Back to skill

Security audit

医疗大健康采招雷达-医疗招标采购网

Security checks for vulnerabilities and agentic risk

Overview

This skill provides procurement search capabilities, but it also handles account creation, device fingerprinting, local API-key storage, account links, and promotional referrals that users should review before installing.

Install only if you are comfortable with this vendor's account workflow. Prefer configuring your own ZLBX_API_KEY instead of approving automatic registration; if you do approve it, expect a stable MAC-derived device hash to be sent to the vendor and an API key to be stored under ~/.zlbx/config.json. Review file permissions, avoid sharing generated auto-login links, and be aware that the skill may append same-vendor service referrals after answers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:269
Finding

Mandatory Promotional Content and Referral-Link Injection

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:42
Finding

Transmission of a Stable Hardware-Derived Device Fingerprint

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json ``` ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s36" } ``` The macOS and Windows branches similarly obtain a physical-interface MAC address, normalize it, and calculate an unsalted SHA-256 hash before transmission. ### Technical Analysis A MAC address is a stable hardware identifier with a constrained input space. Applying unsalted SHA-256 does not make it anonymous because a recipient can enumerate likely MAC addresses, hash them, and compare the results. The resulting value also remains stable across registrations, allowing correlation of activity associated with the same physical network adapter. Reading a hardware interface and transmitting a device-derived identifier exceeds the minimum privileges needed to search bidding data. It supports the vendor's free-trial deduplication model r ...[truncated 1785 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Plaintext API Key Stored Without Mandatory Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
references/auto-register.md:195
Finding

