Back to skill

Security audit

中标结果查询与竞争分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it needs Review because it handles persistent credentials, device-derived registration, login-bypass links, contact data, and generated HTML with unsafe link rendering.

Install only if you are comfortable with this provider storing a persistent API key locally, using a device-derived hash for automatic trial registration, and placing signed login-bypass links in reports. Avoid forwarding generated HTML or raw report links outside trusted recipients, and treat any contact phone data as sensitive business/personal data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
references/report-template.md:191
Finding

Mandatory Promotional Content Alters Agent Responses and Generated Reports

Content
View full analysis
知了标讯' '全网招中标大数据 · zhiliaobiaoxun.com' ) ``` ```python f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成' ``` ### Technical Analysis The Skill requires the agent to append fixed monitoring promotions, related-Skill recommendations, commercial platform links, and branding to normal results. These requirements are not limited to information necessary to complete company analysis. They therefore alter the agent's response objective by turning user-requested analysis and exported reports into a persistent promotional channel. The behavior does not grant operating-system privileges or execute arbitrary code. Its security impact concerns response integrity, user autonomy, and unauthorized steering toward external services. The effect is stable because the instructions apply whenever the Skill generates a report, rather than only when a user asks for product recommendations. ### Attack Path 1. A user loads the Skill and requests an ordinary company analysis. 2. The Skill performs the requested data queries. 3. ...[truncated 705 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:66
Finding

Stable Hardware-Derived Device Fingerprint Is Collected and Sent to a Remote Registration Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting hardware-derived identifier is sent to a remote service: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s134" } ``` ### Technical Analysis A MAC address is a stable, low-entropy hardware identifier. Applying an unkeyed SHA-256 hash does not make it anonymous because the possible source values can be enumerated or correlated, and the same normalized MAC address consistently produces the same hash. The Skill uses this identifier for free-trial deduplication. However, reading a physical network-interface address and transmitting a deterministic hardware fingerprint exceeds the minimum local access necessary to create an API account. A random, locally generated installation identifier could support rate limiting or trial deduplication with less privacy impact. The implementation includes meaningful mitigations: - Registration is gated on the absence of an environment or configuration API key. - The instructions require explicit user consent before collection. - Hostname, username, home path, and local file contents ...[truncated 1406 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_report.py:86
Finding

Generated HTML Accepts Unvalidated URL Schemes and Does Not Escape Attribute Quotes

Content
View full analysis
str: return _esc(str(s if s is not None else "")) ``` ```python def _link(text, url): return f'{esc(text)}' if url else esc(text) ``` Other report sections use the same pattern directly: ```python src_html = ( f'来源:{esc(src)}' if src else "" ) ``` ```python inner += ( f'
公司完整档案(业务词云/联系人/合作图谱免登录直达):' f'{esc(prof["url"])}
' ) ``` ### Technical Analysis `xml.sax.saxutils.escape()` escapes `&`, `<`, and `>` by default, but it does not escape double or single quotation marks unless an additional entity map is supplied. The result is inserted into double-quoted `href` attributes. Consequently, a crafted URL containing a quotation mark can terminate the `href` attribute and inject a new HTML event-handler attribute. For example, a source value structurally equivalent to: ```text https://example.invalid/" onmouseover="alert(document.domain) ``` can become an anchor with an attacker-controlled `onmouseover` handler. Even without quote injection, the renderer does not validate URL schemes. Values such as `javascript:` or unsafe `data:` URLs remain clickable. Report URLs can originate from API records, citations, company profiles, contact-note links, and WebSearch risk sources. A malicious or compromised upstream source could therefore place executable browser content into a locally generated report. The fixed `target="_blank"` links also omit `rel="noopener noreferrer"`, which can expose the opener page to the destination in browsers where opener isolati ...[truncated 1336 chars]
Remediation
View remediation
str: return escape(str(value if value is not None else ""), quote=False) def esc_attr(value) -> str: return escape(str(value if value is not None else ""), quote=True) ``` 5. Centralize link construction so that no report section interpolates URLs directly. 6. Return plain escaped text, rather than an anchor, when URL validation fails. 7. Add `rel="noopener noreferrer"` to every `target="_blank"` anchor. 8. Add a restrictive Content Security Policy to the generated HTML. Because the report currently contains inline JavaScript, move that script to a nonce- or hash-authorized block, or remove it where practical. 9. Add automated tests covering quotation marks, control characters, `javascript:`, mixed-case schemes, encoded schemes, protocol-relative URLs, and malformed hostnames. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码的实际职责是“将企业情报报告 JSON 渲染成 HTML”,属于展示层/报表导出工具。它根据输入 JSON 条件性渲染单公司或双公司版式,生成 HTML 文件,并提供打印、保存长图等前端交互。这与声明中的核心用途——查询全网招投标数据、识别竞对、分析竞争格局、输出背调结论——存在明显差异。虽然渲染内容的字段名称与声明中的报告结构高度相关,说明它服务于该技能的报告输出环节,但该代码片段本身并不实现所宣称的核心分析与检索能力,因此就“描述是否准确代表该代码块实际行为”而言,属于不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document embeds a full account lifecycle workflow—device-based registration, account recovery guidance, API key persistence, and recharge/login flows—inside a skill whose declared purpose is bidding and competitive analysis. That materially expands the skill's authority and creates an unnecessary pathway for collecting device identifiers, creating remote accounts, and steering users into commercial account actions unrelated to the core analysis task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires preserving and sharing full URLs containing sk login-bypass parameters. These tokenized links are effectively bearer secrets; exposing them in chat output or exported reports can grant unintended access to protected pages if forwarded, logged, or indexed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Requiring raw sk login-bypass parameters in shared links without any warning treats sensitive access URLs as ordinary content. In this skill context, reports are meant to be shareable; embedding bearer-style access tokens in them materially increases the chance of accidental credential leakage through forwarding, screenshots, logs, or exported HTML.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

