Back to skill

Security audit

中标概率分析-投标胜率评估器

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a bid-analysis service, but it also handles device fingerprinting, persistent API credentials, signed links, default report files, and recharge/session flows that need careful review before installation.

Install only if you are comfortable with a Chinese bid-data service receiving project/company queries and, if you use auto-registration, device-derived identifiers. Prefer setting your own ZLBX_API_KEY through a trusted secret mechanism, review or protect ~/.zlbx/config.json, avoid sharing exported reports that contain signed sk links, and treat recharge/auto-login links as sensitive account links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:140
Finding

Mandatory Promotional Content Hijacks Normal Skill Output

Content
View full analysis
' f'
📊 报告涉及企业的完整档案与更多商机,见 知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 投标决策分析 Skill 生成
' f'
数据说明:{esc(n.get("source", "知了标讯全网招中标数据"))} · 数据缺口:{esc(gaps)}{cost}
' ) ``` ### Technical Analysis The Skill changes the agent's normal response policy by requiring an affiliated recommendation after the requested analysis. This behavior is not needed to calculate bid probability, assess competition, estimate pricing, or generate the report. The HTML ren ...[truncated 1510 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:138
Finding

Unvalidated URL Schemes Permit Dangerous Links in Generated HTML Reports

Content
View full analysis
{esc(text)}' if url else esc(text) ``` Citation URLs are passed directly to that helper: ```python rows = "".join( f'{_link(x.get("title"), x.get("url"))}' + ('(需登录主站)' if x.get("login_required") else "") + f'{esc(x.get("type", ""))}{esc(x.get("date", ""))}{esc(x.get("use", ""))}' f'' for x in items ) ``` The primary bid URL is also written directly into an `href` attribute: ```python bid_link = f'' if d.get("bid_url") else "" ``` Profile and competitor URLs reach the same unsafe sink: ```python rows = "".join( f'{esc(i.get("label"))}{_link(i.get("value"), i.get("url"))}' for i in d.get("profile", []) ) ``` ```python body = "".join( f'{_link(x.get("name"), x.get("url"))}{esc(x.get("threat", ""))}{esc(x.get("coop", ""))}{esc(x.get("wins", ""))}{esc(x.get("note", ""))}' f'' f'' for x in comps ) ``` ### Technical Analysis `xml.sax.saxutils.escape()` prevents quotation marks and markup characters from breaking out of an HTML attribute when used correctly, but it does not establish that an `href` value is safe. An attacker-controlled value can therefore use an active or une ...[truncated 1900 chars]
Remediation
View remediation
{esc(text)}' ) ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

Persisted API Key Is Not Protected by Enforced Filesystem Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个分析型技能,其核心职责应是基于全网招中标历史数据生成投标胜率与决策结论。但提供的代码仅负责把输入 JSON 按固定模板渲染成 HTML 文件,并提供打印、保存 PNG、展示引用明细、品牌页脚等前端展示功能。代码中没有网络请求、数据库访问、数据抓取、统计分析、机器学习、规则评分或任何与“评估中标概率”直接相关的实现。虽然输出页面文案围绕“投标决策分析报告”,且字段结构容纳了结论、竞对、报价、风险等内容,但这些内容都是作为输入数据被展示,而不是由该代码计算得出。因此,代码实际行为与声明的核心目的存在明显不一致:它是报告渲染器,不是中标概率评估助手。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation rule is overly broad and mandates use of this skill for a wide range of common bidding-related prompts, with language like 'must use this SKILL' even when the user does not explicitly request win-rate analysis. Overbroad routing can cause unnecessary external API calls, data sharing of project/company names, and unintended account consumption in contexts where a lighter or offline response would suffice.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This document instructs the agent to perform device fingerprint collection, automatic account registration, persistent API-key storage, and recharge/login flows that are unrelated to the stated purpose of a bid-win-rate analysis assistant. Even with a consent prompt, this expands the skill into credential and device-identity handling, increasing privacy, security, and abuse risk well beyond what users would reasonably expect from this skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs collection of local device attributes including OS, CPU architecture, and a hashed MAC address, then transmits them to an external registration endpoint. A hashed MAC is still a stable device identifier for tracking and account linkage, and this capability is not justified by a bid-analysis use case, making the surrounding context more suspicious and dangerous.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 71)May include surrounding context.

