T01 · Skill Instruction Hijacking
- Location
SKILL.md:497- Finding
Mandatory Promotional Output Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s tender-data analysis is coherent, but its onboarding flow collects device-identifying telemetry, creates and stores API credentials locally, and injects promotional links into normal answers.
Install only if you are comfortable with this skill using an external Zhiliaobiaoxun API, reading or creating ~/.zlbx/config.json, storing an API key locally, and sending a hashed device identifier during auto-registration. Prefer configuring your own ZLBX_API_KEY manually, review file permissions on ~/.zlbx/config.json, and expect occasional promotional referral links in answers.
SKILL.md:497Mandatory Promotional Output Hijacking
references/auto-register.md:100Incomplete Disclosure of Device and Agent Telemetry
references/auto-register.md:175Plaintext API Key Persistence Without Required File Permissions
The description says the skill must be used for many broad scenarios and even when the user does not mention bidding, as long as the request involves terms like procurement, suppliers, competitors, or market share. These concepts appear in many everyday business-analysis requests, so the trigger boundary is too expansive and lacks explicit exclusions, increasing the risk of unintended invocation.
The documented auto-registration flow collects device characteristics such as platform, architecture, and a MAC-derived hash, even though the skill's advertised purpose is tender/bid analysis. Collecting host fingerprints for account creation is privacy-invasive and increases the risk of covert tracking, deanonymization, or policy violations, especially if the data is transmitted to a third-party service.
The skill instructs collection of device fingerprints, including platform, CPU architecture, and a hashed MAC-derived identifier, for service registration. Even if minimized and hashed, this is device-identifying telemetry unrelated to tender analysis and creates privacy and tracking risk, especially because it is tied to account issuance and deduplication.
This file instructs the agent to perform account creation, login-link generation, quota handling, and API-key lifecycle management, which is materially outside the advertised scope of a tender-analysis skill. Scope expansion is dangerous because users invoking an analytics skill would not reasonably expect credential provisioning and account operations, increasing the risk of unauthorized external actions and consent confusion.
The document directs the agent to persist newly obtained API keys into a local config file and immediately reuse them in-session, which conflicts with the expected behavior of a data-analysis skill. Persisting secrets locally creates durable side effects and can silently change future agent behavior, especially when the user did not expect this skill to modify local authentication state.
The skill description and operational instructions are written as mandatory Chinese-language behavior for all covered scenarios, with no indication that users may choose another language. This can violate language or locale policy when a skill implicitly forces a specific language without opt-in.
The skill is presented as a procurement-data analysis tool, but it also instructs the agent to perform account bootstrapping and persist credentials locally. That expands the trust boundary from data querying into identity provisioning and local secret storage, creating opportunities for unauthorized account creation, silent state changes on the host, and accidental exposure or misuse of API credentials.
The skill contains contradictory guidance: one section says not to surface auto-registration behavior when an existing or user-provided key is present, while error handling later instructs the agent to initiate auto-registration even if an existing key fails. This inconsistency can cause the agent to override user intent, create replacement accounts unexpectedly, or mask legitimate authentication problems by falling back to a new identity.
The manifest describes a skill centered on招中标 data analysis, but L458-L468 explicitly recommends combining WebSearch for company news, industry rankings, policy analysis, and broader internet research. That is a broader internet-intelligence capability not clearly declared in the manifest scope.
The documentation explicitly instructs the agent to automatically aggregate and analyze multiple matched companies, including subsidiaries, without user confirmation. In a company-intelligence context this can cause unauthorized scope expansion, misattribution, and privacy-sensitive overcollection, especially when a user intended a single legal entity but the system silently includes affiliated entities.
The file title and all instructional content are written entirely in Chinese, with no indication that another language is supported or that the Chinese-only restriction is intentional for a region-specific or language-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.
Reading environment variables and local config for API keys is not inherently malicious, but in this skill it introduces unrelated credential-discovery behavior beyond the tender-analysis purpose. That broadens the skill's effective privileges and can normalize secret access in a context where users expect only analytical processing.
This section explicitly directs the agent to serialize collected device features and transmit them to an external registration endpoint. External transmission of locally collected identifiers is sensitive in this context because the skill is presented as an analytics tool, not an onboarding or telemetry collector, so users may not anticipate exfiltration.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
The curl -d @file guidance is another explicit mechanism for sending locally assembled data to an external service. While the serialization advice aims to avoid malformed JSON, it still operationalizes exfiltration of device-derived data from within a skill whose declared purpose is unrelated analysis.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
Line L129 explicitly states the ch field must be fixed to "s01", but the request example uses "s53" at L115 and the pseudocode also uses "s53" at L242. This is an active contradiction in the file's own instructions and can cause the agent to implement behavior inconsistent with the documented intent.
This duplicate finding points to the same session-persistence behavior: writing and retaining API credentials in a user config file and immediately activating them for subsequent calls. In this skill context, persistent credential state increases blast radius if the local environment is shared or the user did not intend to authorize ongoing access.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding points to the same session-persistence behavior: writing and retaining API credentials in a user config file and immediately activating them for subsequent calls. In this skill context, persistent credential state increases blast radius if the local environment is shared or the user did not intend to authorize ongoing access.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The entire skill documentation is presented only in Chinese and all examples/instructions assume Chinese-language interaction, with no indication that users may choose another language. Under the stated policy, forcing a specific language without opt-in can be a locale/language policy issue.
No suspicious patterns detected.