T01 · Skill Instruction Hijacking
- Location
SKILL.md:269- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a real procurement-data assistant, but it reaches beyond its narrow construction-material description by adding broad company intelligence, contact lookup, device-based registration, and local credential storage.
Install only if you are comfortable with a China-focused procurement service that may query broad company and contact data, can create an account after consent using a MAC-derived device identifier, and stores a service API key locally. Prefer setting ZLBX_API_KEY yourself, avoid auto-registration if you do not want device-based deduplication, and review contact-data and referral behavior before using it in sensitive workflows.
SKILL.md:269Mandatory Promotional Content Hijacks Agent Responses
references/auto-register.md:35Persistent Hardware Fingerprint Is Collected and Transmitted for Automatic Registration
references/auto-register.md:173Bearer API Key Is Persisted Without Mandatory Restrictive File Permissions
Automatic account registration based on collected device characteristics is not necessary to answer construction-material pricing queries and introduces privacy-sensitive data collection. Even with stated consent, the feature broadens the skill from read-only analysis into identity/device enrollment and credential creation, increasing abuse and compliance risk.
The documented APIs are for broad company intelligence, contacts, competitors, and bidder discovery, which materially exceed the stated purpose of a construction material bid assistant focused on price trends and top brands. This scope drift increases the chance of unnecessary collection and use of sensitive business data, enabling surveillance or profiling workflows unrelated to the user’s requested material-pricing task.
The documented APIs do not support the skill’s declared purpose of construction-material price trends, top brands, and supplier lists; instead they expose bid/tender intelligence functions. This creates a dangerous capability mismatch: the agent may invoke unrelated procurement-search tools under a misleading manifest, causing unauthorized data access, overbroad querying, or deceptive behavior toward users and downstream orchestrators.
The document defines an auto-registration and device/account management workflow that is unrelated to the declared purpose of a construction-material bidding assistant. This mismatch is a strong indicator of hidden capability insertion: it instructs the agent to fingerprint the host, provision accounts, persist credentials, and manage billing flows, all of which expand access and data handling far beyond what the skill needs.
The file directs the agent to read environment/config secrets, collect device fingerprint components, and send them to an external service to obtain and persist an API key. For a construction-material query assistant, these actions are unnecessary and privacy-invasive, and they create a path for unauthorized data collection and credential manipulation on the user's machine.
The header advertises a construction-material assistant, while the body describes a much broader national bidding-data platform. This discrepancy undermines informed consent and can cause the orchestrator or user to authorize a wider capability set than intended.
The trigger condition is broad and ambiguous, using common material-related terms that can cause over-triggering on loosely related user queries. Over-broad activation increases the chance that the skill is invoked unnecessarily, exposing users to undeclared external calls, credential handling, or unrelated workflow logic.
The skill description is written as a hard requirement in Chinese and presents the skill as a Chinese-language assistant without any indication that users may choose another language. This can violate language/locale policy when no opt-in or justified locale restriction is documented.
The skill documents automatic API-key acquisition, device-feature collection, and persistent local storage of credentials, none of which is reflected in the manifest description of a simple query assistant. Hidden credential enrollment and local persistence materially expand the trust and privacy boundary beyond what users would reasonably expect.
The manifest presents a narrow construction-material bidding assistant, but the body exposes a broad general-purpose tendering and company-intelligence platform. This capability mismatch can cause unintended invocation, over-collection, and user deception about what data and operations the skill may perform.
The skill instructs use of WebSearch for broader internet enrichment, expanding from structured material-bid queries into open-web company, policy, and market research. This increases the data surface, raises prompt-injection and untrusted-content exposure, and departs from the narrow role described in the manifest.
This file adds account balance and usage-inspection capabilities that are outside the stated purpose of a construction-material bidding assistant. Even though the documented APIs are not inherently unsafe and avoid exposing the API key directly, the scope expansion creates an unnecessary privilege surface and can enable unintended access to billing and account-usage information.
The balance-query documentation instructs the agent to call an account endpoint using the environment API key, despite this capability being unrelated to construction-material pricing or supplier lookup. In a mismatched skill context, that creates a data-exposure risk by allowing the skill to retrieve sensitive account and billing state that users did not request and that the skill does not need to function.
The daily consumption analytics capability exposes account-usage telemetry unrelated to the assistant's advertised procurement role. This unnecessarily broadens the skill's access to operational metadata, which could reveal usage patterns, call volumes, or spending behavior without a legitimate need in the declared use case.
The documentation instructs automatic expansion from a named company to all related headquarters and branch entities, followed by additional analysis, without user confirmation. This can silently broaden the dataset and query scope, causing over-collection and potentially inaccurate or privacy-sensitive aggregation beyond what the user intended.
The contact lookup capability exposes project contact information in a skill whose declared purpose is material pricing and supplier lookup, so the data access is not justified by task necessity. Even masked contact data can facilitate lead generation, targeting, or privacy-invasive enrichment when combined with other results.
The contact lookup section discusses returning project contacts, including masked or full phone data depending on account tier, but lacks an explicit privacy warning or strict purpose limitation in this skill context. Because the skill is marketed for construction material bidding assistance, exposing contact-handling behavior here makes misuse for unsolicited outreach or personal-data harvesting more likely.
Competitor analysis is outside the declared scope of providing material prices and major suppliers, and it supports strategic profiling rather than the advertised assistant function. In context, this broadens the assistant into corporate intelligence gathering without transparent disclosure, increasing misuse risk.
Potential bidder recommendation goes beyond historical unit price and top-brand lookup and can be used to influence sourcing strategies or identify targets for outreach. This is a meaningful expansion of capability beyond the user-facing description, creating hidden data use and purpose-limitation concerns.
The manifest says this skill should be used for construction-material queries and must return historical unit prices plus major suppliers, implying a narrowly scoped material sourcing assistant. This file documents additional APIs for top purchasers and multidimensional bid aggregation, which support broader market research and customer-acquisition analysis beyond the stated construction-material assistant behavior.
This markdown file presents all instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue unless the constraint is explicitly justified.
The file documents broad market-intelligence endpoints such as expiring-project mining and proposed-project discovery, which exceed the stated need of a construction-material pricing assistant. In context, this over-scoping increases the chance of data misuse, unauthorized competitive intelligence gathering, and least-privilege violations if the agent is routed here based on benign material-related queries.
This line documents making an outbound POST request carrying collected device features to a third-party endpoint. External transmission of host-derived identifiers is sensitive on its own, and in this skill it is especially dangerous because the transfer is unrelated to the stated material-query purpose and is part of a hidden registration/fingerprinting flow.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
The curl -d @file mention is not dangerous because of curl itself, but because it is part of instructions for sending locally assembled registration data to an external service. In context, it reinforces the existence of an unnecessary exfiltration path for host-derived metadata.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
The documentation contains contradictory instructions for the ch value, stating it must be s01 while examples and pseudocode use s35. In security-sensitive registration flows, such inconsistencies can misroute registrations, break auditing/attribution, and indicate the document may be stitched together from multiple contexts without proper review.
No suspicious patterns detected.