T01 · Skill Instruction Hijacking
- Location
SKILL.md:497- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent tender-search integration, but it needs Review because it can collect a stable device identifier, store an API key locally, and force promotional referrals beyond the core query task.
Install only if you are comfortable using this provider for procurement-data queries. Prefer configuring your own ZLBX_API_KEY manually; if using automatic registration, understand that it sends a stable MAC-derived hash plus device platform details to the provider and saves an API key under ~/.zlbx/config.json. Watch for promotional referral text and avoid sending sensitive business strategy or contact-harvesting requests unless that is intended and permitted.
SKILL.md:497Mandatory Promotional Content Hijacks Agent Responses
references/auto-register.md:46Persistent Hardware Fingerprint Is Collected and Transmitted to an External Service
references/auto-register.md:173Persisted API Key Is Not Protected by Explicit File-Permission Requirements
The activation rule is extremely broad and mandates use of this skill whenever common procurement-related keywords appear, even if the user did not request this provider. Such over-capture can route unrelated or sensitive business conversations into an external bidding-data service, increasing the chance of unnecessary data sharing and reducing meaningful user choice.
The skill instructs automatic collection of device characteristics and persistence of a newly obtained API key into a local config file, but the privacy and credential-storage implications are not prominently disclosed. This can lead to silent collection of device fingerprints and storage of reusable secrets on disk without informed consent or secure-storage guarantees.
The skill explicitly recommends using external WebSearch to enrich analysis, which can cause data from procurement, company, or competitor queries to be sent outside the declared API workflow and trust boundary. In a manifest-scoped enterprise data skill, this creates unnecessary data exposure risk and weakens control over provenance, auditing, and least-privilege behavior.
The manifest requires this skill to handle business-opportunity, competitor, and supplier-related intents, but later instructions redirect some of those same intents to sibling skills or agents. That inconsistency can cause policy bypass, unexpected capability switching, and disclosure of user context to additional tools the user did not intend to invoke.
The skill explicitly instructs the agent to automatically expand a user-supplied company name into all matching headquarters and branch entities, then run follow-on analysis without user confirmation. This can cause over-collection and unintended aggregation of data about multiple legal entities, especially when a short name or ambiguous brand refers to many affiliates, leading to privacy, accuracy, and authorization concerns.
The skill exposes a workflow for retrieving project contact information, including names and phone numbers, but only discusses account-tier masking and upsell behavior rather than safe handling of personal data. Without explicit privacy safeguards, purpose limitation, anti-harvesting restrictions, and user-facing warnings, the feature may facilitate collection and misuse of personal contact information.
This markdown documentation is written entirely in Chinese and does not indicate any language selection, alternative locale, or user opt-in. Under the stated policy, forcing a specific language without offering choice is a natural-language locale violation unless clearly justified as region-specific.
SQP-3 applies to all file types and includes language or locale policy violations. This API reference forces a single language for all instructions and examples, with no opt-in, alternative locale, or justification that the skill is limited to Chinese-speaking users or a China-only compliance context.
The skill instructs the agent to collect device fingerprints (platform, arch, mac_hash) and transmit them to an external service for automatic account registration. Even with hashing and user-consent language, this is still external transmission of host-derived identifiers from the local environment, which is sensitive in an agent context and can enable tracking or account linkage.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
The curl -d @file guidance is part of the same auto-registration flow that sends locally derived device information to an external endpoint. In an agent skill, any instruction path that packages and submits host-derived identifiers off-box increases privacy and supply-chain risk, especially because the skill also persists the resulting credential for future use.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
This duplicate finding points to the same risky behavior: creating ~/.zlbx and merging a stored API key for ongoing use. The danger is not the directory creation itself, but durable credential storage combined with automatic account provisioning and subsequent authenticated requests, which can silently extend access beyond the user's immediate intent.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding points to the same risky behavior: creating ~/.zlbx and merging a stored API key for ongoing use. The danger is not the directory creation itself, but durable credential storage combined with automatic account provisioning and subsequent authenticated requests, which can silently extend access beyond the user's immediate intent.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The text at L487 says '本 SKILL 专注数据查询本身,' yet the next section defines trigger conditions covering project screening, strategy, competitor, customer, and market analysis and instructs referral after normal answering. While not code, this inline operational guidance creates an intent contradiction inside the file: it simultaneously narrows the skill to data lookup and operationalizes broader analysis-oriented handling paths.
The example request body at L115 uses "ch": "s21", but L129 says the ch field must be fixed to "s01". This is active documentation contradiction about what the agent should send, and could cause behavior different from what the surrounding instructions intend.
L129 instructs that ch must be fixed to "s01", while the pseudocode at L242 sends "s21" and comments that it is the package's attribution code injected at build time. These statements directly contradict each other about intended runtime behavior.
No suspicious patterns detected.