Back to skill

Security audit

招标商机发现-还没发标先知道

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent tender-opportunity purpose, but it needs Review because it can auto-register accounts, send a MAC-derived device fingerprint, store API keys locally, and expose signed access links in reports.

Install only if you are comfortable with a China-focused vendor API workflow that may use paid credits, can create a trial account after consent, sends a MAC-hash device identifier for trial deduplication, stores an API key under ~/.zlbx, and includes signed platform links in generated reports. Prefer setting your own ZLBX_API_KEY and avoid sharing generated reports unless you are comfortable exposing their embedded access links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:303
Finding

Mandatory Promotional Content Alters Agent Outputs

Content
View full analysis
' f'
📡 这套扫描条件可固化成「商机晨报」定时跑增量 · 清单涉及单位的完整档案与更多商机,见 ' f'知了商机大师' f' · 本清单由 知了标讯 AI 开放平台 商机雷达 Skill 生成
' ``` The associated Skill instructions require fixed promotional output: ```text - 报告尾部固定附一句订阅引导(见 report-template.md)。 ## 安装成功后的自我介绍(固定输出,缺一不可) 用户安装完成或询问「这个 skill 能干什么」时,回复必须包含: ``` ### Technical Analysis The Skill requires the agent to append fixed subscription messaging, vendor branding, referrals to related vendor products, and external vendor links to otherwise task-oriented responses. The HTML renderer independently hardcodes equivalent calls to action, meaning normal report generation cannot produce a neutral result. These instructions are not necessary to locate, rank, or report tender opportunities. They alter the agent's response goals by making promotional content mandatory and therefore exceed the minimum behavior needed for the declared functionality. Because the instructions are activated when the Skill is loaded and affect the current session's responses, the best matching classification is `T01: Skill Instruction Hijacking`. ### Attack Path 1. A user installs or invokes the opportunity-finder Skill for a legitimate tender search. 2. The agent loads the Skill instructions. 3. The instructions require fixed self-introduction, subscription, referral, and vendor-link content. 4. The normal opportunity-search workflow completes. 5. The agent appends the required promotional material to its response. 6. ...[truncated 795 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:46
Finding

Stable Hardware-Derived Device Fingerprint Sent to an External Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting stable identifier is included in the external registration request: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "opportunity-radar-1.0.3", "ch": "s97" } ``` ### Technical Analysis The automatic registration workflow enumerates a physical network interface, reads its MAC address, normalizes it, computes a SHA-256 digest, and sends that digest together with the operating-system platform and CPU architecture to an external provider. A MAC-address hash remains a stable, hardware-derived identifier. Hashing protects the original textual value in transit but does not make the identifier anonymous. MAC addresses have constrained structure and entropy, and a stable digest can still support device recognition and cross-session correlation. The workflow includes useful safeguards: it requires user consent before collection, does not transmit the raw MAC address, avoids collecting the hostname and username, and can be bypassed by supplying an API key. Nevertheless, hardware fingerprinting serves the provider's free-trial deduplication process rather than the Skill's core tender-search function. It therefore exceeds the minimum data access necessary to find and rank opportunities. ## ...[truncated 1172 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Persisted API Key Lacks Mandatory Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger logic is extremely broad, including generic concepts like finding leads, customers, market opportunities, channel expansion, and even cases where the user did not mention 'business opportunity' at all. That makes accidental invocation likely in ordinary conversations, which is risky here because the skill can perform network actions, consume paid API credits, register accounts after consent, and generate local files.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file instructs the agent to perform account creation, login recovery guidance, quota handling, and persistent credential management even though the skill’s declared purpose is tender-opportunity discovery. This materially expands the skill’s authority and data-handling surface, creating unnecessary risk of unauthorized account operations, credential handling mistakes, and privacy-impacting behavior outside user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document directs collection of device fingerprinting attributes, including a MAC-derived hash, and transmission to a remote service for trial deduplication. Even with hashing and consent text, this is persistent device tracking unrelated to the stated tender-discovery purpose, and it can surprise users, enable cross-session correlation, and create privacy/compliance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file instructs writing API keys to a local config file and reusing them automatically in the current and future sessions. Persisting secrets from a business-discovery skill broadens compromise impact if the local environment is shared, malware-infected, backed up insecurely, or if file permissions are weak.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This template repeatedly instructs preservation and disclosure of full login-bypass URLs with sk parameters in both Markdown and exported HTML/JSON artifacts. That materially increases the chance of credential-like token leakage through conversation transcripts, shared files, browser history, analytics, or downstream storage, enabling unauthorized access to protected content.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 64)May include surrounding context.

