Back to skill

Security audit

企业中标履历查询-业绩与履约记录

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent business-report purpose, but it needs review because it collects a hashed device identifier for auto-registration, stores an API key locally, creates shareable files with signed links, and relays vendor-controlled notices.

Install only if you are comfortable with a China-focused procurement service using your company queries, optionally collecting a MAC-derived device hash for free-trial registration, and storing a vendor API key and generated reports on disk. Prefer supplying your own API key, review any generated HTML before sharing it, and treat signed links or contact details in reports as sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
references/report-template.md:183
Finding

Mandatory Vendor Promotion and Remote-Controlled Output Injection

Content
View full analysis
知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成' ``` The instructions additionally require the Agent to relay the contents of a remotely supplied `skill_update_notice` field verbatim once per conversation. ### Technical Analysis The Skill's legitimate function is to retrieve public procurement information and produce a company-intelligence report. Mandatory advertisements, vendor branding, product referrals, monitoring promotions, and verbatim remote notices are not necessary to perform that function. These directives alter the Agent's normal output policy when the Skill is loaded. In particular, forwarding a remotely returned field verbatim creates a server-controlled content channel: the reviewed local package does not fully determine what text will subsequently appear in the user's conversation. Although the observed instructions do not explicitly disable safety controls, they systematically subordinate normal response composition to vendor-defined promotional and remote content. This is consistent with Skill instruction hijacking. ### Attack Path 1. A user invokes the Skill for a normal company-intelligence report. 2. The Agent loads the mandatory output and report-template instructions. 3. The Agent queries the vendor API. 4. Vendor promotions and referral links are appended to the report ...[truncated 857 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/auto-register.md:33
Finding

Consent-Gated Hardware Fingerprint Collection and Exfiltration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting fingerprint and host characteristics are sent to the vendor: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s125" } ``` Equivalent collection procedures are provided for macOS and Windows. ### Technical Analysis A MAC address is a stable, low-entropy hardware identifier. Applying SHA-256 does not anonymize it in the same manner as hashing a high-entropy secret because candidate MAC addresses may be enumerated or correlated. The resulting hash remains a persistent device fingerprint suitable for cross-session tracking. The workflow does require explicit user consent before running collection commands or sending the registration request. That consent gate is a meaningful safeguard, but it does not establish that hardware enumeration is the minimum privilege required for the Skill's declared function. Company-intelligence queries only require an API credential and do not inherently require access to physical network adapter identifiers. The collection is used for free-trial deduplication, which is a vendor account-management goal rather than a technical requirement for ...[truncated 1272 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:177
Finding

API Credential Persisted in Plaintext Without Required File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:167
Finding

Generated HTML Accepts Unvalidated Active URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` Risk-source URLs are rendered in the same manner: ```python src_html = ( f'来源:{esc(src)}' if src else "" ) ``` Additional profile, contact, company, and citation links are inserted using equivalent `href` construction. ### Technical Analysis HTML escaping protects the attribute syntax from quotation-mark and markup injection, but it does not make a URL safe. Values using active or unexpected schemes, including `javascript:` and some `data:` URLs, remain syntactically valid `href` targets. The input JSON may contain URLs originating from an external API or public WebSearch results. If either source is compromised, manipulated, or insufficiently validated upstream, a dangerous scheme can reach the generated report. The use of `target="_blank"` without `rel="noopener noreferrer"` also permits opener access in browser environments that do not automatically isolate new tabs. ### Attack Path 1. A malicious or compromised upstream result supplies a URL using an active scheme. 2. The Agent copies that URL into the report JSON. 3. `render_report.py` escapes characters but does not parse or allowlist the URL scheme. 4. The generated HTML contains the attacker-controlled URL in an anchor element. 5. The user opens the report and clicks the link. 6. The browser processes the active URL, potentially executing script or displaying attacker-controlled active content in the local report context. ### Impact Assessment A successful attac ...[truncated 500 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:554
Finding

