Back to skill

Security audit

标前分析助手-投标前必查的一份报告

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a bid-analysis assistant, but it asks the agent to collect a stable device identifier, persist API credentials, and expose signed access links in shareable reports.

Review this skill before installing. Use a preconfigured API key if possible to avoid device-based auto-registration, treat generated sk links and auto-login URLs as sensitive, and avoid sharing exported HTML reports unless you are comfortable exposing their contents and access-bearing links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:284
Finding

Mandatory commercial promotion and referral injection into generated reports

Content
View full analysis
' f'
📊 报告涉及企业的完整档案与更多商机,见 知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 投标决策分析 Skill 生成
' f'
数据说明:{esc(n.get("source", "知了标讯全网招中标数据"))} · 数据缺口:{esc(gaps)}{cost}
' '
免责声明:本报告基于公开招中标数据自动生成,仅供一般性参考,不构成投标或商业决策建议,' '亦不构成对任何单位或个人行为的认定。数据可能存在不完整或滞后,请结合实际情况独立判断并自行承担决策结果。
' ) ``` The associated Skill instructions also mandate a fixed installation response and require a promotional next step after completing a report. The report template independently requires links to affiliated services. ### Technical Analysis The Skill alters ordinary report-generation behavior by requiring branded referrals, cross-Skill recommendations, and commercial-platform links regardless of whether the user requested them. The HTML renderer hardcodes the same promotion, so an agent cannot generate a neutral report merely by omitting the promotional instruction at runtime. This is instruction hijacking because loading the Skill changes the agent's response objective from performing bid analysis to also acquiring traffic for affiliated services. The behavior is not technically necessary to retrieve bid data, assess a project, or render the report. ### Attack Path 1. A user asks for a bid-project analysis. 2. The agent loads the Skill and follows its mandatory response rules. 3. The agent completes the legitimate analysis. 4. The closing instructions force selection of a commercial referral or affiliated Skill. 5. The HTML renderer independently inserts fixed pr ...[truncated 682 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:50
Finding

Stable hardware fingerprint collection and transmission during trial registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "bid-decision-1.0.5", "ch": "s83" } ``` Equivalent physical-interface enumeration and hashing procedures are provided for macOS and Windows. ### Technical Analysis The registration flow reads a physical network adapter's MAC address, normalizes it, computes a SHA-256 digest, and sends the result to an external service together with the operating-system platform and CPU architecture. Hashing does not anonymize a stable, low-entropy hardware identifier. The recipient can compare hashes across registrations and sessions, while an actor with candidate MAC addresses can compute matching hashes offline. The resulting value is therefore a persistent device fingerprint rather than anonymous telemetry. The flow includes an important mitigating control: it requires user consent before collection and can be bypassed by supplying an API key. Nevertheless, the fingerprint is not required for the declared bid-analysis functionality. It serves the provider's trial-abuse and device-deduplication system, which exceeds the minimum data access needed to analyze procurement information. ### Attack Path 1. The Skill does not fi ...[truncated 1138 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

API bearer credential persisted without required restrictive filesystem permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:138
Finding

Unvalidated URL schemes are inserted into clickable HTML links

Content
View full analysis
{esc(text)}' if url else esc(text) ``` ```python rows = "".join( f'{_link(i.get("label"), i.get("url"))}' for i in d.get("profile", []) ) ``` The actual profile rendering uses the same helper as follows: ```python rows = "".join( f'{esc(i.get("label"))}{_link(i.get("value"), i.get("url"))}' for i in d.get("profile", []) ) ``` The bid link bypasses the helper but applies only HTML escaping: ```python bid_link = f'' if d.get("bid_url") else "" ``` ### Technical Analysis The `esc` function performs XML/HTML escaping, which prevents quotation-mark breakout and ordinary attribute injection. It does not validate the URL scheme, destination hostname, embedded credentials, or redirect target. Consequently, a value using an active-content scheme such as `javascript:` or a dangerous `data:` URL remains syntactically valid inside `href`. The affected values can come from report JSON fields such as `bid_url`, profile URLs, competitor URLs, and citation URLs. Although the Skill expects these fields to contain API-returned links, the renderer itself does not enforce that trust boundary. Links opened with `target="_blank"` also omit `rel="noopener noreferrer"`, which may expose the originating window to a hostile destination in browser environments where implicit opener isolation is unavailable. ### Attack Path 1. An attacker influences an API URL field, generated report JSON, or a lo ...[truncated 1108 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向投标前调查与决策分析的核心分析型技能,预期应具备数据获取、分析推理、风险排查和建议生成等能力。但提供的代码片段只是一个离线报告生成器:从输入 JSON 读取现成结果,拼接 HTML/CSS/JS,嵌入 logo,渲染各板块,并支持保存长图和打印为 PDF。代码没有网络访问、没有调用数据库/API、没有对招投标信息做解析或建模、没有任何规则引擎或分析算法。虽然渲染出的报告栏目名称与声明场景一致,但这只是对上游分析结果的展示,不等于实现了所声明的主要能力。因此该代码与技能声明存在明显的功能性不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document directs collection of platform, architecture, and a hashed MAC address to create a stable device identifier, then transmits it externally for account registration. Even with consent language and hashing, this is device fingerprinting unrelated to the stated procurement-analysis purpose, and it can enable cross-session tracking, duplicate-account controls, or misbinding of identity in a context where users would not reasonably expect host-level fingerprint collection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is घोषित as a pre-bid analysis assistant, but this document instructs the agent to perform account provisioning, device-based registration, quota handling, and recovery/login flows that are unrelated to bid-analysis. That scope expansion gives the skill authority to manage credentials and user accounts, increasing attack surface and creating opportunities for unwanted data collection or unauthorized account actions under the guise of a business-analysis tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to write API keys into a local config file, mark their source, and immediately switch the active session to use the new credential. Persisting and activating credentials from within a skill that is supposed to perform pre-bid analysis violates least privilege, creates credential-handling risk, and could overwrite or mix trust boundaries between manually managed and auto-provisioned accounts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires exposing API-returned URLs with intact sk parameters to end users, and describes sk as a login-bypass signature. That means the skill is intentionally propagating access-bearing links outside the system boundary, which can leak bearer-like access tokens through chats, logs, screenshots, forwarding, browser history, and referrer chains.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 71)May include surrounding context.