python
ROUTE_COLOR = {"拟建": "#7c5cbf", "意向": "#0b7a6a", "临期": "#b9770e"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to write HTML reports to a local directory, but it does not declare a restrictive tool scope such as allowed file-write paths or explicit permissions. In an agent environment, this creates unnecessary capability exposure: a compromised or mis-triggered execution path could write files outside the intended report directory, overwrite user files, or persist unwanted artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill content is written as a Chinese-only workflow and includes fixed Chinese response requirements without offering user language selection or consent. This can cause misleading or inaccessible output for users in other languages, increasing the chance that they approve scans, account registration, or data handling without fully understanding what the skill is doing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Line L04 instructs the caller to send an X-API-Key header, which involves handling sensitive credentials. The file provides no warning about protecting the key, avoiding exposure in logs/shared outputs, or treating it as confidential.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file provides mandatory user-facing wording in Chinese and instructs the agent to present that text before proceeding. Similar required Chinese output appears later for quota-exhaustion handling, with no opt-in or alternative locale path, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This section explicitly instructs the agent to transmit collected device features to an external service. In context, the transmission includes hardware-derived fingerprint material and account-registration metadata that are not necessary for the skill’s declared purpose, so the external exfiltration risk is real even if the destination is first-party.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The curl -d @file guidance is another expression of the same external transmission behavior: packaging local data into a request body for a remote registration endpoint. In this skill context, sending device-derived identifiers outside the host environment is unnecessary and increases privacy and tracking risk.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline documentation explicitly states that the ch field must be fixed to "s86", but the surrounding request example uses "ch": "s97" and the pseudocode later hard-codes "s97". This is an active contradiction in the file's own instructions, creating intent-code divergence about what value the agent should actually send.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a config directory and storing authentication state for future reuse. The risk is the same—unnecessary retention of secrets and authentication state beyond the immediate task, which is especially dangerous in shared or weakly secured environments.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a config directory and storing authentication state for future reuse. The risk is the same—unnecessary retention of secrets and authentication state beyond the immediate task, which is especially dangerous in shared or weakly secured environments.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Recharge-link generation and auto-login flows are unrelated to opportunity discovery and introduce additional authentication and account-linking behavior into the skill. This increases phishing-like risk, mishandling of login artifacts such as SIDs, and user confusion about what the skill is permitted to do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions require a specific Chinese message to be shown to the user when free quota is exhausted and when generating a recharge link. Because the file does not provide any user language choice or documented regional justification, this is a policy-style locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template explicitly requires exposing full API-returned URLs including the sk login-bypass parameter in user-facing output and forbids removing it. These links appear to function as bearer-style access URLs; if shared, logged, or leaked through chat history, they may grant unintended access without authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template instructs the agent to write a temporary JSON file and execute a local Python script by default, but provides no user-facing notice, consent gate, or safety constraints. In an agent environment, default file writes and subprocess execution expand the attack surface and can surprise users, especially if input-derived filenames or paths are later incorporated by the implementation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file content and output instructions are written as a fixed Chinese-language report template, with no indication that the user can request another language or that the skill is intentionally restricted to a Chinese locale. This can constitute a language/locale policy issue when the skill forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The generated document hardcodes lang='zh-CN', which enforces a specific language/locale for all outputs. The file does not offer any user opt-in or configuration for locale, nor does it document a region-specific requirement that would justify this constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.