python
THREAT_COLOR = {"高": "#c0392b", "中": "#b9770e", "低": "#0d9463"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly describes writing HTML reports to a user directory, but it does not declare any tool scope such as permissions or allowed-tools. That creates a capability/visibility gap: the skill can perform filesystem writes without an explicit least-privilege declaration, making it harder for reviewers and runtime policy to constrain where and when writes occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is entirely prescriptive in Chinese and does not indicate that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs automatic account registration when no API key is present and collects device-derived identifiers such as platform, architecture, and a MAC-address hash. Even with user consent language, this expands the data collection and account lifecycle beyond what is necessary to analyze a bid, increasing privacy risk and enabling unnecessary outbound transmission of device fingerprints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file instructs users to send requests with an X-API-Key header, which involves handling sensitive credentials. The quick reference does not include any warning or caution about protecting the key, avoiding accidental disclosure, or limiting its use, despite documenting a privacy- and security-relevant behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document provides mandatory user-facing wording in Chinese and frames it as text that can be relayed verbatim to the user. Similar required Chinese output appears elsewhere in the file, with no indication that the user may choose another language or that the locale restriction is justified as region-specific behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This line describes sending collected device features to an external endpoint via JSON POST. External transmission of locally derived device identifiers is security-relevant here because the skill’s stated purpose does not justify exporting tracking-related host data, making the context materially more dangerous than ordinary API use.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L129 explicitly states that the ch field must be fixed to "s64". However, the sample request at L115 and pseudocode at L242 use "s73", which directly contradicts the instruction and could cause implementers to follow inconsistent channel attribution behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to create and modify ~/.zlbx/config.json and to persist an API key for future use. Writing authentication material into local files from a skill increases the risk of secret sprawl, accidental overwrite/merge issues, and use outside user expectations for a simple analysis assistant.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill explicitly establishes persistent local session/auth state by creating ~/.zlbx and storing an API key for reuse in subsequent operations. This increases the blast radius of compromise on the local system and exceeds what a user would expect from an analysis skill, especially when combined with automatic registration and immediate authenticated reuse.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill explicitly establishes persistent local session/auth state by creating ~/.zlbx and storing an API key for reuse in subsequent operations. This increases the blast radius of compromise on the local system and exceeds what a user would expect from an analysis skill, especially when combined with automatic registration and immediate authenticated reuse.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quota-exhaustion flow generates auto-login recharge links and drives monetization/account-binding behavior from inside the skill. This is outside the expected scope of a bid-analysis tool and introduces account-session handling and phishing-like UX risks, especially because the skill is instructing an agent to surface login links tied to account state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template not only preserves signed sk parameters but instructs doing so without any privacy or security warning, normalizing the disclosure of what appears to be an authentication-bypass or session-bearing URL component. In this skill context, reports are meant to be shared and exported, so embedding signed links materially increases the likelihood of credential-like token leakage to recipients, logs, and downstream systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires exposing full signed sk URLs to end users and preserving them verbatim in Markdown, JSON, and HTML output. If sk functions as a bearer-style access token or login-bypass signature, publishing it leaks a reusable secret that can grant unintended access, enable link sharing beyond the intended audience, and propagate sensitive authenticated URLs into logs, transcripts, and exported files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to create a local HTML file by default without a user-facing warning that a file will be written or where it will be stored. Silent file creation can violate user expectations, leave sensitive business intelligence on disk, and create privacy/compliance issues if the environment is shared or monitored.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document title and all operational instructions are written as a Chinese-only execution manual, and no part of the workflow offers the user a choice of response language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The output HTML hard-codes lang='zh-CN', which enforces a specific locale in generated content. Under the policy rule, forcing a language or locale without user opt-in is a natural-language policy violation unless the restriction is explicitly justified or configurable.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest focuses on evaluating bid-winning probability and producing decision reports. These lines document endpoints for account balance, daily consumption, registration, and recharge-link retrieval, which are billing/account operations not directly part of tender analysis.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.