Back to skill

Security audit

医疗设备商机雷达-医院采购早期发现

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it needs review because it collects a stable device fingerprint, stores an API key locally, exposes login-bypass links, and generates HTML reports with an injection risk.

Install only if you are comfortable with the vendor receiving a MAC-derived device hash for trial registration, storing an API key under your home directory, and generating reports that preserve login-bypass links. Prefer providing your own ZLBX_API_KEY, avoid sharing generated HTML or sk links broadly, and treat reports from untrusted data as potentially unsafe until the HTML escaping issue is fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
references/report-template.md:78
Finding

Mandatory promotional content hijacks Agent responses and generated reports

Content
View full analysis
' f'
📡 这套扫描条件可固化成「商机晨报」定时跑增量 · 清单涉及单位的完整档案与更多商机,见 ' f'知了商机大师' f' · 本清单由 知了标讯 AI 开放平台 商机雷达 Skill 生成
' f'
数据说明:{esc(n.get("source", "知了标讯全网拟建/招中标数据"))} · 数据缺口:{esc(gaps)}{cost}
' ``` ### Technical Analysis The Skill requires fixed subscription prompts, cross-Skill referrals, and external-platform links to be appended to otherwise functional responses. The HTML renderer independently hard-codes the same promotional links into every generated report. These directives alter the Agent's expected output beyond the minimum necessary to search, rank, and report procurement opportunities. Because the promotional behavior is mandatory rather than conditional on an explicit user request, loading and following the Skill changes the Agent's current-session response goals. The behavior affects both conversational responses and persistent report artifacts. It is therefore classified as Skill Instruction Hijacking rather than a purely cosmetic reporting issue. ### Attack Path 1. A user invokes the Skill for procurement-opportunity research. 2. The Agent loads the Skill instructions and performs the requested API searches. 3. The Ag ...[truncated 882 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:33
Finding

Stable hardware fingerprint is collected and transmitted for trial registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` `references/auto-register.md:98-116`: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "opportunity-radar-1.0.3", "ch": "s103" } ``` ### Technical Analysis The registration workflow enumerates a physical network interface, reads its MAC address, normalizes it, computes a SHA-256 hash, and transmits the resulting value to an external registration service. It also sends operating-system, architecture, Agent, and Skill metadata. Hashing a MAC address does not make it anonymous. A MAC address is a structured, stable hardware identifier with limited entropy, and its hash remains suitable for cross-session correlation. The resulting value is therefore a persistent pseudonymous device fingerprint. The Skill does require consent before collecting or transmitting these features, which limits covert collection. However, the hardware fingerprint is not necessary for the declared core function of searching and ranking procurement opportunities. Describing it as having no identity significance understates its tracking properties. ### Attack Path 1. The Agent checks for `ZLBX_API_KEY` and `~/.zlbx/config.json`. 2. No existing API key is found. 3. The user accepts the trial-registration p ...[truncated 1021 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

API key is persisted without restrictive filesystem permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_report.py:80
Finding

Insufficient HTML attribute escaping permits injection through report URLs

Content
View full analysis
str: return _esc(str(s if s is not None else "")) def _link(text, url): return f'{esc(text)}' if url else esc(text) ``` Representative use at `scripts/render_report.py:223-224`: ```python f'{_stars(x.get("stars"))}' f'{_link(x.get("name"), x.get("url"))}{esc(x.get("caller", ""))}' ``` ### Technical Analysis `xml.sax.saxutils.escape()` escapes `&`, `<`, and `>` by default, but it does not escape double or single quotation marks unless an explicit entity mapping is supplied. The renderer inserts the escaped URL inside a double-quoted `href` attribute. An attacker-controlled URL containing a double quote can therefore terminate the `href` value and inject another HTML attribute, including an event handler. For example, a malicious value conceptually shaped like the following could escape the intended attribute context: ```text https://example.invalid/" onmouseover="maliciousBehavior() ``` The Skill requires URLs returned by the API to be copied into reports without modification. Consequently, a malicious or compromised upstream API response can reach this vulnerable HTML-generation sink. The absence of URL-scheme validation also allows non-HTTPS schemes to be inserted. Although browser behavior varies, accepting unvalidated schemes unnecessarily expands the attack surface. ### Attack Path 1. An upstream data source, compromised API, or malicious record supplies a crafted `url` field containing a quotation mark and injected attribute content. 2. The Agent copies the returned URL into report JSON as required by the Skill. 3. `_link()` calls `esc(ur ...[truncated 1004 chars]
Remediation
View remediation
str: return escape(str(value if value is not None else ""), quote=False) def esc_attr(value) -> str: return escape(str(value if value is not None else ""), quote=True) ``` 2. Apply `esc_attr()` to every value inserted into an HTML attribute. 3. Apply `esc_text()` only to text-node content. 4. Parse and validate report URLs before rendering them. 5. Allow only `https` URLs and reject schemes such as `javascript`, `data`, and `file`. 6. Consider restricting hosts to the expected Zhiliaobiaoxun domains if API links are contractually limited to those domains. 7. Add `rel="noopener noreferrer"` to links opened with `target="_blank"`. 8. Prefer a maintained templating engine with contextual autoescaping rather than assembling HTML with f-strings. 9. Add regression tests containing: - Double and single quotation marks. - Event-handler fragments. - `javascript:` URLs. - Encoded control characters. - Malformed and protocol-relative URLs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (21)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger condition is overly broad: it mandates use of this skill even when the user does not mention 'medical,' as long as the conversation touches hospital procurement clues or sales opportunities. Overbroad routing can cause unintended external data queries, unnecessary spending of API credits, and disclosure of user query intent to a third-party service in situations where the user did not clearly request this specialized workflow.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file defines an auto-registration subsystem that collects device characteristics, provisions remote accounts, and stores API credentials on disk, which is materially outside the stated purpose of a medical sales/opportunity radar skill. This expands the skill's trust boundary to local environment inspection, external account creation, and persistent authentication, creating privacy, consent, and secret-handling risk even if presented as a convenience feature.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions direct the agent to inspect environment variables, read local config files, and run OS-specific commands to derive a device fingerprint from platform, architecture, and MAC-derived data. For a healthcare procurement intelligence skill, this collection is unrelated to core functionality and turns the skill into a local host reconnaissance and tracking mechanism, with external transmission of the derived fingerprint.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The template explicitly requires preserving and exposing full URLs containing sk access parameters to end users in both Markdown and JSON/HTML outputs. If sk is an access-bearing token, disclosing it leaks credentials or bearer-style access that can be reused, forwarded, or indexed, potentially granting unauthorized access outside the intended session.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow explicitly instructs the skill to output links containing embedded sk parameters that bypass normal login requirements. Exposing authenticated or bearer-style access tokens in generated output can enable unauthorized access, replay, link sharing, leakage through logs/referrers, and downstream compromise of procurement-related data. In this business-intelligence context, that creates real confidentiality and account-bound access risks rather than being a harmless convenience.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 64)May include surrounding context.

