T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/parse_bids.py:25- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is broadly about bid monitoring, but it needs review because it scrapes and emails business data with insecure network handling and incomplete scoping.
Install only after review or fixes. Expect Chinese bid-source scraping, local report/history files, SMTP credentials, and outbound email delivery. Before operational use, restore normal HTTPS verification, restrict fetches to approved public bidding domains, sanitize Excel output, and make email sending an explicit opt-in step.
scripts/parse_bids.py:25Unrestricted URL Fetching Enables Server-Side Request Forgery
scripts/search_bids.py:16HTTPS Certificate and Hostname Verification Are Disabled
scripts/generate_report.py:288Untrusted Bid Data Is Written to Excel Without Formula Neutralization
声明描述的是一个完整的投标情报监控系统,包含行业招标监控、特定竞争对手追踪、定期自动采集、报告生成和邮件发送等能力。而提供的代码片段只是一个数据增强脚本:读取本地JSON文件,对招标标题做正则提取,补充company/budget字段,并按简单规则打优先级标签后写回JSON。其功能可视为该系统中的一个辅助处理步骤,但它没有体现声明中的核心能力,尤其没有追踪所列4家竞争对手,且公司匹配列表与声明目标明显不一致。因此该代码片段与声明用途存在实质性不匹配。
该代码块的核心功能是报告生成与文件存档:读取 data 目录中的 bids_parsed_enriched.json 或 bids_raw_*.json,统计优先级、相关性和竞争公司分布,输出 Markdown 和可选 Excel 文件,并归档历史报告。这与声明中的“监控系统”存在明显差距,因为代码没有网络抓取、搜索调用、定时调度或任何自动采集逻辑;也没有邮件发送实现。虽然报告内容围绕锂电/储能行业和4家竞争对手,属于声明目标的一部分,但仅覆盖了“生成表格报告”的子功能,未覆盖声明中的主要能力(监控、追踪、每周自动采集、发送邮件),因此应判定为描述与实际行为不一致。
声明描述的是一个较完整的“投标情报监控系统”,包含竞争对手定向追踪、周期性自动执行、报告生成和邮件发送。实际代码只实现了数据采集的一部分:访问预置链接和两个搜索平台,提取标题/链接,并将结果保存为JSON。虽然代码确实与储能/锂电相关招标信息搜索有关,属于声明目标的一个子环节,但关键承诺能力均未出现:COMPETITORS 常量被定义却未使用,没有任何竞争对手名称匹配、投标行为分析、周度调度、表格导出或邮件发送逻辑。因此描述明显高于实际行为,存在实质性不匹配。
TLS hostname and certificate verification are explicitly disabled for all outbound HTTPS requests. This allows a man-in-the-middle attacker on the network path to impersonate target sites and feed the script tampered HTML, causing false intelligence collection, poisoned reports, or potentially unsafe downstream processing if later components trust the fetched content.
The skill advertises behaviors that require network access, local file read/write, and environment-variable access, but it does not declare any explicit tool scope or permissions. This weakens security review and least-privilege enforcement, making it easier for the skill to access sensitive resources such as SMTP credentials and write/archive data without clear user visibility.
The skill handles SMTP configuration and sends collected reports by email, but the top-level description does not prominently warn users that credentials are required and outbound transmission occurs. This can lead to accidental exposure of sensitive business intelligence or unsafe credential handling because operators may not realize the skill exfiltrates data to external mail infrastructure.
This code file contains natural-language instructions and output entirely in Chinese, including the module description and runtime messages, with no indication that the skill is China-specific or that users can choose another language. The policy requires flagging language or locale constraints when they are imposed without opt-in or clear justification.
The script’s natural-language interface and generated report content are hard-coded in Chinese, including the module description and all user-facing output. There is no option for user language selection or documentation explaining that the tool is intentionally limited to a Chinese-language, region-specific workflow.
The request headers hard-code Accept-Language: zh-CN,zh;q=0.9, which directs remote services to respond in a specific language/locale. Under the policy, locale constraints should not be forced unless the user opts in or the region-specific requirement is clearly documented and justified.
The Accept-Language header forces zh-CN/zh for all outbound requests, which is a natural-language locale constraint applied without user opt-in. The file does not document this as a justified region-specific requirement or provide a way for users to select another language or locale.
The manifest says the skill tracks bidding dynamics of four specific competitors, but the only competitor-related logic is a constant dictionary declaring their names. No search, filtering, matching, or reporting logic uses COMPETITORS; the executable flow only fetches preset links and keyword search results from industry sites.
The manifest describes monitoring 招标信息 for 锂电池/储能/装配段行业 and competitor bid dynamics, yet the search terms focus narrowly on storage systems and battery equipment procurement phrases. There is no explicit assembly-segment coverage and no competitor-name queries, so the implemented behavior is materially narrower than the claimed scope.
This code file performs a network operation that transmits potentially sensitive report data and attachments via SMTP. Although it logs success and failure, there is no explicit disclosure or confirmation before the send occurs, and the script description only says it sends weekly reports without warning about external transmission.
The skill persistently writes raw, enriched, and historical bid-monitoring data to local files, but this retention behavior is not clearly surfaced as a user warning. Silent accumulation of business intelligence can increase exposure if the host is shared, backups are broad, or retention is longer than intended.
Natural-language strings in the module docstring and runtime messages are presented only in Chinese, and there is no indication that users can opt into another language. This may violate language or locale policy when skills are expected to avoid forcing a specific language without user choice.
No suspicious patterns detected.