Back to skill

Security audit

弱电智能化投标决策-安防监控项目投标评估

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches a bid-analysis assistant, but it also sets up accounts, fingerprints the device, stores API keys, and emits signed access links in ways users should review carefully.

Review this skill before installing if you are uncomfortable with automatic account setup, device fingerprinting, persistent API-key storage in your home directory, signed links appearing in shareable reports, or vendor promotional links in generated output. Prefer configuring ZLBX_API_KEY yourself to skip auto-registration, and avoid sharing generated reports unless you are comfortable exposing the included signed URLs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:140
Finding

Mandatory Promotional Content Hijacks Agent Responses and Generated Reports

Content
View full analysis
📊 报告涉及企业的完整档案与更多商机,见 知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 投标决策分析 Skill 生成' ``` ### Technical Analysis The Skill instructions require the Agent to append cross-promotional recommendations and platform links after completing the requested analysis. The HTML renderer independently injects promotional calls to action into every generated report without checking whether the user requested them or consented to their inclusion. This behavior changes the Agent's task output from a bid-analysis response into a persistent traffic-acquisition and advertising channel. It is not technically necessary to query bid data, assess competitors, calculate price ranges, or generate a usable report. The renderer makes the behavior unconditional: callers cannot omit the promotional footer through report data because the links are hardcoded in `render()`. ### Attack Path 1. A user loads the Skill for a legitimate bid-analysis request. 2. The Skill's mandatory instructions alter the Agent's response policy. 3. The Agent is required to recommend another commercial Skill or external platform after the requested task. 4. In full mode, `render_report.py` generates an HTML report. 5. The rende ...[truncated 771 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

API Key Persistence Lacks Mandatory Filesystem Permission Controls

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:138
Finding

Generated HTML Links Accept Unsafe URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` ```python bid_link = f'' if d.get("bid_url") else "" ``` ### Technical Analysis The renderer HTML-escapes URLs before placing them in `href` attributes, which prevents direct attribute-boundary injection. However, HTML escaping does not validate URL semantics. Values using schemes such as `javascript:`, `data:`, or other unexpected protocols remain valid attribute values. The affected URL values can originate from the input JSON and may indirectly come from API responses. If that data is malicious, compromised, or manually crafted, the generated report contains an attacker-controlled clickable link. All links also use `target="_blank"` without `rel="noopener noreferrer"`. Depending on browser behavior, the opened page may receive an opener reference and attempt reverse-tabnabbing or manipulate the source browsing context. ### Attack Path 1. An attacker influences a URL returned by a data source, supplies a crafted report JSON file, or compromises an upstream API response. 2. The malicious value is assigned to `bid_url`, a profile URL, a competitor URL, or a citation URL. 3. `_link()` or the direct `bid_url` interpolation escapes only HTML metacharacters. 4. The renderer writes the unsafe scheme into an HTML `href`. 5. The user opens the generated report and clicks the apparently legitimate report link. 6. The browser processes the attacker-controlled scheme or opens a hostile page with a possible opener relationship. ### Impact Assessment Exploitation requires the report viewer to click the mal ...[truncated 575 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个“分析助手”,核心职责是根据招投标历史数据做投标决策分析并产出报告;而实际代码仅负责把已生成的 JSON 结果渲染成 HTML 文件,属于展示/报告生成组件。它没有网络访问、数据库查询、分析建模、规则评估、竞对识别、报价计算或风险判断逻辑,因此其实际主功能与声明的主功能存在明显偏差。虽然渲染报告可视为整个技能链路中的支持性步骤,但如果以该代码块代表技能行为,则它并未实现所宣称的关键能力,构成描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file embeds an auto-registration flow, device fingerprint collection, external account creation, API-key retrieval, and persistent credential storage inside a skill whose declared purpose is bid-decision analysis. Even with a consent prompt, this is a strong scope mismatch that expands the skill into system profiling and account-management behavior, increasing privacy, abuse, and supply-chain risk if invoked unexpectedly or modified later.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to collect platform, CPU architecture, and a hashed MAC-derived identifier, which is device fingerprinting unrelated to tender analysis. Hashed hardware identifiers are still stable identifiers and enable device tracking, trial-abuse controls, and unintended correlation across sessions or users, especially when collected by a skill users expect to perform document/market analysis only.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the agent to create directories, merge configuration files, persist API keys under the user's home directory, and immediately reuse the credential in-session. Persistent local credential management is unrelated to the skill's stated analysis function and creates credential exposure and unauthorized state-change risks if the skill is triggered without the user's clear expectation of filesystem writes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires exposing API-returned full URLs including the sk parameter to end users. If sk functions as a bearer-like signed access token, disclosing it can grant unintended access, bypass login controls, enable link sharing beyond the intended recipient, and leak sensitive tracking or authorization data. In this bidding-analysis context, the report is meant for external sharing, which increases the chance of uncontrolled dissemination of signed links.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 71)May include surrounding context.