python
ROUTE_COLOR = {"拟建": "#7c5cbf", "意向": "#0b7a6a", "临期": "#b9770e"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to write HTML reports to a local directory, but it does not declare any tool scope such as permissions or allowed-tools. That creates a capability mismatch: an agent may perform filesystem writes without transparent consent boundaries, increasing the risk of unintended file creation or overwrite if the skill is invoked in broader contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

“固定输出,缺一不可”并要求回复必须包含特定中文定位语和三条中文示例话术,等于把输出语言固定为中文。文件中未说明可根据用户语言偏好切换,也未给出用户可选择语言的机制。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly instructs users to output url values that contain an sk login-bypass parameter and says they can be clicked directly. That exposes authenticated or access-bypassing links as normal output, which can enable unauthorized sharing, bypass intended access controls, and leak procurement data to unintended recipients if links are forwarded or logged.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The sample request body shows "ch": "s103", while line 129 states the field must be fixed to "s86", and later pseudocode again uses "s103". This is an active contradiction in the file's own intent/documentation that could cause the agent to implement behavior inconsistent with the stated instructions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This section explicitly instructs sending collected device features and agent metadata to an external service via JSON POST. Although the transport itself may be intended, it is still a security-relevant external exfiltration path because the transmitted data originates from local system inspection and is not required by the skill's declared medical-opportunity function.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The curl -d @file guidance is another explicit mechanism for posting serialized registration payloads to a remote endpoint. In context, it reinforces a non-core data exfiltration channel from the local machine to an external service, which is risky because it operationalizes host-derived data collection within a business-intelligence skill.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This duplicate finding points to the same persistence behavior: creating ~/.zlbx and merging an api_key plus source metadata into a local config for future authentication decisions. That creates durable session state and secret retention beyond the user request, which is risky and outside the minimal scope expected of a medical opportunity discovery skill.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This duplicate finding points to the same persistence behavior: creating ~/.zlbx and merging an api_key plus source metadata into a local config for future authentication decisions. That creates durable session state and secret retention beyond the user request, which is risky and outside the minimal scope expected of a medical opportunity discovery skill.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes unrelated logic for account recovery handling, auto-login SID generation, and recharge-link flows, which are not necessary for identifying medical equipment opportunities. Bundling these capabilities into the skill broadens its authority and creates additional paths for authentication abuse, phishing-like link delivery, or user confusion about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template directs the agent to write JSON to a temporary file and execute a local Python script to generate an HTML report on disk, which expands behavior from data summarization into local file creation and code execution. Even if the script is internal, this creates an unnecessary execution and filesystem side effect path that can be abused or fail unsafely when report content is attacker-influenced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file presents all operational guidance, examples, and output instructions only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated HTML hard-codes lang='zh-CN' and the script’s output strings are entirely Chinese, which imposes a specific language/locale on all users. The file does not offer a language option or explain that the skill is restricted to a China-specific or Chinese-only context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document states that expiring-project results include contact fields but only references being 'restrained' in output, without a concrete rule to suppress, minimize, or protect personal/contact information. In a sales-opportunity workflow, this creates a real risk of unnecessary disclosure of PII or direct contact data to users, downstream systems, or conversation logs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.