Back to skill

Security audit

Cn Tendering Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese construction tendering/procurement reference assistant with no hidden execution, data access, persistence, or destructive behavior found.

Install this only if you want Chinese-language guidance for PRC construction tendering/procurement workflows. Treat legal and procurement outputs as drafting aids, verify current law and project-specific requirements, and have qualified professionals review major tendering or contract decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared description promises a full-chain tendering/procurement expert system with multiple specialized capabilities, but the actual code chunk is merely a minimal example script with no implemented business logic beyond printing a message. This is not an undeclared dangerous capability issue; rather, the primary purpose of the code does not match the described functionality at all.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list contains broad business terms such as '采购管理', '发包人需求', and '专家判断' that may appear in ordinary conversation without a clear intent to invoke this skill. Over-broad activation can cause unintended routing, leading the agent to apply procurement-specific guidance in the wrong context or disclose irrelevant domain workflows when another skill should respond.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation section defines broad scenarios but does not specify boundaries or exclusion criteria, so the agent may select this skill for adjacent legal, contract, or project-management discussions that are not actually tendering tasks. In a multi-skill environment, ambiguous activation increases the chance of misrouting, which can produce incorrect specialized guidance or bypass a more appropriate safety-constrained skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest description, tags, and triggers are entirely Chinese-language and targeted to a specific locale, but there is no documented locale scoping or user opt-in mechanism. This can lead to unintended activation for Chinese text regardless of user language preferences, causing misrouting, confusion, or improper processing of user requests in multilingual environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The trigger set includes broad procurement terms such as '采购管理' and '工程招标' that are likely to appear in ordinary user conversations, which can cause the skill to activate outside the user's clear intent. In an agent setting, overbroad activation can route sensitive business or procurement discussions into a specialized workflow unexpectedly, increasing the chance of inappropriate handling or disclosure of context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses only Chinese throughout, including headings, templates, and instructions, with no indication that the skill is limited to Chinese-speaking users or a China-specific workflow. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is entirely written in Chinese and presents the template library as if Chinese is the required language, with no indication that other languages are supported or that the locale is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all instructions and legal reference material exclusively in Chinese, and there is no statement that the skill is China-specific or that users can opt into this language. Under the language/locale policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file is written entirely in Chinese and presents the framework as-is without any note about language choice, translation availability, or locale limitation. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents the skill content exclusively in Chinese from the title onward, with no indication that the user can choose another language or that the document is intentionally limited to a Chinese-speaking or China-specific audience. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.