Sensitive Reports Written to Predictable Paths Without Secure File Creation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (22)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file defines an automatic account lifecycle unrelated to the advertised bid-history/profile lookup purpose: it collects device fingerprints, creates accounts, persists credentials locally, and generates login/recharge links. This materially expands the skill's authority and data-handling surface, creating privacy, consent, and secret-management risks beyond what a user would reasonably expect from a company-profile query skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prose says user consent is mandatory before any collection or registration, but the pseudocode path immediately falls through to collect device features and call auto-register when no key is present. In agent implementations, executable-looking pseudocode often gets copied into real logic, so this inconsistency can lead to silent fingerprinting and account creation without informed consent.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

python
# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to write HTML reports to a local directory and references a local rendering script, which implies file-write capability, but it does not declare any corresponding tool scope or allowed-tools restrictions. This creates a least-privilege and transparency gap: an agent/runtime may grant broader filesystem access than users expect, increasing the blast radius if the skill is misused or combined with prompt injection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description is entirely framed in Chinese and says users 'must use this SKILL' for the covered task, but it does not indicate that language can be adapted to user preference. This creates a natural-language locale constraint without user opt-in, which matches the policy-violation category for language/locale issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section marked '固定输出,缺一不可' requires a specific Chinese self-introduction and example utterances whenever the user installs the skill or asks what it can do. Because it is mandatory and does not offer localization or user choice, it enforces a specific language/locale behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation explicitly enables retrieval and display of project contact phone numbers, including full numbers for paid accounts, and only constrains formatting/output behavior rather than enforcing purpose limitation, consent, authorization, or abuse prevention. In a company-intelligence and bidding context, this materially increases the risk of privacy violations, targeted solicitation, social engineering, and bulk contact harvesting by downstream agents or users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document provides fixed Chinese wording to relay to the user and frames it as text that can be forwarded verbatim. Similar mandatory Chinese user-facing phrases appear later for quota and recovery flows, with no indication that the agent should respect the user's preferred language or ask first.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This line documents sending collected device features to an external service via JSON POST. External transmission of even minimized device fingerprint data is security-relevant here because the skill is nominally for bid-history lookup, so users may not expect hardware-derived identifiers to be transmitted to a third party.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill instructs the agent to persist the received API key in ~/.zlbx/config.json and immediately reuse it for subsequent calls. Storing bearer credentials in a predictable local file increases the blast radius of local compromise, accidental disclosure, and cross-context reuse, especially when the user did not explicitly ask this skill to manage credentials.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill instructs the agent to persist the received API key in ~/.zlbx/config.json and immediately reuse it for subsequent calls. Storing bearer credentials in a predictable local file increases the blast radius of local compromise, accidental disclosure, and cross-context reuse, especially when the user did not explicitly ask this skill to manage credentials.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template title and formatting instructions require the report to be produced in Chinese, including a directive that the report be output in Markdown as written. This imposes a specific language/locale on all users without offering a language choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template instructs the agent to write a temporary JSON file, execute a local Python script, and reveal the absolute output path to the user. That expands the skill from data reporting into local file-system and subprocess operations, which can expose host environment details and create opportunities for misuse if report content or paths are attacker-influenced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template silently mandates file creation and subprocess execution as a default behavior, without explicit user warning or consent. In an agent setting, hidden side effects violate least surprise and can lead to unauthorized local writes, operational risk, and disclosure of environment-specific file paths to end users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and the entire workflow are written as a mandatory Chinese execution manual, with no indication that the user can choose another language or locale. This creates a natural-language policy concern because it effectively fixes the interaction language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow explicitly expands from bid-history verification into broad WebSearch-based background checks, which goes beyond the stated core function of analyzing bid-winning records and performance evidence. This creates scope creep that can lead the agent to collect and present unrelated sensitive reputational or legal information without a clear user need or tight relevance controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This step instructs the agent to search for lawsuits, administrative penalties, dishonesty records, and news as a standard part of the workflow, even though the skill is framed around bid-winner history and performance profiling. That broad risk-investigation behavior can surface highly sensitive adverse information and turn a procurement-history tool into a general-purpose due-diligence or reputation-screening tool without clear scope boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script intentionally renders and preserves direct-access URLs, including links described as carrying 'sk' tokens, into a self-contained HTML file meant for offline sharing and forwarding. If those links embed bearer-style access secrets, anyone who receives the report can reuse them to access company profiles, announcements, or gated contact data, turning the report into a credential-distribution artifact rather than just a presentation layer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The generated document is hardcoded as Chinese via lang='zh-CN', and the surrounding user-facing content is entirely fixed in Chinese. There is no option for the user to choose language or locale, so the skill enforces a specific locale rather than offering opt-in or selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.