Temporary Auto-Login Bearer Token Exposed in Conversation Output and URL

Content
View full analysis
2. Obtain: {"sid": "..."} 3. Print the following link to the user as a bare URL on its own line: https://ai.zhiliaobiaoxun.com/auto-login?sid= The link is valid for one hour. ``` The pseudocode explicitly prints the token-bearing URL: ```python def on_balance_exhausted(api_key, source): if source == "auto": sid = POST( ".../generate-device-sid", headers={"X-API-Key": api_key} )["sid"] print(f"https://ai.zhiliaobiaoxun.com/auto-login?sid={sid}") ``` ### Technical Analysis The `sid` is an authentication-bearing token used to enter an account session. The Skill embeds it in a URL query parameter and prints the complete URL into conversation output. Query-string credentials are prone to secondary disclosure through chat retention, terminal scrollback, screenshots, clipboard history, browser history, proxy logs, monitoring tools, and URL-processing telemetry. Although the token expires after one hour, it remains usable during that window unless the service also enforces one-time consumption and narrow scope. Those additional protections are not specified in the audited files. The token is generated only in a defined quota-recovery flow, so this is not covert credential theft. The weakness is unsafe delivery and exposure of a temporary bearer credential. ### Attack Path 1. An automatically registered account exhausts its quota. 2. The Agent sends the ...[truncated 1071 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill includes logic to automatically register third-party accounts and persist obtained API credentials to a local file, even though that behavior is unrelated to the stated medical bid analysis purpose. Automatic account creation plus local secret storage expands the trust boundary, risks unauthorized account actions, and can leave credentials on disk without clear user expectation or admin control.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs collection of platform, architecture, and a MAC-derived hash as device characteristics for registration. Even with hashing, this is device-fingerprinting behavior that is unnecessary for a hospital bidding radar use case and creates privacy and tracking risk if collected or transmitted without strict necessity and governance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to collect device fingerprint components such as platform, CPU architecture, and a MAC-derived SHA256 hash, then transmit them for account creation. Even if hashed, the MAC-derived value is a stable device identifier and is unnecessary for a medical tender analysis skill, making this an unjustified collection of device-level telemetry with privacy and tracking implications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file adds a full auto-registration, account recovery, recharge, and auto-login workflow that is materially unrelated to the stated hospital tender analysis function of the skill. This expands the trust boundary from data retrieval into device identification, credential lifecycle management, and billing flows, creating unnecessary security and privacy exposure if the skill is invoked in normal use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill name and operational description are entirely specified in Chinese, with no indication that users may choose another language or that the skill is restricted to a China-specific audience for compliance reasons. This can constitute a language/locale policy violation because it implicitly fixes the interaction locale without offering opt-in or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a narrowly scoped medical bid radar, but the implementation exposes a much broader set of capabilities including generic bidding search, company intelligence, market analysis, and account operations. This scope mismatch can cause over-collection, over-triggering, and unintended access to data or workflows users did not expect when invoking a medical-focused skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description activates on very broad terms such as hospital, medical, health, and checkup, without tighter scope controls. Broad triggers can invoke the skill in unrelated contexts, increasing the chance of unnecessary third-party requests, unintended data disclosure, or activation of risky auxiliary behaviors like account handling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file adds account-balance and usage-query capabilities that are outside the stated purpose of a medical bidding radar skill. Even though it does not directly expose the API key, it expands the skill's authority and data access surface to billing and account telemetry, creating unnecessary privilege and increasing the chance of abuse, prompt-trigger confusion, or unapproved account reconnaissance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Including recharge guidance and account-usage support in a medical tender analysis skill is unjustified capability creep. This can be exploited to steer the agent into handling billing workflows, disclosing sensitive account state, or performing unintended support actions unrelated to hospital/vendor analysis, which broadens attack surface and violates least-privilege design.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file exposes a broad company-intelligence surface far beyond the skill’s stated medical procurement radar purpose, including registry enrichment, competitor discovery, partner mapping, contact lookup, and bidder recommendation. This over-scoping increases the chance of unnecessary data access and misuse because an agent operating under a narrow hospital/supplier-analysis expectation could still invoke unrelated enterprise profiling capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs the agent to automatically match company names and proceed with follow-up queries without user confirmation, including aggregating headquarters and subsidiaries. In ambiguous-name cases this can cause the agent to analyze the wrong entities, expand scope beyond user intent, and retrieve extra company data the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The contact lookup endpoint returns named project contacts and phone numbers, which is not necessary for the stated purpose of analyzing hospital procurement patterns or top suppliers. Even if some numbers are masked for lower-tier accounts, exposing contact discovery within this skill creates a clear privacy and outreach-abuse path, including targeted solicitation, deanonymization attempts, or harvesting of procurement personnel details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill includes access to project contact information with only limited mention of masking and upsell behavior, but without a clear privacy warning, purpose restriction, or anti-harvesting safeguards in the skill context. In a medical procurement setting, contact details may belong to hospital or vendor staff, making privacy misuse and inappropriate outreach more sensitive than ordinary business enrichment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill is triggered for hospital/medical/health-check related searches and focuses on extracting purchasers (hospitals) and winners to analyze top supplier systems for specific hospitals. This file documents generic market-analysis APIs for arbitrary keywords, products, brands, regions, industries, and pricing trends, including non-medical examples like AI and servers, which is materially broader than the stated hospital-focused medical procurement scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all operational instructions, parameters, and warnings exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This section explicitly instructs the agent to send collected device features to an external endpoint as part of automatic registration. The transmission is security-relevant because it exports host-derived identifiers to a third party in a workflow unrelated to the core skill purpose, increasing privacy and data-handling risk.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L129 states the ch field must be fixed to "s01", but the earlier request example uses "ch": "s36" and the pseudocode also posts "ch": "s36". This is an active contradiction in the file’s own instructions and could change attribution behavior if followed literally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions direct the agent to create and modify a local config file under ~/.zlbx, merge content, persist API credentials, and immediately reuse them in-session. For a search/analytics skill, local credential storage and filesystem mutation are unnecessary privileged actions that increase risk of credential leakage, unauthorized persistence, and unintended side effects on the user's environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The instructions establish persistent local storage of API keys in ~/.zlbx/config.json and immediate reuse in the current session. Persistent credential storage by a content skill increases the chance of credential exposure, unintended long-term authorization, and cross-context misuse, especially when the skill's declared purpose does not require managing local auth state.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The instructions establish persistent local storage of API keys in ~/.zlbx/config.json and immediate reuse in the current session. Persistent credential storage by a content skill increases the chance of credential exposure, unintended long-term authorization, and cross-context misuse, especially when the skill's declared purpose does not require managing local auth state.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes logic to generate device SID values and present auto-login and recharge links, which is outside the expected scope of tender analysis and introduces session-management behavior. This can steer the agent into handling account access flows and monetization paths that should remain in a dedicated authenticated web application, not an analytics skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document instructs the agent to output a fixed Chinese message when quota is exhausted, including exact wording and follow-up instructions. This imposes a specific language on the user without any opt-in or alternative locale handling, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all user-facing documentation in Chinese, including headings, parameter descriptions, and examples. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest states the skill should重点提取采购方(医院), implying hospital-centered purchaser analysis. However, the documented response example uses a government purchaser ("XX市人民政府") and the example query targets AI procurement in Beijing, suggesting a generic purchaser-ranking tool rather than one specialized for hospitals.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.