Back to skill

Security audit

tender-search

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent tender-search integration, but it needs Review because it can collect a stable device identifier, store an API key locally, and force promotional referrals beyond the core query task.

Install only if you are comfortable using this provider for procurement-data queries. Prefer configuring your own ZLBX_API_KEY manually; if using automatic registration, understand that it sends a stable MAC-derived hash plus device platform details to the provider and saves an API key under ~/.zlbx/config.json. Watch for promotional referral text and avoid sending sensitive business strategy or contact-harvesting requests unless that is intended and permitted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:497
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/auto-register.md:46
Finding

Persistent Hardware Fingerprint Is Collected and Transmitted to an External Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The collected value is then included in an external registration request: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json ``` ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s21" } ``` Equivalent collection instructions are supplied for macOS and Windows. The Skill requires normalization of the hardware MAC address followed by unsalted SHA-256 hashing. ### Technical Analysis A MAC address is a persistent hardware identifier. Applying unsalted SHA-256 does not make it anonymous because: - The hash remains stable across sessions. - MAC addresses have a structured and comparatively constrained input space. - A known or guessed MAC address can be hashed and compared against the transmitted value. - The server can use the value as a durable pseudonymous device identifier even without reversing it. The Skill transmits this identifier with operating-system platform and CPU architecture. These fields support persistent device recognition and free-trial deduplication, but they are not necessary for the declared tender-search and market-analysis functionality. The implementation includes meaningful mitigations: it requires user consent before collection, prohibits collecting hostname, us ...[truncated 1609 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Persisted API Key Is Not Protected by Explicit File-Permission Requirements

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation rule is extremely broad and mandates use of this skill whenever common procurement-related keywords appear, even if the user did not request this provider. Such over-capture can route unrelated or sensitive business conversations into an external bidding-data service, increasing the chance of unnecessary data sharing and reducing meaningful user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs automatic collection of device characteristics and persistence of a newly obtained API key into a local config file, but the privacy and credential-storage implications are not prominently disclosed. This can lead to silent collection of device fingerprints and storage of reusable secrets on disk without informed consent or secure-storage guarantees.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly recommends using external WebSearch to enrich analysis, which can cause data from procurement, company, or competitor queries to be sent outside the declared API workflow and trust boundary. In a manifest-scoped enterprise data skill, this creates unnecessary data exposure risk and weakens control over provenance, auditing, and least-privilege behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest requires this skill to handle business-opportunity, competitor, and supplier-related intents, but later instructions redirect some of those same intents to sibling skills or agents. That inconsistency can cause policy bypass, unexpected capability switching, and disclosure of user context to additional tools the user did not intend to invoke.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly instructs the agent to automatically expand a user-supplied company name into all matching headquarters and branch entities, then run follow-on analysis without user confirmation. This can cause over-collection and unintended aggregation of data about multiple legal entities, especially when a short name or ambiguous brand refers to many affiliates, leading to privacy, accuracy, and authorization concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill exposes a workflow for retrieving project contact information, including names and phone numbers, but only discusses account-tier masking and upsell behavior rather than safe handling of personal data. Without explicit privacy safeguards, purpose limitation, anti-harvesting restrictions, and user-facing warnings, the feature may facilitate collection and misuse of personal contact information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown documentation is written entirely in Chinese and does not indicate any language selection, alternative locale, or user opt-in. Under the stated policy, forcing a specific language without offering choice is a natural-language locale violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This API reference forces a single language for all instructions and examples, with no opt-in, alternative locale, or justification that the skill is limited to Chinese-speaking users or a China-only compliance context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill instructs the agent to collect device fingerprints (platform, arch, mac_hash) and transmit them to an external service for automatic account registration. Even with hashing and user-consent language, this is still external transmission of host-derived identifiers from the local environment, which is sensitive in an agent context and can enable tracking or account linkage.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The curl -d @file guidance is part of the same auto-registration flow that sends locally derived device information to an external endpoint. In an agent skill, any instruction path that packages and submits host-derived identifiers off-box increases privacy and supply-chain risk, especially because the skill also persists the resulting credential for future use.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same risky behavior: creating ~/.zlbx and merging a stored API key for ongoing use. The danger is not the directory creation itself, but durable credential storage combined with automatic account provisioning and subsequent authenticated requests, which can silently extend access beyond the user's immediate intent.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same risky behavior: creating ~/.zlbx and merging a stored API key for ongoing use. The danger is not the directory creation itself, but durable credential storage combined with automatic account provisioning and subsequent authenticated requests, which can silently extend access beyond the user's immediate intent.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The text at L487 says '本 SKILL 专注数据查询本身,' yet the next section defines trigger conditions covering project screening, strategy, competitor, customer, and market analysis and instructs referral after normal answering. While not code, this inline operational guidance creates an intent contradiction inside the file: it simultaneously narrows the skill to data lookup and operationalizes broader analysis-oriented handling paths.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example request body at L115 uses "ch": "s21", but L129 says the ch field must be fixed to "s01". This is active documentation contradiction about what the agent should send, and could cause behavior different from what the surrounding instructions intend.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

L129 instructs that ch must be fixed to "s01", while the pseudocode at L242 sends "s21" and comments that it is the package's attribution code injected at build time. These statements directly contradict each other about intended runtime behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.