Back to skill

Security audit

施工建材采招助手-鲁班乐标

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a real procurement-data assistant, but it reaches beyond its narrow construction-material description by adding broad company intelligence, contact lookup, device-based registration, and local credential storage.

Install only if you are comfortable with a China-focused procurement service that may query broad company and contact data, can create an account after consent using a MAC-derived device identifier, and stores a service API key locally. Prefer setting ZLBX_API_KEY yourself, avoid auto-registration if you do not want device-based deduplication, and review contact-data and referral behavior before using it in sensitive workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:269
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/auto-register.md:35
Finding

Persistent Hardware Fingerprint Is Collected and Transmitted for Automatic Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```powershell $mac = (Get-NetAdapter | Where-Object { $_.Status -eq 'Up' -and $_.HardwareInterface } | Sort-Object ifIndex | Select-Object -First 1).MacAddress if ($mac) { $hex = ($mac -replace '[-:]', '').ToLower() $bytes = [Text.Encoding]::UTF8.GetBytes($hex) -join ([Security.Cryptography.SHA256]::Create().ComputeHash($bytes) | ForEach-Object { $_.ToString('x2') }) } ``` The resulting data is sent to the external registration service: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json ``` ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s35" } ``` ### Technical Analysis When no API key is available, the Skill offers automatic registration. After obtaining user consent, it reads the operating-system type, processor architecture, and the MAC address of a selected physical network interface. It normalizes the MAC address, hashes it with SH ...[truncated 2603 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Bearer API Key Is Persisted Without Mandatory Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (30)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Automatic account registration based on collected device characteristics is not necessary to answer construction-material pricing queries and introduces privacy-sensitive data collection. Even with stated consent, the feature broadens the skill from read-only analysis into identity/device enrollment and credential creation, increasing abuse and compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented APIs are for broad company intelligence, contacts, competitors, and bidder discovery, which materially exceed the stated purpose of a construction material bid assistant focused on price trends and top brands. This scope drift increases the chance of unnecessary collection and use of sensitive business data, enabling surveillance or profiling workflows unrelated to the user’s requested material-pricing task.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented APIs do not support the skill’s declared purpose of construction-material price trends, top brands, and supplier lists; instead they expose bid/tender intelligence functions. This creates a dangerous capability mismatch: the agent may invoke unrelated procurement-search tools under a misleading manifest, causing unauthorized data access, overbroad querying, or deceptive behavior toward users and downstream orchestrators.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document defines an auto-registration and device/account management workflow that is unrelated to the declared purpose of a construction-material bidding assistant. This mismatch is a strong indicator of hidden capability insertion: it instructs the agent to fingerprint the host, provision accounts, persist credentials, and manage billing flows, all of which expand access and data handling far beyond what the skill needs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file directs the agent to read environment/config secrets, collect device fingerprint components, and send them to an external service to obtain and persist an API key. For a construction-material query assistant, these actions are unnecessary and privacy-invasive, and they create a path for unauthorized data collection and credential manipulation on the user's machine.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The header advertises a construction-material assistant, while the body describes a much broader national bidding-data platform. This discrepancy undermines informed consent and can cause the orchestrator or user to authorize a wider capability set than intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition is broad and ambiguous, using common material-related terms that can cause over-triggering on loosely related user queries. Over-broad activation increases the chance that the skill is invoked unnecessarily, exposing users to undeclared external calls, credential handling, or unrelated workflow logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is written as a hard requirement in Chinese and presents the skill as a Chinese-language assistant without any indication that users may choose another language. This can violate language/locale policy when no opt-in or justified locale restriction is documented.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill documents automatic API-key acquisition, device-feature collection, and persistent local storage of credentials, none of which is reflected in the manifest description of a simple query assistant. Hidden credential enrollment and local persistence materially expand the trust and privacy boundary beyond what users would reasonably expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest presents a narrow construction-material bidding assistant, but the body exposes a broad general-purpose tendering and company-intelligence platform. This capability mismatch can cause unintended invocation, over-collection, and user deception about what data and operations the skill may perform.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs use of WebSearch for broader internet enrichment, expanding from structured material-bid queries into open-web company, policy, and market research. This increases the data surface, raises prompt-injection and untrusted-content exposure, and departs from the narrow role described in the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file adds account balance and usage-inspection capabilities that are outside the stated purpose of a construction-material bidding assistant. Even though the documented APIs are not inherently unsafe and avoid exposing the API key directly, the scope expansion creates an unnecessary privilege surface and can enable unintended access to billing and account-usage information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The balance-query documentation instructs the agent to call an account endpoint using the environment API key, despite this capability being unrelated to construction-material pricing or supplier lookup. In a mismatched skill context, that creates a data-exposure risk by allowing the skill to retrieve sensitive account and billing state that users did not request and that the skill does not need to function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The daily consumption analytics capability exposes account-usage telemetry unrelated to the assistant's advertised procurement role. This unnecessarily broadens the skill's access to operational metadata, which could reveal usage patterns, call volumes, or spending behavior without a legitimate need in the declared use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs automatic expansion from a named company to all related headquarters and branch entities, followed by additional analysis, without user confirmation. This can silently broaden the dataset and query scope, causing over-collection and potentially inaccurate or privacy-sensitive aggregation beyond what the user intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The contact lookup capability exposes project contact information in a skill whose declared purpose is material pricing and supplier lookup, so the data access is not justified by task necessity. Even masked contact data can facilitate lead generation, targeting, or privacy-invasive enrichment when combined with other results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The contact lookup section discusses returning project contacts, including masked or full phone data depending on account tier, but lacks an explicit privacy warning or strict purpose limitation in this skill context. Because the skill is marketed for construction material bidding assistance, exposing contact-handling behavior here makes misuse for unsolicited outreach or personal-data harvesting more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Competitor analysis is outside the declared scope of providing material prices and major suppliers, and it supports strategic profiling rather than the advertised assistant function. In context, this broadens the assistant into corporate intelligence gathering without transparent disclosure, increasing misuse risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Potential bidder recommendation goes beyond historical unit price and top-brand lookup and can be used to influence sourcing strategies or identify targets for outreach. This is a meaningful expansion of capability beyond the user-facing description, creating hidden data use and purpose-limitation concerns.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says this skill should be used for construction-material queries and must return historical unit prices plus major suppliers, implying a narrowly scoped material sourcing assistant. This file documents additional APIs for top purchasers and multidimensional bid aggregation, which support broader market research and customer-acquisition analysis beyond the stated construction-material assistant behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file documents broad market-intelligence endpoints such as expiring-project mining and proposed-project discovery, which exceed the stated need of a construction-material pricing assistant. In context, this over-scoping increases the chance of data misuse, unauthorized competitive intelligence gathering, and least-privilege violations if the agent is routed here based on benign material-related queries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This line documents making an outbound POST request carrying collected device features to a third-party endpoint. External transmission of host-derived identifiers is sensitive on its own, and in this skill it is especially dangerous because the transfer is unrelated to the stated material-query purpose and is part of a hidden registration/fingerprinting flow.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The curl -d @file mention is not dangerous because of curl itself, but because it is part of instructions for sending locally assembled registration data to an external service. In context, it reinforces the existence of an unnecessary exfiltration path for host-derived metadata.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation contains contradictory instructions for the ch value, stating it must be s01 while examples and pseudocode use s35. In security-sensitive registration flows, such inconsistencies can misroute registrations, break auditing/attribution, and indicate the document may be stitched together from multiple contexts without proper review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.