Back to skill

Security audit

China Bid Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a China-market bid document generator with some overstated capabilities and dependency hygiene issues, but no evidence of hidden, destructive, persistent, or deceptive behavior.

Install only in an isolated Python environment, review generated bid documents manually, and do not provide confidential pricing, bid strategy, government project details, or private source files to web search unless you explicitly intend that external disclosure. Expect the bundled code to generate a basic Word document rather than fully implementing every advertised feature.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:7
Finding

Unpinned Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 7
Vulnerability Type: Unpinned dependencies installed from the active pip package index
Risk Level: Medium

Vulnerable Code

yaml
dependencies: "pip install python-docx fpdf2"

Technical Analysis

The skill directs users or the runtime to install python-docx and fpdf2 without pinned versions, package hashes, or an explicitly trusted package index. Dependency resolution therefore relies on mutable package releases and the current pip configuration. This makes installations non-reproducible and exposes them to compromised upstream releases, transitive-dependency compromise, or a malicious package index configured in the environment.

The embedded Python example only imports and uses python-docx; fpdf2 is not used. Installing this unnecessary dependency expands the supply-chain attack surface without supporting the demonstrated functionality.

This finding does not prove that either named package is malicious. The weakness is the unsafe and unconstrained installation process.

Attack Path

  1. A user or automation framework loads the skill and follows its dependency declaration.
  2. It executes pip install python-docx fpdf2.
  3. pip resolves the latest compatible packages and transitive dependencies through the environment's configured index.
  4. An attacker compromises a package release or dependency, or controls a configured package index and serves a malicious artifact.
  5. pip downloads and installs that artifact.
  6. Malicious installation or imported runtime code executes with the privileges of the account performing installation or running the skill.

Impact Assessment

Successful exploitation could execute arbitrary code under the installing or runtime user's privileges. Depending on those privileges, the attacker could access files and credentials available to that account, alter generated documents, tamper with the local environment, or establish further compr ...[truncated 181 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin each direct dependency to a reviewed, exact version.
  2. Lock all transitive dependencies using a generated lock file.
  3. Require cryptographic hashes, such as through pip install --require-hashes -r requirements.txt.
  4. Configure an explicitly trusted package index and prevent unexpected fallback to untrusted indexes.
  5. Scan and periodically update locked dependencies through a controlled review process.
  6. Remove fpdf2 until PDF generation is implemented and the dependency is actually required.
  7. Install dependencies in an isolated, least-privileged virtual environment rather than under an administrator or system account.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises internet search integration and PDF output, but the included code only creates and saves a local .docx file. This mismatch can mislead users and downstream agents about data flows and capabilities, causing unsafe assumptions about whether external services are contacted or whether expected output validation occurred.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill claims internet-query integration but does not warn that project information or uploaded materials may be transmitted to external services. For procurement documents, this is sensitive because bids, pricing, specifications, and government or enterprise project details may be confidential and disclosure could create compliance, confidentiality, or competitive-risk issues.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill claims batch generation and multi-source material integration, but the code only processes a single supplied project_info object into one document. This can cause operators to trust the skill for workflows involving additional files or bulk processing that are not actually implemented, increasing the risk of incorrect handling of sensitive bid materials or silent workflow failures.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad and map to ordinary writing requests, which increases the chance that the skill is invoked unexpectedly in unrelated contexts. In a bidding workflow, this can lead to accidental use of specialized templates, unintended handling of procurement data, or invocation of any future external-search behavior without the user clearly opting in.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE
FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The skill name and description define the tool entirely around Chinese bidding documents and Chinese regulatory norms, but the file does not explicitly present this as a constrained locale choice or ask the user to opt in to that locale. Because the skill is framed as a general document generator rather than an explicitly region-locked compliance tool, this can be read as imposing a specific language/locale by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.