Back to skill

Security audit

AI招投标分析师-全网招中标智能分析

Security checks for vulnerabilities and agentic risk

Overview

The skill’s tender-data analysis is coherent, but its onboarding flow collects device-identifying telemetry, creates and stores API credentials locally, and injects promotional links into normal answers.

Install only if you are comfortable with this skill using an external Zhiliaobiaoxun API, reading or creating ~/.zlbx/config.json, storing an API key locally, and sending a hashed device identifier during auto-registration. Prefer configuring your own ZLBX_API_KEY manually, review file permissions on ~/.zlbx/config.json, and expect occasional promotional referral links in answers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:497
Finding

Mandatory Promotional Output Hijacking

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/auto-register.md:100
Finding

Incomplete Disclosure of Device and Agent Telemetry

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

Plaintext API Key Persistence Without Required File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill must be used for many broad scenarios and even when the user does not mention bidding, as long as the request involves terms like procurement, suppliers, competitors, or market share. These concepts appear in many everyday business-analysis requests, so the trigger boundary is too expansive and lacks explicit exclusions, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented auto-registration flow collects device characteristics such as platform, architecture, and a MAC-derived hash, even though the skill's advertised purpose is tender/bid analysis. Collecting host fingerprints for account creation is privacy-invasive and increases the risk of covert tracking, deanonymization, or policy violations, especially if the data is transmitted to a third-party service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs collection of device fingerprints, including platform, CPU architecture, and a hashed MAC-derived identifier, for service registration. Even if minimized and hashed, this is device-identifying telemetry unrelated to tender analysis and creates privacy and tracking risk, especially because it is tied to account issuance and deduplication.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file instructs the agent to perform account creation, login-link generation, quota handling, and API-key lifecycle management, which is materially outside the advertised scope of a tender-analysis skill. Scope expansion is dangerous because users invoking an analytics skill would not reasonably expect credential provisioning and account operations, increasing the risk of unauthorized external actions and consent confusion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document directs the agent to persist newly obtained API keys into a local config file and immediately reuse them in-session, which conflicts with the expected behavior of a data-analysis skill. Persisting secrets locally creates durable side effects and can silently change future agent behavior, especially when the user did not expect this skill to modify local authentication state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and operational instructions are written as mandatory Chinese-language behavior for all covered scenarios, with no indication that users may choose another language. This can violate language or locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a procurement-data analysis tool, but it also instructs the agent to perform account bootstrapping and persist credentials locally. That expands the trust boundary from data querying into identity provisioning and local secret storage, creating opportunities for unauthorized account creation, silent state changes on the host, and accidental exposure or misuse of API credentials.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill contains contradictory guidance: one section says not to surface auto-registration behavior when an existing or user-provided key is present, while error handling later instructs the agent to initiate auto-registration even if an existing key fails. This inconsistency can cause the agent to override user intent, create replacement accounts unexpectedly, or mask legitimate authentication problems by falling back to a new identity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes a skill centered on招中标 data analysis, but L458-L468 explicitly recommends combining WebSearch for company news, industry rankings, policy analysis, and broader internet research. That is a broader internet-intelligence capability not clearly declared in the manifest scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly instructs the agent to automatically aggregate and analyze multiple matched companies, including subsidiaries, without user confirmation. In a company-intelligence context this can cause unauthorized scope expansion, misattribution, and privacy-sensitive overcollection, especially when a user intended a single legal entity but the system silently includes affiliated entities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and all instructional content are written entirely in Chinese, with no indication that another language is supported or that the Chinese-only restriction is intentional for a region-specific or language-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Reading environment variables and local config for API keys is not inherently malicious, but in this skill it introduces unrelated credential-discovery behavior beyond the tender-analysis purpose. That broadens the skill's effective privileges and can normalize secret access in a context where users expect only analytical processing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This section explicitly directs the agent to serialize collected device features and transmit them to an external registration endpoint. External transmission of locally collected identifiers is sensitive in this context because the skill is presented as an analytics tool, not an onboarding or telemetry collector, so users may not anticipate exfiltration.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The curl -d @file guidance is another explicit mechanism for sending locally assembled data to an external service. While the serialization advice aims to avoid malformed JSON, it still operationalizes exfiltration of device-derived data from within a skill whose declared purpose is unrelated analysis.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Line L129 explicitly states the ch field must be fixed to "s01", but the request example uses "s53" at L115 and the pseudocode also uses "s53" at L242. This is an active contradiction in the file's own instructions and can cause the agent to implement behavior inconsistent with the documented intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding points to the same session-persistence behavior: writing and retaining API credentials in a user config file and immediately activating them for subsequent calls. In this skill context, persistent credential state increases blast radius if the local environment is shared or the user did not intend to authorize ongoing access.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding points to the same session-persistence behavior: writing and retaining API credentials in a user config file and immediately activating them for subsequent calls. In this skill context, persistent credential state increases blast radius if the local environment is shared or the user did not intend to authorize ongoing access.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill documentation is presented only in Chinese and all examples/instructions assume Chinese-language interaction, with no indication that users may choose another language. Under the stated policy, forcing a specific language without opt-in can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.