python
THREAT_COLOR = {"高": "#c0392b", "中": "#b9770e", "低": "#0d9463"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs writing reports to the local filesystem, but it does not declare any tool scope or permissions boundary for file writing. Undeclared write capability increases the chance of unintended or overbroad filesystem access, especially because the skill also mandates generating artifacts automatically after analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation rule is overly broad and effectively forces use of this skill for a wide range of security-project bidding queries, even when the user may not have requested it specifically. Overbroad triggering can cause unnecessary external API use, file generation, or account-registration prompts in contexts where the user expected a narrower or more privacy-preserving response.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs automatic account registration using device-derived identifiers such as platform, architecture, and a MAC-based hash. Even with user consent language, collecting and transmitting device fingerprints is broader than necessary for bid analysis and creates privacy and tracking risk if reused, correlated, or retained improperly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill directs storage of API credentials in a home-directory config file, which expands the persistence of sensitive secrets beyond the immediate session. Local credential persistence can expose API keys to other local processes, backups, or users if file permissions are weak or the path is broadly accessible.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file requires a fixed self-introduction response in Chinese and marks it as mandatory, but does not indicate that the user can choose another language. This is a natural-language policy concern because it forces a locale/language behavior without opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This line documents transmitting collected device features to an external service via JSON POST. External transmission is expected for API-backed products, but in this context the transmitted data is gathered by a bid-analysis skill and includes stable device-identifying material, making the transmission security-relevant because it exports host-derived metadata beyond the skill's stated purpose.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This duplicate finding describes the same persistence behavior: creating ~/.zlbx, merging config, and writing source-tagged API-key data for future automatic use. Persistent auth state is unnecessary for the advertised tender-analysis role and increases the chance of unauthorized reuse, user surprise, and credential leakage across sessions.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This duplicate finding describes the same persistence behavior: creating ~/.zlbx, merging config, and writing source-tagged API-key data for future automatic use. Persistent auth state is unnecessary for the advertised tender-analysis role and increases the chance of unauthorized reuse, user surprise, and credential leakage across sessions.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Generating account-recovery or recharge auto-login links is outside the scope of bid-evaluation assistance and turns the skill into an authentication/payment funnel. This increases phishing-style risk, trains users to trust login links emitted by a skill, and broadens the blast radius if the upstream service or document is compromised.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions prescribe exact Chinese text for the user-facing quota-exhausted message and tell the agent to output it directly. This imposes a specific language on users without any indication of locale choice, opt-in, or region-specific justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The template mandates generating a local HTML report and revealing its absolute filesystem path to the user. Disclosing internal paths leaks environment details such as usernames, directory layout, and storage conventions, which can aid reconnaissance; additionally, directing users to local filesystem locations may unintentionally expose reports containing sensitive business intelligence if the path is reachable or later shared through other tooling. In a multi-tenant or agent-hosted environment, this behavior is more risky because local paths are implementation details that should not be exposed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

标题及整份工作流均以中文固定呈现,且未见任何允许根据用户偏好切换语言或说明仅限特定中文场景的文字。根据规则,未获用户选择或未作明确合理限定的语言强制属于自然语言策略违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated report explicitly sets lang='zh-CN' and uses Chinese-only UI text throughout the output, which enforces a specific language/locale without offering user opt-in or alternative locale selection. Under the policy, locale constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest emphasizes analysis based on web-scale bid history data, while these lines state the skill reads local tender documents yet does not upload their contents. In this file, the operational guidance centers on remote API queries and does not define how local file contents are actually analyzed, creating a mild description/behavior mismatch around file handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language content appears to require Chinese comprehension for use, but the document does not offer an alternative language or indicate that the skill is intentionally limited to a Chinese-language or region-specific audience. Under the language/locale policy, forcing a specific language without user opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file explicitly instructs callers to send requests with an X-API-Key header, which involves handling a sensitive credential. The document provides usage details but does not include any warning about protecting the key, avoiding exposure in logs/shared examples, or limiting its use to authorized contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.