Back to skill

Security audit

能源电力采招分析仪-电力招标网

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real procurement-data integration, but it asks the agent to create accounts, fingerprint the device, persist API keys, and add referral content in ways users should review carefully before installing.

Install only if you are comfortable with this provider's account flow. Prefer setting your own ZLBX_API_KEY manually instead of auto-registration; if you use auto-registration, understand that a MAC-derived hash will be sent to the service and an API key will be stored under ~/.zlbx/config.json. Review file permissions on that config file and avoid using contact-export features for bulk outreach or attempts to reconstruct masked phone numbers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:273
Finding

Mandatory Promotional Output Hijacking

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

API Key Persisted Without Mandatory Permission Hardening

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/auto-register.md:7
Finding

Stable Hardware Fingerprint Collected and Transmitted for Trial Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` macOS collection logic: ```bash ifconfig | awk '/ether/{print $2; exit}' \ | tr -d ':' | tr 'A-Z' 'a-z' \ | shasum -a 256 | awk '{print $1}' ``` The resulting value is transmitted as follows: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s38" } ``` ### Technical Analysis The workflow derives a stable identifier from a physical network adapter's MAC address and transmits it to a remote registration service together with platform, architecture, Agent metadata, Skill version, and channel attribution. Hashing a MAC address does not make it anonymous. MAC addresses have limited entropy and known vendor prefixes, and the same normalized address always produces the same SHA-256 value. The hash can therefore act as a persistent device identifier and may be correlated across registration attempts. If an observer has a candidate MAC address, the hash can also be verified offline. The audited workflow includes meaningful mitigations: - It requires user consent before collection. - It does not transmit the raw MAC address. - It explicitly prohibits collecting hostname, username, home path, and file ...[truncated 1823 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs automatic API key registration and persistence to a local config file, creating and storing credentials beyond the user’s immediate query intent. This is dangerous because it can silently expand the trust boundary, leave long-lived secrets on disk, and cause users to unknowingly authorize ongoing access to third-party services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented auto-registration flow collects device fingerprinting fields such as platform, architecture, and MAC-derived hash, which are not necessary for ordinary energy bid analysis. Collecting host identifiers in this context creates unnecessary privacy and tracking risk, especially when tied to account creation and persistent local state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger condition is broad, keyword-based, and lacks strong exclusion boundaries, so the skill may activate for many loosely related queries. Over-broad triggering is dangerous because it can route users into a tool with credential handling, account flows, and broader capabilities than expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description mandates Chinese-language behavior without checking the user’s language preference. While not severe on its own, it can mislead or disadvantage users, and in security-sensitive flows such as consent, registration, and account handling, language mismatch can undermine informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest positions this as a narrow energy/power bid analysis skill, but the body exposes broad cross-industry search, company intelligence, account operations, referrals, and marketing flows. This scope expansion increases the chance of unexpected data access and user deception because consumers and policy gates may permit the skill under a narrower description than what it actually does.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill expands into broad WebSearch-based company, industry, policy, and market analysis beyond the stated procurement-data purpose. This broadening can pull in unrelated external content, increasing data leakage and prompt-scope creep risks, especially when users expect a bounded procurement-analysis tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes promotional referrals and handoff logic to sibling skills and an external agent, which is unrelated to core bid analysis. This is risky because it can steer users and their data into additional systems and capabilities without clear necessity, weakening purpose limitation and increasing the chance of over-collection or unintended disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guidance explicitly tells the agent to automatically match company names and proceed with follow-up analysis without user confirmation. In ambiguous cases this can cause analysis on the wrong legal entity or over-broaden scope to affiliates and subsidiaries, producing inaccurate or privacy-impacting results and potentially querying data for entities the user did not intend to target.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented API exposes project contact information, including phone numbers, for company-related bid records even though the skill’s stated purpose is bid concentration analysis for energy and power procurement. This creates unnecessary access to personal contact data and expands the skill’s data-access scope beyond need-to-know, increasing privacy, misuse, and unauthorized outreach risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is written entirely in Chinese and provides no indication that other languages are supported or that Chinese is required for a region-specific compliance reason. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says this skill is an '能源电力采招分析仪' that triggers for power-grid, electricity, photovoltaic, storage, and wind-related queries, with emphasis on State Grid/Southern Grid procurement concentration analysis. However, this file documents generic market-analysis APIs and examples for unrelated domains such as AI, servers, ventilators, and large language models, indicating the skill supports broad cross-industry procurement analysis rather than a narrowly energy/power-focused capability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented APIs expose broad cross-domain procurement search features, including general bid search, advanced search, expiring projects, and proposed projects, while the skill is described as energy-and-power focused. This creates a scope mismatch that can let the agent access and use capabilities beyond user-expected boundaries, increasing the risk of over-collection, unintended use, or policy circumvention through generic queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file provides mandatory user-facing consent and guidance text entirely in Chinese and instructs the agent to use it before proceeding. Because the skill does not offer the user a language/locale choice or document a justified region-specific constraint, this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document gives conflicting instructions for the ch parameter: the example request shows "ch": "s38", while a later note says the field must be fixed to "s01", and pseudocode again uses "s38". This inconsistency can misroute registrations, break attribution, or cause agents to send unexpected data to the wrong channel, which is a real integrity and operational-security issue in an auto-registration flow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This file instructs the agent to transmit device-derived identifiers (platform, arch, mac_hash) to an external service as part of automatic registration. Even though the MAC is hashed, it remains a persistent device fingerprint for account linkage and tracking, and the skill context explicitly enables external transmission of host-derived data after only a one-line consent prompt.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The documentation explicitly supports using tools like curl -d @file to send the registration payload to a third-party endpoint, reinforcing a pattern of external data transmission from the local environment. In this skill context, that transmission is not core to energy bid analysis; it is an ancillary account-provisioning flow that collects and exports device fingerprints, increasing privacy and tracking risk.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicate finding points to the same persistence behavior: writing a reusable API key to a stable config file and marking it as source: "auto" so the agent can continue privileged operations automatically. In context, this is more dangerous because the credential is obtained through an automatic enrollment flow and then silently made durable for subsequent sessions.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicate finding points to the same persistence behavior: writing a reusable API key to a stable config file and marking it as source: "auto" so the agent can continue privileged operations automatically. In context, this is more dangerous because the credential is obtained through an automatic enrollment flow and then silently made durable for subsequent sessions.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill mandates specific Chinese output text for recharge and link-regeneration flows, including trigger phrases the user is expected to send. This forces a specific language interaction pattern without opt-in or an explicit documented locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The entire skill documentation, examples, parameter descriptions, and required user-facing phrases are written only in Chinese, including prescribed output text such as the recharge prompt. For a generally applicable skill, this can constitute a language/locale policy issue if users are not given an option to interact in another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all user-facing instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.