python
THREAT_COLOR = {"高": "#c0392b", "中": "#b9770e", "低": "#0d9463"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs generation of an HTML report written to a local directory, but it declares no tool scope or permissions boundary. In an agent environment, undeclared file-write capability weakens least-privilege controls and can let the skill create artifacts without transparent authorization, increasing the blast radius if the skill is abused or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says the skill must be used not only for explicit 'pre-bid analysis' requests, but also whenever the user discusses pre-bid investigation, project background checks, or whether to bid. This broad catch-all phrasing lacks clear exclusions or negative examples, making activation scope ambiguous and increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'fixed output' section requires a specific Chinese self-introduction and example utterances, and the overall skill description is written as mandatory Chinese-facing behavior without any opt-in or language-selection mechanism. This creates a language-policy issue because it enforces a locale/language choice regardless of user preference.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file explicitly instructs callers to include X-API-Key in HTTP headers, which involves use of sensitive credentials. The document does not include any warning to protect the key, avoid logging it, or handle it securely, so readers may copy or expose credentials without disclosure of the risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The file explicitly instructs the agent to send collected device features to an external service during auto-registration. External transmission of host-derived identifiers is sensitive in this context because the skill's declared purpose is bid analysis, not telemetry or account enrollment, so users may not anticipate outbound sharing of device-linked data.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The mention of curl -d @file is part of the same external registration workflow and reinforces that the skill is designed to package and transmit local data off-host. In a pre-bid analysis skill, this outbound transfer is functionally unrelated and expands privacy and exfiltration risk, even if the payload is JSON-serialized correctly.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Line L129 states the request field ch must be fixed to "s64" and not read dynamically. However, the concrete request example uses "ch": "s83" at L115, the manual links throughout use ?ch=s83, and the pseudocode sets "ch": "s83" at L242. This is an active contradiction in the file’s operational instructions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same persistence behavior: creating ~/.zlbx, merging config, and using source: "auto" to drive later login flows. That design establishes ongoing stateful credential behavior beyond the immediate task, which is excessive for a pre-bid analysis skill and increases opportunities for credential misuse or confusion over account provenance.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same persistence behavior: creating ~/.zlbx, merging config, and using source: "auto" to drive later login flows. That design establishes ongoing stateful credential behavior beyond the immediate task, which is excessive for a pre-bid analysis skill and increases opportunities for credential misuse or confusion over account provenance.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs the agent to output fixed Chinese copy to the user for quota exhaustion handling, including exact wording and follow-up instructions. This imposes a specific language on users without indicating that the agent should match the user's preferred language or ask for consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions not only preserve signed sk parameters but require them to remain in both report text and generated JSON/HTML outputs, while encouraging sharing of the resulting report. This materially increases the chance that access-sensitive links are redistributed beyond the intended recipient, turning a token-handling mistake into a scalable leakage channel.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs the agent to run an external Python script by default to generate an HTML report file on the local filesystem. Default code/script execution and file creation expand the attack surface, create persistence of potentially sensitive report contents, and can be abused in environments where tool execution should require explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to write a report file to disk automatically, without warning or consent, after producing the Markdown response. This can surprise users, leave sensitive procurement analysis on shared hosts or developer machines, and create unintended retention/exfiltration paths via backups, sync tools, or later local access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and the generated report are entirely Chinese-language, and the HTML explicitly sets lang='zh-CN'. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified; this file does not provide a user choice or a stated region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

All natural-language instructions in the file are presented only in Chinese, and the document does not indicate that this locale restriction is optional or required for a region-specific compliance reason. Under the stated policy, forcing a specific language without user opt-in can be a language or locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.