Back to skill

Security audit

拟建项目跟踪-立项审批阶段就发现

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a coherent Chinese business-opportunity lookup/reporting integration, but it handles device identifiers, API keys, login-bypass links, and local persistence in ways users should review carefully before installing.

Install only if you are comfortable using this vendor service, sending opportunity queries to its APIs, optionally sharing a MAC-derived device hash for trial registration, and storing a reusable API key in ~/.zlbx/config.json. Prefer setting your own ZLBX_API_KEY, review generated links before sharing reports, and treat sk or auto-login URLs as sensitive access links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
references/report-template.md:77
Finding

Mandatory Promotional Content Hijacks Agent Output

Content
View full analysis
' f'
📡 这套扫描条件可固化成「商机晨报」定时跑增量 · 清单涉及单位的完整档案与更多商机,见 ' f'知了商机大师' f' · 本清单由 知了标讯 AI 开放平台 商机雷达 Skill 生成
' ``` ### Technical Analysis The Skill requires fixed subscription messaging and vendor links to be appended to ordinary results. These directives are unrelated to the minimum functionality required to search, rank, and report project opportunities. The behavior exists at both the instruction and implementation layers. Even if an Agent omits the promotional language from its conversational answer, the HTML renderer inserts vendor calls to action directly into the generated artifact. This overrides the Agent's discretion and turns user-requested output into a traffic-redirection channel. The issue exceeds least privilege because generating project intelligence does not require control over unrelated recommendations or mandatory promotion. ### Attack Path 1. A user asks the Agent to search for project opportunities. 2. Loading the Skill introduces mandatory output directives. 3. The Agent performs the legitimate API queries and ranking operations. 4. The report template requires subscription and vendor promotion to b ...[truncated 809 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:98
Finding

Deterministic Hardware Identifier Is Collected and Transmitted to an External Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ### Technical Analysis The automatic-registration workflow reads a physical network adapter's MAC address, normalizes it, computes an unsalted SHA-256 hash, and sends that hash to the vendor along with the operating-system platform and CPU architecture. Although the raw MAC address is not transmitted, a deterministic unsalted hash remains a stable device identifier. Hashing does not make the value anonymous because: - The same MAC address always produces the same hash. - The service can recognize repeat registrations from the same device. - The value can be correlated across requests or datasets that use the same derivation. - MAC address candidate spaces can be constrained by known vendor prefixes and observed hardware inventories. The documentation states that consent must be obtained before collection, which reduces unauthorized collection risk. However, ...[truncated 1576 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Persisted API Key Lacks Mandatory Restrictive File Permissions and Symlink Protection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:143
Finding

Generated HTML Accepts Unvalidated Active URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` The helper is used for URLs originating from report data, including project and citation entries: ```python f'{_link(x.get("name"), x.get("url"))}{esc(x.get("caller", ""))}' ``` ### Technical Analysis The `esc()` function prevents straightforward HTML attribute breakout by escaping XML-sensitive characters. It does not validate URL semantics or constrain the scheme. Consequently, values using schemes such as the following can still become clickable links: ```text javascript:... data:text/html,... file:///... ``` The report JSON can be assembled from API responses, and the Skill explicitly instructs the Agent to preserve returned links exactly. If the upstream service is compromised, returns malformed data, or a crafted JSON file is passed directly to the renderer, the dangerous scheme is retained in the generated `href`. The links also use `target="_blank"` without `rel="noopener noreferrer"`. Modern browsers commonly mitigate opener access by default, but the explicit relationship attribute remains appropriate defense in depth. ### Attack Path 1. An attacker controls or influences a URL in an upstream API response or crafted report JSON. 2. The attacker supplies a URL with an active or otherwise unsafe scheme. 3. The renderer passes the URL through XML escaping only. 4. `_link()` inserts the unchanged scheme into an anchor's `href`. 5. The user opens the generated HTML report. 6. The user clicks the malicious project or citation link. 7. The browser executes or navigates according to the dangerous scheme, subject to browser-specific restrictions. ### Impact Assessment The renderer itself does not automatical ...[truncated 621 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向用户的商机发现/检索型技能,核心能力应是搜索、筛选、跟踪、扫描和排序。实际代码只是一个离线报表生成器,输入是已经准备好的 JSON 结果,输出是带品牌样式、打印/PDF/PNG导出按钮的 HTML 页面。它仅展示数据,不负责发现数据;仅格式化结果,不执行业务分析。虽然报告内容字段与声明场景相关(拟建、采购意向、临期续约等),但这只是结果展示层,不能等同于声明中的核心功能。因此描述与代码实际行为存在明显且实质性的用途不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document adds an auto-registration and account bootstrapping flow to a skill whose declared purpose is project/opportunity tracking, which is a material scope expansion unrelated to the user-facing business function. That mismatch is dangerous because it normalizes credential/account creation behavior in a context where users would not reasonably expect device-derived data collection and backend account provisioning.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to collect device fingerprint components (platform, architecture, MAC-derived hash) and transmit them for account creation, even though those identifiers are not necessary for the stated project-tracking purpose. Even with hashing, MAC-derived values remain stable device identifiers, enabling cross-session tracking and creating privacy/security risk if collected by an agent unexpectedly.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The requirement to preserve and output full URLs with sk login-bypass parameters is a direct secret/token exposure issue. If those parameters function as access grants, any recipient or leaked transcript can reuse them to bypass authentication controls, extending access beyond the intended user and undermining auditability.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 64)May include surrounding context.

