T01 · Skill Instruction Hijacking
- Location
SKILL.md:273- Finding
Mandatory Promotional Output Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real procurement-data integration, but it asks the agent to create accounts, fingerprint the device, persist API keys, and add referral content in ways users should review carefully before installing.
Install only if you are comfortable with this provider's account flow. Prefer setting your own ZLBX_API_KEY manually instead of auto-registration; if you use auto-registration, understand that a MAC-derived hash will be sent to the service and an API key will be stored under ~/.zlbx/config.json. Review file permissions on that config file and avoid using contact-export features for bulk outreach or attempts to reconstruct masked phone numbers.
SKILL.md:273Mandatory Promotional Output Hijacking
references/auto-register.md:175API Key Persisted Without Mandatory Permission Hardening
references/auto-register.md:7Stable Hardware Fingerprint Collected and Transmitted for Trial Registration
The skill instructs automatic API key registration and persistence to a local config file, creating and storing credentials beyond the user’s immediate query intent. This is dangerous because it can silently expand the trust boundary, leave long-lived secrets on disk, and cause users to unknowingly authorize ongoing access to third-party services.
The documented auto-registration flow collects device fingerprinting fields such as platform, architecture, and MAC-derived hash, which are not necessary for ordinary energy bid analysis. Collecting host identifiers in this context creates unnecessary privacy and tracking risk, especially when tied to account creation and persistent local state.
The trigger condition is broad, keyword-based, and lacks strong exclusion boundaries, so the skill may activate for many loosely related queries. Over-broad triggering is dangerous because it can route users into a tool with credential handling, account flows, and broader capabilities than expected.
The skill description mandates Chinese-language behavior without checking the user’s language preference. While not severe on its own, it can mislead or disadvantage users, and in security-sensitive flows such as consent, registration, and account handling, language mismatch can undermine informed consent.
The manifest positions this as a narrow energy/power bid analysis skill, but the body exposes broad cross-industry search, company intelligence, account operations, referrals, and marketing flows. This scope expansion increases the chance of unexpected data access and user deception because consumers and policy gates may permit the skill under a narrower description than what it actually does.
The skill expands into broad WebSearch-based company, industry, policy, and market analysis beyond the stated procurement-data purpose. This broadening can pull in unrelated external content, increasing data leakage and prompt-scope creep risks, especially when users expect a bounded procurement-analysis tool.
The skill includes promotional referrals and handoff logic to sibling skills and an external agent, which is unrelated to core bid analysis. This is risky because it can steer users and their data into additional systems and capabilities without clear necessity, weakening purpose limitation and increasing the chance of over-collection or unintended disclosure.
The guidance explicitly tells the agent to automatically match company names and proceed with follow-up analysis without user confirmation. In ambiguous cases this can cause analysis on the wrong legal entity or over-broaden scope to affiliates and subsidiaries, producing inaccurate or privacy-impacting results and potentially querying data for entities the user did not intend to target.
The documented API exposes project contact information, including phone numbers, for company-related bid records even though the skill’s stated purpose is bid concentration analysis for energy and power procurement. This creates unnecessary access to personal contact data and expands the skill’s data-access scope beyond need-to-know, increasing privacy, misuse, and unauthorized outreach risks.
This markdown file is written entirely in Chinese and provides no indication that other languages are supported or that Chinese is required for a region-specific compliance reason. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The manifest says this skill is an '能源电力采招分析仪' that triggers for power-grid, electricity, photovoltaic, storage, and wind-related queries, with emphasis on State Grid/Southern Grid procurement concentration analysis. However, this file documents generic market-analysis APIs and examples for unrelated domains such as AI, servers, ventilators, and large language models, indicating the skill supports broad cross-industry procurement analysis rather than a narrowly energy/power-focused capability.
The documented APIs expose broad cross-domain procurement search features, including general bid search, advanced search, expiring projects, and proposed projects, while the skill is described as energy-and-power focused. This creates a scope mismatch that can let the agent access and use capabilities beyond user-expected boundaries, increasing the risk of over-collection, unintended use, or policy circumvention through generic queries.
The file provides mandatory user-facing consent and guidance text entirely in Chinese and instructs the agent to use it before proceeding. Because the skill does not offer the user a language/locale choice or document a justified region-specific constraint, this is a natural-language locale policy issue.
The document gives conflicting instructions for the ch parameter: the example request shows "ch": "s38", while a later note says the field must be fixed to "s01", and pseudocode again uses "s38". This inconsistency can misroute registrations, break attribution, or cause agents to send unexpected data to the wrong channel, which is a real integrity and operational-security issue in an auto-registration flow.
This file instructs the agent to transmit device-derived identifiers (platform, arch, mac_hash) to an external service as part of automatic registration. Even though the MAC is hashed, it remains a persistent device fingerprint for account linkage and tracking, and the skill context explicitly enables external transmission of host-derived data after only a one-line consent prompt.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
The documentation explicitly supports using tools like curl -d @file to send the registration payload to a third-party endpoint, reinforcing a pattern of external data transmission from the local environment. In this skill context, that transmission is not core to energy bid analysis; it is an ancillary account-provisioning flow that collects and exports device fingerprints, increasing privacy and tracking risk.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
This duplicate finding points to the same persistence behavior: writing a reusable API key to a stable config file and marking it as source: "auto" so the agent can continue privileged operations automatically. In context, this is more dangerous because the credential is obtained through an automatic enrollment flow and then silently made durable for subsequent sessions.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding points to the same persistence behavior: writing a reusable API key to a stable config file and marking it as source: "auto" so the agent can continue privileged operations automatically. In context, this is more dangerous because the credential is obtained through an automatic enrollment flow and then silently made durable for subsequent sessions.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The skill mandates specific Chinese output text for recharge and link-regeneration flows, including trigger phrases the user is expected to send. This forces a specific language interaction pattern without opt-in or an explicit documented locale constraint.
The entire skill documentation, examples, parameter descriptions, and required user-facing phrases are written only in Chinese, including prescribed output text such as the recharge prompt. For a generally applicable skill, this can constitute a language/locale policy issue if users are not given an option to interact in another language.
This markdown file presents all user-facing instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.
No suspicious patterns detected.