narrowly scoped contract-renewal discovery workflow, but the behavior includes extra report-generation/export capabilities while omitting several advertised decision steps. This mismatch undermines user and policy trust boundaries: operators may authorize the skill for one purpose while it performs different actions, including producing persistent artifacts from potentially sensitive business data.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill says it must be used even when the user did not explicitly ask for this niche function, which is an overly broad invocation trigger. That can hijack unrelated procurement or search requests, causing unnecessary external API calls, quota consumption, and data disclosure to a third-party service without clear user intent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file defines a full auto-registration and credential-management workflow that is unrelated to the stated contract-renewal discovery purpose of the skill. It instructs the agent to collect device fingerprints, create remote accounts, persist API keys locally, and manage recharge/login flows, which materially expands the skill’s authority and data handling surface beyond user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These sections direct the agent to collect device characteristics, including a MAC-derived stable identifier, for trial deduplication. Even though the document frames this as privacy-minimized, it is still device fingerprinting unrelated to finding expiring contracts, and it creates a persistent cross-session identifier that can be transmitted to a third party.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill includes instructions for remote account creation, handling 401/429 registration states, generating device SIDs, and issuing recharge/login links. This is unrelated billing and account lifecycle management embedded inside a business-opportunity skill, increasing the chance of unexpected network actions, silent account creation, and confusing trust boundaries for users.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This instruction combines two risky behaviors: preserving full login-bypass URLs with access-token-like parameters in visible Markdown output and carrying the same raw links into exported HTML files. That creates durable, shareable artifacts containing bearer-style access, making unauthorized reuse, leakage through screenshots/forwards, and downstream indexing or logging significantly more likely.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 64)May include surrounding context.

python
ROUTE_COLOR = {"拟建": "#7c5cbf", "意向": "#0b7a6a", "临期": "#b9770e"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill explicitly instructs writing HTML reports to a local directory, but it does not declare any tool scope such as permissions or allowed-tools. Undeclared file-write capability weakens least-privilege controls and can let the skill create or overwrite files in ways that are not visible to the user or policy layer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'fixed output' section requires a specific self-introduction and example utterances entirely in Chinese, with no indication that users may choose another language. This is a natural-language policy concern because it forces a locale/language behavior without opt-in or stated region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs direct use of an authenticated API using an X-API-Key header and a fixed client identifier, but provides no guidance on secret handling, storage, logging, or least-privilege use. In a skill that may be used by agents and operators, this omission increases the risk that credentials are hardcoded, exposed in prompts, logs, screenshots, or shared documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file states that returned url values contain an sk auto-login or login-bypass parameter and says they can be output directly for clicking, without warning that these links are bearer-style secrets. If such URLs are copied into chats, reports, analytics, browser history, or third-party systems, anyone possessing the link may gain unintended access to protected content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This finding reflects explicit instructions to serialize and send collected device features to an external service endpoint. In context, the transmission is not ancillary to the skill’s declared function; it exports device-derived identifiers and registration metadata to a third party, making the external transmission security-relevant.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The curl-based example provides an alternative mechanism for sending registration payloads off-host, reinforcing that the skill is instructing external exfiltration of device-derived data. The danger comes from the context and payload purpose, not from curl itself: the transmission supports unrelated account creation and fingerprint-based tracking.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicated finding points to the same persistence behavior: creating ~/.zlbx, preserving prior config, recording source metadata, and using the stored key for future behavior. In the context of a contract-renewal skill, that persistence is unnecessary and dangerous because it silently converts a one-time consent event into durable account control.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicated finding points to the same persistence behavior: creating ~/.zlbx, preserving prior config, recording source metadata, and using the stored key for future behavior. In the context of a contract-renewal skill, that persistence is unnecessary and dangerous because it silently converts a one-time consent event into durable account control.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file title and all required output/template text are written in Chinese, and the instructions prescribe fixed Chinese phrasing such as specific section names and guidance text. This imposes a specific language/locale on the skill output without any stated user opt-in or alternative language option, which matches the language-policy violation criterion.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires exposing full API-returned URLs containing the sk login-bypass parameter directly to users. If sk is an access-bearing token, disclosing it in chat output or copied links can leak authenticated access, enable unintended sharing, and bypass normal access controls for anyone who obtains the URL.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire workflow is written as mandatory operating guidance in Chinese and specifies fixed output phrasing and templates in Chinese, but does not provide any user opt-in or alternative language option. Under the policy, imposing a specific language without user choice is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The template directs the skill to generate a shareable HTML report file on disk by default, which increases the persistence and distribution of potentially sensitive business intelligence and embedded links. While file generation alone is not inherently dangerous, doing it automatically and framing it as shareable expands the chance of accidental disclosure, especially if the report includes tokenized URLs or sensitive procurement data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.