Back to skill

Security audit

招标中标查询&数据分析-乙方投标助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate procurement-data helper, but it asks for device fingerprinting and persistent credential/account actions that users should review carefully.

Install only if you are comfortable with this skill using an external procurement-data service, reading or creating a local API-key config, and optionally registering your device with a hashed MAC-derived identifier. Prefer setting your own ZLBX_API_KEY manually, avoid auto-registration if device fingerprinting is unacceptable, and treat generated auto-login or recharge links as sensitive account links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:497
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/auto-register.md:46
Finding

Registration Transmits a Persistent Hardware-Derived Device Fingerprint

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```json POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s24" } ``` The same file provides equivalent MAC-address collection procedures for macOS and Windows. ### Technical Analysis The registration workflow derives a stable identifier from a physical network adapter's MAC address and transmits it with platform, processor architecture, Agent identity, Agent version, Skill version, and channel-attribution metadata. SHA-256 hashing does not make a MAC address anonymous. MAC addresses have a small, structured search space, including publicly known vendor prefixes, and can be tested offline against a captured hash. More importantly, the hash itself remains a stable pseudonymous identifier even if it is never reversed. The stated purpose is prevention of repeated free-trial registration. That purpose is ancillary to the Skill's declared procurement-analysis functionality and therefore exceeds the minimum data access necessary to perform searches and analysis. The workflow includes a positive safeguard: collection is explicitly consent-gated, and the instructions prohibit collecting the hostname, username, home directory, and r ...[truncated 1551 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

API Key Is Persisted in a Predictable Plaintext File Without Mandatory Permission Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs collection of platform, architecture, and a hashed MAC address for device-based registration, which constitutes device fingerprinting unrelated to the stated tender-analysis function. Even with hashing and disclosure text, this is still persistent hardware-derived tracking data that is transmitted externally and can be used for cross-session identification or account correlation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file directs the agent to perform account auto-registration, account recovery handling, quota-upgrade link generation, and local credential persistence, which materially exceed the declared bid-data analysis purpose of the skill. This expands the skill from analytical assistance into identity/account provisioning and stateful auth management, increasing the chance of unauthorized data collection, hidden account creation, and misuse of user environment access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares that it 'must' be used for a wide range of bidding-related scenarios, creating an overbroad routing rule with weak boundaries. This can cause the agent to invoke the skill when a narrower, safer, or more appropriate tool should be used, increasing the chance of unnecessary external data access, unintended account actions, and policy bypass through tool over-selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description mandates Chinese output without offering a user language choice or documenting a strict locale constraint. While not a direct code-execution risk, this can mislead users, reduce comprehension of sensitive procurement results, and create unsafe misunderstandings when users expect another language or bilingual output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file documents account-balance and consumption APIs that are unrelated to the skill’s stated purpose of bid and award data analysis for suppliers. This unjustified expansion of capability increases the chance the agent will access sensitive account metadata and usage information outside user intent, violating least-privilege and enabling data exposure or behavioral profiling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation instructs the agent to use an API key from environment/config to retrieve account balance and consumption data, even though the bid-analysis context does not justify access to billing or usage records. In an agent setting, this can cause unauthorized retrieval of sensitive operational/account information and normalize hidden use of credentials for out-of-scope actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs the agent to automatically match ambiguous company names and expand analysis to all matching headquarters and subsidiaries without user confirmation. This can cause over-collection, mistaken attribution, and disclosure of analysis about entities the user did not intend to target, particularly when short names map to multiple related or unrelated legal entities.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes a tool for retrieving company project contact information, including names and phone numbers, which goes beyond aggregate bid-analysis and enters targeted personal/contact data access. In a supplier bidding assistant, this can enable scraping, unsolicited outreach, deanonymization of masked contacts, or operational profiling of organizations and individuals, especially when combined with keyword/date filters for systematic targeting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all tool instructions, parameters, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all operational instructions and API details exclusively in Chinese, which can constitute a language/locale policy violation when no user opt-in or alternative language is offered. The content does not state that the skill is region-specific or otherwise justify the language restriction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill checks environment variables and local config files for API keys, then later instructs writing credentials back to a user config file. Reading and modifying local credential stores is unrelated to bid analysis and introduces risk of unauthorized secret handling, accidental overwrite/merging issues, and persistent side effects in the user environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This section explicitly instructs the agent to serialize and send collected device features to an external endpoint. Because the transmitted data includes persistent device-derived identifiers for a purpose outside the skill's declared role, the transmission creates privacy and trust risks even if the transport format is correctly serialized.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Line L129 states the ch field must be fixed to "s01", but the request example at L115, the manual link references, and the pseudocode at L242 consistently use "s24". This is an active contradiction in the documented intent that can cause implementers to send the wrong value.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This duplicate finding points to the same session-persistence behavior: creating ~/.zlbx, merging config, marking source: "auto", and continuing to use the key without restart. Such persistent auth side effects are not justified by the skill's analytical purpose and can silently alter user environment state.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This duplicate finding points to the same session-persistence behavior: creating ~/.zlbx, merging config, marking source: "auto", and continuing to use the key without restart. Such persistent auth side effects are not justified by the skill's analytical purpose and can silently alter user environment state.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document prescribes exact Chinese text to present to users for quota exhaustion handling, including a required regeneration phrase. This imposes a specific language on user interactions without any indication that the user can choose their preferred language or that the skill is intentionally region-locked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

All user-facing instructions, examples, and operational guidance are presented exclusively in Chinese, and there is no indication that users may choose another language. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.