Back to skill

Security audit

标书制作工具

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real bid-document API client, but it needs review because it handles App Keys and sensitive document uploads while allowing an unvalidated API destination and using over-controlling agent instructions.

Review this skill before installing. Use it only if you trust the publisher and the 招采猫 service, and only with documents you are allowed to upload to that cloud platform. Prefer manual credential setup instead of pasting the App Key into chat; verify ZCM_BASE and any saved base value point only to the official API; rotate the App Key if it was exposed; and avoid untrusted report basenames or output paths.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:23
Finding

Mandatory Output-Control Directives Can Hijack Agent Responses

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/zcm.py:159
Finding

Unrestricted API Base Override Can Exfiltrate App Keys and Uploaded Documents

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/report.py:638
Finding

Unsanitized Report Basename Permits Path Traversal and Arbitrary File Overwrite

Content
View full analysis
招标文件名_{标签} > 标签_时间戳。 fmt 默认 html(用户未明确要 Word 时只出 HTML);要 Word 传 docx 或 both。 """ detected, result = _unwrap(data) service = service or detected if service not in RENDERERS: raise ValueError(f"未知 service:{service}(应为 interpretation / compliance)") html, blocks = RENDERERS[service](result) os.makedirs(out_dir, exist_ok=True) label = _LABEL[service] tender_name = tender_name or _auto_tender_name(service, result) if basename: base = basename elif tender_name: base = f"{_safe_name(tender_name)}_{label}" else: base = f"{label}_{datetime.now():%Y%m%d_%H%M%S}" outs = [] if fmt in ("html", "both"): p = os.path.join(out_dir, base + ".html") with open(p, "w", encoding="utf-8") as f: f.write(html) outs.append(p) if fmt in ("docx", "both"): p = os.path.join(out_dir, base + ".docx") with open(p, "wb") as f: f.write(build_docx(blocks)) ``` ### Technical Analysis The `tender_name` path passes through `_safe_name()`, but an explicitly supplied `basename` does not. It is used directly in: ```python os.path.join(out_dir, base + ".html") ``` and: ```python os.path.join(out_dir, base + ".docx") ``` A basename containing `../` components can escape `out_dir`. On platforms where an absolute second component overrides the first path component, an absolute basename can also disregard `out_dir` entirely. The files are opened with write mode, so an existing writable target is truncated and replaced. Appending a fixed extension limits the target to names ending in `.html` or `.docx`, but i ...[truncated 1225 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向招采猫线上接口的端到端标书制作客户端,核心能力包括调用开放 API、上传文件、智能解读、抽取分包、生成成品投标文件以及合规审查。实际代码仅处理已经存在的 JSON 结果,按 interpretation/compliance 两类结果渲染出可视化报告,并保存为 HTML 或最小 OOXML 的 .docx 文件。它没有网络请求、认证、App Key 使用、文件上传、标书正文生成、分包抽取或审查执行逻辑。虽然代码涉及“智能解读/合规审查”结果,但只是结果展示层,属于整个系统中的辅助组件,而非声明所说的主要功能实现。因此该代码块与声明用途存在实质性不匹配。

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs users to paste an App Key into the chat and even provides reusable wording that normalizes credential disclosure in conversation. Chat transcripts are commonly retained, logged, exported, or viewed by others, so encouraging secret entry into chat increases the chance of credential leakage and later unauthorized API use or account billing abuse.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The setup section tells users to disclose their App Key in the conversation so the assistant can save it for future use, which promotes collection and persistence of a reusable credential through an insecure channel. Because the key authorizes cloud API actions and may consume account credits, compromise of chat history or logs can lead to unauthorized access, misuse, and financial impact.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/usage.md (reported line 57)May include surrounding context.

配置方式(任选其一):

  1. 用户把 Key 粘贴到对话后,由你代跑 login --app-key bk_live_xxx 保存(自动建/更新凭证文件,权限 600)——别把这条命令丢给用户自己敲。⚠️ 同时提醒:粘贴的 Key 会留在会话记录中,介意可用方式 3 手动配置。
  2. 临时用环境变量:export ZCM_APP_KEY=bk_live_xxx(首次会自动落盘到凭证文件)。
  3. 手动配置(Key 全程不经对话,最私密):用户自行创建凭证文件 ~/.zcm/config.json(完整全路径,~ 为用户主目录),内容模板如下,保存后建议 chmod 600:
    json
    {"app_key": "bk_live_xxxxx"}
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L119 says the script output and report have been automatically converted to Chinese and instructs the assistant to present them directly in Chinese. This imposes a specific language on the user without any opt-in or alternative, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and user-facing behavior are entirely written in Chinese, and the code later converts result enums into Chinese for display. There is no indication that users may opt into another language or locale, which matches the policy concern for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The zh_risk mapping rewrites risk_level and priority enum values into Chinese for display, and there is no alternate locale path. This hard-codes a specific language in user-visible output without offering opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generated HTML document sets lang='zh', and the report content and labels are consistently forced to Chinese. This is a natural-language locale constraint in a code file, and there is no visible user opt-in or alternative language selection path in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest frames the skill primarily as a thin client that uploads tender/bid documents to the 招采猫 API, but this file additionally stores the App Key in ~/.zcm/config.json and remembers tender filename mappings in ~/.zcm/projects.json. Those local persistence behaviors are not mentioned in the manifest, so the implemented behavior is slightly broader than the stated user-facing description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.