python
ROUTE_COLOR = {"拟建": "#7c5cbf", "意向": "#0b7a6a", "临期": "#b9770e"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs writing HTML reports to a local directory, but it declares no tool scope or permission boundary for file-write behavior. That creates an authorization gap: a host agent may allow broader filesystem writes than users expect, increasing the chance of unintended local persistence, data leakage into generated files, or abuse if downstream content is ever attacker-controlled.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says it must be used even when the user does not explicitly mention this domain, which broadens activation beyond clear user intent. Over-broad routing can cause unnecessary external API calls, unwanted spending/telemetry, and disclosure of user queries to the vendor service in contexts where the user did not knowingly request this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'fixed output' self-introduction is fully prescribed in Chinese and marked as mandatory, but the file does not state that the skill is intentionally limited to Chinese-speaking users or provide an opt-in language choice. This can violate language/locale policy by forcing a specific language regardless of user preference.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This line is part of explicit instructions to send collected device features to an external service for automatic account registration. External transmission of host-derived identifiers from within an unrelated skill is risky because it exports persistent metadata off-device and can occur in an agent context where users may not expect network-side account creation.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The curl example reinforces an implementation path for exfiltrating the same collected registration payload to an external endpoint. Although the line itself is only an example, in context it operationalizes outbound transfer of stable device metadata for a purpose unrelated to project tracking.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Persisting API keys to a local config file and generating recharge/auto-login links are account-management behaviors outside the declared project-tracking role. This increases the blast radius of compromise by storing reusable credentials locally and by encouraging the agent to handle monetization/session continuation flows that users may not expect from this skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicate finding points to the same credential-persistence behavior: creating ~/.zlbx, merging config, and marking source metadata to enable future login-link logic. The danger is the same persistent secret handling pattern in a non-auth skill, which broadens exposure and creates durable side effects on the host.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicate finding points to the same credential-persistence behavior: creating ~/.zlbx, merging config, and marking source metadata to enable future login-link logic. The danger is the same persistent secret handling pattern in a non-auth skill, which broadens exposure and creates durable side effects on the host.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs the agent to output a fixed Chinese message to the user, including exact wording and follow-up behavior. This is a language/locale constraint in natural-language instructions, and the file does not indicate that the user may choose another language or that Chinese is region-specific and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file title and formatting instructions require the report to be produced in Chinese and state fixed output requirements, but nowhere offer the user a language or locale choice. This is a natural-language policy concern because it forces a specific language by default without opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template explicitly instructs the agent to disclose raw API-returned URLs containing sk login-bypass parameters and to share a local absolute HTML file path with the user. Exposing bearer-like access parameters can grant unintended access or enable link sharing outside intended controls, while disclosing local filesystem paths reveals internal environment details not needed for normal project-tracking output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template directs the agent to write JSON to a temporary file and execute a local Python script without any user disclosure or consent boundary. In an agent setting, hidden file writes and command execution expand the side-effect surface and can surprise users, especially when combined with user-influenced report content and output paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file presents all user-facing workflow instructions, examples, and output guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not stated here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The request example and multiple surrounding instructions use channel code "s98", but line L129 states the ch field must be fixed to "s86". This is an active contradiction in the documentation that could cause the agent to implement behavior different from what the examples and other instructions indicate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.