T01 · Skill Instruction Hijacking
- Location
SKILL.md:497- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a legitimate procurement-data helper, but it asks for device fingerprinting and persistent credential/account actions that users should review carefully.
Install only if you are comfortable with this skill using an external procurement-data service, reading or creating a local API-key config, and optionally registering your device with a hashed MAC-derived identifier. Prefer setting your own ZLBX_API_KEY manually, avoid auto-registration if device fingerprinting is unacceptable, and treat generated auto-login or recharge links as sensitive account links.
SKILL.md:497Mandatory Promotional Content Hijacks Agent Responses
references/auto-register.md:46Registration Transmits a Persistent Hardware-Derived Device Fingerprint
references/auto-register.md:173API Key Is Persisted in a Predictable Plaintext File Without Mandatory Permission Controls
The skill instructs collection of platform, architecture, and a hashed MAC address for device-based registration, which constitutes device fingerprinting unrelated to the stated tender-analysis function. Even with hashing and disclosure text, this is still persistent hardware-derived tracking data that is transmitted externally and can be used for cross-session identification or account correlation.
The file directs the agent to perform account auto-registration, account recovery handling, quota-upgrade link generation, and local credential persistence, which materially exceed the declared bid-data analysis purpose of the skill. This expands the skill from analytical assistance into identity/account provisioning and stateful auth management, increasing the chance of unauthorized data collection, hidden account creation, and misuse of user environment access.
The skill declares that it 'must' be used for a wide range of bidding-related scenarios, creating an overbroad routing rule with weak boundaries. This can cause the agent to invoke the skill when a narrower, safer, or more appropriate tool should be used, increasing the chance of unnecessary external data access, unintended account actions, and policy bypass through tool over-selection.
The description mandates Chinese output without offering a user language choice or documenting a strict locale constraint. While not a direct code-execution risk, this can mislead users, reduce comprehension of sensitive procurement results, and create unsafe misunderstandings when users expect another language or bilingual output.
The file documents account-balance and consumption APIs that are unrelated to the skill’s stated purpose of bid and award data analysis for suppliers. This unjustified expansion of capability increases the chance the agent will access sensitive account metadata and usage information outside user intent, violating least-privilege and enabling data exposure or behavioral profiling.
The documentation instructs the agent to use an API key from environment/config to retrieve account balance and consumption data, even though the bid-analysis context does not justify access to billing or usage records. In an agent setting, this can cause unauthorized retrieval of sensitive operational/account information and normalize hidden use of credentials for out-of-scope actions.
The documentation instructs the agent to automatically match ambiguous company names and expand analysis to all matching headquarters and subsidiaries without user confirmation. This can cause over-collection, mistaken attribution, and disclosure of analysis about entities the user did not intend to target, particularly when short names map to multiple related or unrelated legal entities.
The skill exposes a tool for retrieving company project contact information, including names and phone numbers, which goes beyond aggregate bid-analysis and enters targeted personal/contact data access. In a supplier bidding assistant, this can enable scraping, unsolicited outreach, deanonymization of masked contacts, or operational profiling of organizations and individuals, especially when combined with keyword/date filters for systematic targeting.
This markdown file presents all tool instructions, parameters, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.
This markdown file presents all operational instructions and API details exclusively in Chinese, which can constitute a language/locale policy violation when no user opt-in or alternative language is offered. The content does not state that the skill is region-specific or otherwise justify the language restriction.
The skill checks environment variables and local config files for API keys, then later instructs writing credentials back to a user config file. Reading and modifying local credential stores is unrelated to bid analysis and introduces risk of unauthorized secret handling, accidental overwrite/merging issues, and persistent side effects in the user environment.
This section explicitly instructs the agent to serialize and send collected device features to an external endpoint. Because the transmitted data includes persistent device-derived identifiers for a purpose outside the skill's declared role, the transmission creates privacy and trust risks even if the transport format is correctly serialized.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
Line L129 states the ch field must be fixed to "s01", but the request example at L115, the manual link references, and the pseudocode at L242 consistently use "s24". This is an active contradiction in the documented intent that can cause implementers to send the wrong value.
This duplicate finding points to the same session-persistence behavior: creating ~/.zlbx, merging config, marking source: "auto", and continuing to use the key without restart. Such persistent auth side effects are not justified by the skill's analytical purpose and can silently alter user environment state.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding points to the same session-persistence behavior: creating ~/.zlbx, merging config, marking source: "auto", and continuing to use the key without restart. Such persistent auth side effects are not justified by the skill's analytical purpose and can silently alter user environment state.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The document prescribes exact Chinese text to present to users for quota exhaustion handling, including a required regeneration phrase. This imposes a specific language on user interactions without any indication that the user can choose their preferred language or that the skill is intentionally region-locked.
All user-facing instructions, examples, and operational guidance are presented exclusively in Chinese, and there is no indication that users may choose another language. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is clearly justified.
No suspicious patterns detected.