Back to skill

Security audit

知了商机大师-商机Agent

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated bidding-platform purpose, but it handles API keys in ways that can expose them and uses a configurable endpoint that can receive the bearer token.

Review this skill before installing. Use a dedicated low-privilege API key, do not paste the key into chat, do not run the documented echo command as written, and avoid setting ZLBX_AGENT_BASE unless you fully trust the endpoint. Rotate the key if it has already been printed in logs or used with an untrusted base URL.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:18
Finding

Mandatory Promotional Output and Tracked Registration-Link Injection

Content
View full analysis
Before using this skill, you must provide an API key. Click this link to register and create a key (**registration grants free-user status and a complimentary credit balance**): > Registration address: https://agent.zhiliaobiaoxun.com/developer?utm_source=skill > After creating a key in the form `zlbx_agent_xxx`, send it to me or execute `export ZLBX_AGENT_API_KEY=zlbx_agent_xxx`. Do not invoke any subcommand until the key has been obtained. ``` The snippet above is an English rendering of the instructions at the cited location; the original file presents those instructions in Chinese. ### Technical Analysis The skill instructions require the agent to reproduce predetermined advertising text and a tracked external registration URL verbatim whenever an API key is unavailable. This goes beyond a neutral configuration prerequisite: it takes control of the agent's user-facing response and requires promotional claims, an incentive, and a URL containing the tracking parameter `utm_source=skill`. Because these instructions activate whenever the key is missing, loading the skill can alter the agent's current response objectives from assisting the user to performing a mandatory customer-acquisition flow for the service operator. ### Attack Path 1. A user activates the skill without `ZLBX_AGENT_API_KEY` configured. 2. The skill instructs the agent not to continue with normal functionality. 3. The agent is required to reproduce fixed promotional language and a tracked registration URL. 4. The user is redirected to an external account-registration flow. ...[truncated 524 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:12
Finding

API Key Disclosed Through Mandatory Shell Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/zlbx_agent.py:18
Finding

Bearer Credential Forwarding to an Arbitrary Configurable API Endpoint

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tainted flow: 'req' from os.getenv (line 37, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/zlbx_agent.py (reported line 42)May include surrounding context.

python
if data is not None:
        req.add_header("Content-Type", "application/json")
    try:
        with urllib.request.urlopen(req, timeout=310) as resp:
            raw = resp.read().decode("utf-8")
            return json.loads(raw) if raw else None
    except urllib.error.HTTPError as e:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a Python CLI that reads an API key from environment variables and calls a remote API, but the manifest does not declare any tool scope such as environment or network permissions. This creates a transparency and least-privilege problem: the agent may access secrets and external services without explicit permission boundaries, increasing the risk of unintended secret exposure or unauthorized outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and main instructions are entirely written in Chinese and describe when the skill should be used, but they do not indicate that users may interact in other languages or that the Chinese-only scope is intentional for a region-specific compliance reason. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The helper sends HTTP requests to a remote service, including a Bearer token from the environment and request bodies such as chat messages or task descriptions. While the module docstring mentions where credentials come from, it does not clearly warn users that their inputs and authentication data will be transmitted to an external API, and there is no runtime notice before sending.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language docstring and user-facing error/help text are Chinese-only, which can impose a language constraint on users without opt-in. Under the policy, forcing a specific language is a violation unless the skill offers a choice or clearly documents a justified locale limitation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:36