python
# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly states it will write reports to the local filesystem (~/zlbx-company-intel-files/) and generate HTML output, but it does not declare any tool scope or allowed-tools boundary for file write capability. In an agent environment, undeclared write capability weakens least-privilege controls, increases the chance of unintended file creation/modification, and makes review of side effects harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs the agent to output signed sk URLs verbatim and notes they provide login-free access. These are effectively bearer links: anyone who receives or leaks them may access resources without normal authentication, enabling unintended disclosure and link sharing beyond the authorized session.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exposes a tool for retrieving and displaying project contact phone numbers, but the stated purpose of the skill is bid-award lookup and competitive analysis. That creates unnecessary access to personal contact data beyond the core business need, increasing the risk of privacy violations, misuse for unsolicited outreach, and over-collection of sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents retrieval and display of project contact phone numbers, including instructions to show the returned number as-is. This operationalizes access to personal contact data without any warning, consent model, or usage restriction, making privacy abuse and non-compliant processing more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to collect platform, architecture, and a hashed MAC-derived identifier, then transmit them to a remote service to create an account. Even with some minimization and consent language, this is unrelated to the natural scope of competitive bidding analysis and introduces privacy, tracking, and covert onboarding risk if the agent follows it automatically.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This section explicitly directs the agent to serialize and POST locally collected device features to an external endpoint. In context, that is a real external data transmission path involving persistent device-linked identifiers, and it becomes more dangerous because it is embedded in a non-authentication skill where users may not expect outbound account enrollment behavior.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The curl example is another concrete mechanism for sending collected device information to a remote service. The risk is not the serialization advice itself but that the skill operationalizes outbound transfer of local identifiers for remote account creation, which exceeds the expected trust boundary of a competitive-analysis assistant.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding points to the same persistent credential behavior: creating ~/.zlbx, merging config, storing source metadata, and reusing the key immediately. In context, persistent auth state inside an analysis skill is an unjustified expansion of capability that can silently enable ongoing remote access beyond the user's immediate request.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding points to the same persistent credential behavior: creating ~/.zlbx, merging config, storing source metadata, and reusing the key immediately. In context, persistent auth state inside an analysis skill is an unjustified expansion of capability that can silently enable ongoing remote access beyond the user's immediate request.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The balance-exhaustion logic generates a device SID and presents an auto-login/recharge link, which is a monetization and account-management feature rather than a bidding-analysis capability. Embedding this in the skill increases the chance that an analysis-oriented agent can be turned into a funnel for persistent authentication and billing actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prescribed user message is written as mandatory output text in Chinese, and the document does not offer a user opt-in or alternative locale. This creates a natural-language locale policy issue because the skill directs the agent to communicate in a specific language regardless of the user's preferences.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template directs the agent to perform a local side effect by writing JSON to disk and executing a local Python script as part of normal report generation. That exceeds a pure reporting/template role and creates an execution surface where untrusted report content can flow into file creation and local tooling, increasing risk of unintended code execution paths, unsafe file handling, or environment exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template makes HTML export the default behavior and instructs the agent to reveal an absolute local filesystem path to the user. This creates unnecessary side effects and may disclose host environment details such as directory structure, usernames, or storage conventions, which are unrelated to the analysis task and can aid follow-on attacks or privacy leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow explicitly instructs the agent to disclose contact phone details, including full numbers for some account tiers, based only on a user request. Even though the numbers may come from the backend and masking is preserved for free users, this still operationalizes distribution of personal contact data without any verification of requester authorization, purpose limitation, consent, or user-facing privacy warning, creating a clear privacy and data-protection risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script explicitly documents and renders raw links that include an authentication-like 'sk' parameter, then encourages printing/forwarding/sharing of the generated HTML. Because these links are embedded directly into offline-shareable reports without any warning, recipients may gain unintended access via bearer-style URLs, causing token leakage and unauthorized report or account-scoped data access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The document is entirely written in Chinese and provides no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-only locale. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generated document sets lang='zh-CN' and all user-facing report text is fixed in Chinese, but the file does not offer any language selection or explain that it is intentionally limited to a China-specific audience. This is a natural-language locale policy issue because the skill forces a specific language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.