T01 · Skill Instruction Hijacking
- Location
SKILL.md:23- Finding
Mandatory Output-Control Directives Can Hijack Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real bid-document API client, but it needs review because it handles App Keys and sensitive document uploads while allowing an unvalidated API destination and using over-controlling agent instructions.
Review this skill before installing. Use it only if you trust the publisher and the 招采猫 service, and only with documents you are allowed to upload to that cloud platform. Prefer manual credential setup instead of pasting the App Key into chat; verify ZCM_BASE and any saved base value point only to the official API; rotate the App Key if it was exposed; and avoid untrusted report basenames or output paths.
SKILL.md:23Mandatory Output-Control Directives Can Hijack Agent Responses
scripts/zcm.py:159Unrestricted API Base Override Can Exfiltrate App Keys and Uploaded Documents
scripts/report.py:638Unsanitized Report Basename Permits Path Traversal and Arbitrary File Overwrite
声明描述的是一个面向招采猫线上接口的端到端标书制作客户端,核心能力包括调用开放 API、上传文件、智能解读、抽取分包、生成成品投标文件以及合规审查。实际代码仅处理已经存在的 JSON 结果,按 interpretation/compliance 两类结果渲染出可视化报告,并保存为 HTML 或最小 OOXML 的 .docx 文件。它没有网络请求、认证、App Key 使用、文件上传、标书正文生成、分包抽取或审查执行逻辑。虽然代码涉及“智能解读/合规审查”结果,但只是结果展示层,属于整个系统中的辅助组件,而非声明所说的主要功能实现。因此该代码块与声明用途存在实质性不匹配。
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill explicitly instructs users to paste an App Key into the chat and even provides reusable wording that normalizes credential disclosure in conversation. Chat transcripts are commonly retained, logged, exported, or viewed by others, so encouraging secret entry into chat increases the chance of credential leakage and later unauthorized API use or account billing abuse.
The setup section tells users to disclose their App Key in the conversation so the assistant can save it for future use, which promotes collection and persistence of a reusable credential through an insecure channel. Because the key authorizes cloud API actions and may consume account credits, compromise of chat history or logs can lead to unauthorized access, misuse, and financial impact.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
配置方式(任选其一):
login --app-key bk_live_xxx 保存(自动建/更新凭证文件,权限 600)——别把这条命令丢给用户自己敲。⚠️ 同时提醒:粘贴的 Key 会留在会话记录中,介意可用方式 3 手动配置。export ZCM_APP_KEY=bk_live_xxx(首次会自动落盘到凭证文件)。~/.zcm/config.json(完整全路径,~ 为用户主目录),内容模板如下,保存后建议 chmod 600:
{"app_key": "bk_live_xxxxx"}
Line L119 says the script output and report have been automatically converted to Chinese and instructs the assistant to present them directly in Chinese. This imposes a specific language on the user without any opt-in or alternative, which matches the language/locale policy violation criteria.
The module docstring and user-facing behavior are entirely written in Chinese, and the code later converts result enums into Chinese for display. There is no indication that users may opt into another language or locale, which matches the policy concern for forced language/locale behavior.
The zh_risk mapping rewrites risk_level and priority enum values into Chinese for display, and there is no alternate locale path. This hard-codes a specific language in user-visible output without offering opt-in or documented justification.
The generated HTML document sets lang='zh', and the report content and labels are consistently forced to Chinese. This is a natural-language locale constraint in a code file, and there is no visible user opt-in or alternative language selection path in this file.
The manifest frames the skill primarily as a thin client that uploads tender/bid documents to the 招采猫 API, but this file additionally stores the App Key in ~/.zcm/config.json and remembers tender filename mappings in ~/.zcm/projects.json. Those local persistence behaviors are not mentioned in the manifest, so the implemented behavior is slightly broader than the stated user-facing description.
No suspicious patterns detected.