T01 · Skill Instruction Hijacking
- Location
SKILL.md:269- Finding
Mandatory Promotional Content and Referral-Link Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill provides procurement search capabilities, but it also handles account creation, device fingerprinting, local API-key storage, account links, and promotional referrals that users should review before installing.
Install only if you are comfortable with this vendor's account workflow. Prefer configuring your own ZLBX_API_KEY instead of approving automatic registration; if you do approve it, expect a stable MAC-derived device hash to be sent to the vendor and an API key to be stored under ~/.zlbx/config.json. Review file permissions, avoid sharing generated auto-login links, and be aware that the skill may append same-vendor service referrals after answers.
SKILL.md:269Mandatory Promotional Content and Referral-Link Injection
references/auto-register.md:42Transmission of a Stable Hardware-Derived Device Fingerprint
references/auto-register.md:173Plaintext API Key Stored Without Mandatory Restrictive File Permissions
references/auto-register.md:195Temporary Auto-Login Bearer Token Exposed in Conversation Output and URL
The skill includes logic to automatically register third-party accounts and persist obtained API credentials to a local file, even though that behavior is unrelated to the stated medical bid analysis purpose. Automatic account creation plus local secret storage expands the trust boundary, risks unauthorized account actions, and can leave credentials on disk without clear user expectation or admin control.
The skill instructs collection of platform, architecture, and a MAC-derived hash as device characteristics for registration. Even with hashing, this is device-fingerprinting behavior that is unnecessary for a hospital bidding radar use case and creates privacy and tracking risk if collected or transmitted without strict necessity and governance.
The skill instructs the agent to collect device fingerprint components such as platform, CPU architecture, and a MAC-derived SHA256 hash, then transmit them for account creation. Even if hashed, the MAC-derived value is a stable device identifier and is unnecessary for a medical tender analysis skill, making this an unjustified collection of device-level telemetry with privacy and tracking implications.
The file adds a full auto-registration, account recovery, recharge, and auto-login workflow that is materially unrelated to the stated hospital tender analysis function of the skill. This expands the trust boundary from data retrieval into device identification, credential lifecycle management, and billing flows, creating unnecessary security and privacy exposure if the skill is invoked in normal use.
The skill name and operational description are entirely specified in Chinese, with no indication that users may choose another language or that the skill is restricted to a China-specific audience for compliance reasons. This can constitute a language/locale policy violation because it implicitly fixes the interaction locale without offering opt-in or justification.
The skill is presented as a narrowly scoped medical bid radar, but the implementation exposes a much broader set of capabilities including generic bidding search, company intelligence, market analysis, and account operations. This scope mismatch can cause over-collection, over-triggering, and unintended access to data or workflows users did not expect when invoking a medical-focused skill.
The trigger description activates on very broad terms such as hospital, medical, health, and checkup, without tighter scope controls. Broad triggers can invoke the skill in unrelated contexts, increasing the chance of unnecessary third-party requests, unintended data disclosure, or activation of risky auxiliary behaviors like account handling.
The file adds account-balance and usage-query capabilities that are outside the stated purpose of a medical bidding radar skill. Even though it does not directly expose the API key, it expands the skill's authority and data access surface to billing and account telemetry, creating unnecessary privilege and increasing the chance of abuse, prompt-trigger confusion, or unapproved account reconnaissance.
Including recharge guidance and account-usage support in a medical tender analysis skill is unjustified capability creep. This can be exploited to steer the agent into handling billing workflows, disclosing sensitive account state, or performing unintended support actions unrelated to hospital/vendor analysis, which broadens attack surface and violates least-privilege design.
The file exposes a broad company-intelligence surface far beyond the skill’s stated medical procurement radar purpose, including registry enrichment, competitor discovery, partner mapping, contact lookup, and bidder recommendation. This over-scoping increases the chance of unnecessary data access and misuse because an agent operating under a narrow hospital/supplier-analysis expectation could still invoke unrelated enterprise profiling capabilities.
The documentation instructs the agent to automatically match company names and proceed with follow-up queries without user confirmation, including aggregating headquarters and subsidiaries. In ambiguous-name cases this can cause the agent to analyze the wrong entities, expand scope beyond user intent, and retrieve extra company data the user did not explicitly authorize.
The contact lookup endpoint returns named project contacts and phone numbers, which is not necessary for the stated purpose of analyzing hospital procurement patterns or top suppliers. Even if some numbers are masked for lower-tier accounts, exposing contact discovery within this skill creates a clear privacy and outreach-abuse path, including targeted solicitation, deanonymization attempts, or harvesting of procurement personnel details.
The skill includes access to project contact information with only limited mention of masking and upsell behavior, but without a clear privacy warning, purpose restriction, or anti-harvesting safeguards in the skill context. In a medical procurement setting, contact details may belong to hospital or vendor staff, making privacy misuse and inappropriate outreach more sensitive than ordinary business enrichment.
The manifest says this skill is triggered for hospital/medical/health-check related searches and focuses on extracting purchasers (hospitals) and winners to analyze top supplier systems for specific hospitals. This file documents generic market-analysis APIs for arbitrary keywords, products, brands, regions, industries, and pricing trends, including non-medical examples like AI and servers, which is materially broader than the stated hospital-focused medical procurement scope.
This markdown file presents all operational instructions, parameters, and warnings exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.
This section explicitly instructs the agent to send collected device features to an external endpoint as part of automatic registration. The transmission is security-relevant because it exports host-derived identifiers to a third party in a workflow unrelated to the core skill purpose, increasing privacy and data-handling risk.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
Line L129 states the ch field must be fixed to "s01", but the earlier request example uses "ch": "s36" and the pseudocode also posts "ch": "s36". This is an active contradiction in the file’s own instructions and could change attribution behavior if followed literally.
The instructions direct the agent to create and modify a local config file under ~/.zlbx, merge content, persist API credentials, and immediately reuse them in-session. For a search/analytics skill, local credential storage and filesystem mutation are unnecessary privileged actions that increase risk of credential leakage, unauthorized persistence, and unintended side effects on the user's environment.
The instructions establish persistent local storage of API keys in ~/.zlbx/config.json and immediate reuse in the current session. Persistent credential storage by a content skill increases the chance of credential exposure, unintended long-term authorization, and cross-context misuse, especially when the skill's declared purpose does not require managing local auth state.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The instructions establish persistent local storage of API keys in ~/.zlbx/config.json and immediate reuse in the current session. Persistent credential storage by a content skill increases the chance of credential exposure, unintended long-term authorization, and cross-context misuse, especially when the skill's declared purpose does not require managing local auth state.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The skill includes logic to generate device SID values and present auto-login and recharge links, which is outside the expected scope of tender analysis and introduces session-management behavior. This can steer the agent into handling account access flows and monetization paths that should remain in a dedicated authenticated web application, not an analytics skill.
The document instructs the agent to output a fixed Chinese message when quota is exhausted, including exact wording and follow-up instructions. This imposes a specific language on the user without any opt-in or alternative locale handling, which matches the language/locale policy violation criteria.
This markdown file presents all user-facing documentation in Chinese, including headings, parameter descriptions, and examples. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.
The manifest states the skill should重点提取采购方(医院), implying hospital-centered purchaser analysis. However, the documented response example uses a government purchaser ("XX市人民政府") and the example query targets AI procurement in Beijing, suggesting a generic purchaser-ranking tool rather than one specialized for hospitals.
No suspicious patterns detected.