Back to skill

Security audit

招投标尽调助手-合同流水看经营实态

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with bidding due diligence, but it also handles account registration, stores API keys, sends a stable device fingerprint, and exposes login-bypass links, so it belongs in Review before installation.

Install only if you are comfortable with vendor API usage, credit consumption, local API-key storage, auto-registration after consent, and signed report links that should not be broadly shared. Preconfiguring ZLBX_API_KEY avoids the device-fingerprint registration path, and any generated reports or auto-login URLs should be treated as sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:477
Finding

Mandatory Promotional Content Hijacks Report Output

Content
View full analysis
' f'
📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成
' ``` The associated report instructions also require fixed monitoring prompts, cross-Skill recommendations, membership upselling, and platform links to be appended to reports. ### Technical Analysis The Skill changes the Agent's output behavior by requiring promotional calls to action and external platform links in reports, regardless of whether the user requested promotional content. The HTML renderer enforces the behavior independently by hard-coding the promotional footer into every generated report. This goes beyond formatting or attribution. It systematically redirects users to vendor services and promotes recurring monitoring and paid functionality as part of an otherwise neutral due-diligence artifact. Because the behavior is both instruction-level and code-enforced, an Agent cannot produce a neutral HTML report without modifying the Skill. ### Attack Path 1. A user asks for company due diligence. 2. The Agent loads the Skill and follows its report-generation workflow. 3. The Agent generates the HTML report using `render_report.py`. 4. The renderer unconditionally inserts monitoring promotions, membership upselling, and vendor links. 5. The user receives an artifact whose output has been altered to promote external services. ### Impact Assessment The issue does not grant operating-system privileges ...[truncated 425 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:66
Finding

Stable Hardware-Derived Device Fingerprint Is Transmitted During Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s126" } ``` ### Technical Analysis When no API key is available, the Skill instructs the Agent—after obtaining user consent—to identify a physical network interface, read its MAC address, normalize it, hash it with unsalted SHA-256, and transmit the result to an external registration service. Hashing protects the raw MAC address from appearing directly in transit, but it does not make the identifier anonymous. MAC addresses have a constrained structure and include known vendor prefixes, so candidate values can be enumerated offline. The resulting hash is also stable across registrations and sessions, allowing durable device correlation. The workflow states that the value is used for trial-account deduplication. That purpose is related to registration abuse prevention, but a hardware-derived identifier is more privacy-invasive than necessary for API authentication or installation identification. ### Attack Path 1. The Skill checks the environment and local configuration for an API key. 2. No key is found. 3. The Skill asks the user to approve automatic registration. 4. After approval, the Agent reads the first eligible physical network adapter's MAC address. 5 ...[truncated 952 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Persisted API Key Lacks Mandatory Local File Permission Controls

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:168
Finding

Generated HTML Accepts Unvalidated URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` The same direct `href` construction is used for risk-source URLs, company-profile URLs, contact URLs, and comparison-report URLs. ### Technical Analysis The renderer XML-escapes URL values before placing them in `href` attributes. This prevents direct quote-based attribute breakout, but escaping does not validate the URL scheme or destination. A malicious or compromised upstream API response, WebSearch result, or manually constructed report JSON can therefore supply values such as: ```text javascript:... data:text/html,... file:... ``` These values remain syntactically valid after escaping. When a user opens the generated report and clicks the link, the browser may execute or navigate to attacker-controlled content, depending on the scheme and browser security policy. The use of `target="_blank"` without `rel="noopener noreferrer"` also omits a standard defense against opener-based manipulation in environments where implicit isolation is not enforced. ### Attack Path 1. An upstream API record, WebSearch result, or report JSON field contains a crafted non-HTTP URL. 2. The renderer passes the URL to `_link` or another direct anchor construction. 3. `esc()` encodes markup-sensitive characters but leaves the dangerous scheme intact. 4. The generated self-contained HTML report is opened or shared. 5. A user clicks the malicious link. 6. The browser navigates to or executes content associated with the unsafe scheme. ### Impact Assessment Exploitation requires user in ...[truncated 601 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (31)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file instructs the agent to perform account onboarding, collect device-derived identifiers, register users with a remote service, persist API credentials locally, and later drive recharge/login flows. That behavior is outside the stated purpose of a bidding due-diligence skill, materially expands the skill’s privileges, and creates a path for unexpected credential handling and external data transfer under the guise of normal skill execution.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly instructs the agent to display phone numbers exactly as returned, including full numbers for privileged accounts, which is direct disclosure of personal contact data. In the context of a due-diligence skill, this exceeds necessity, increases privacy exposure, and can be abused for unsolicited outreach, harassment, or data scraping at scale.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

python
# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill performs local file writing to generate HTML reports, but it does not declare an explicit tool/permission scope limiting that capability. Undeclared write access increases the blast radius of prompt-injection or logic mistakes, because the agent may write files without a clearly constrained contract visible to reviewers or users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation rules are very broad and instruct the system to use this skill even when the user did not explicitly request due diligence, covering many generic investment or cooperation discussions. Over-broad triggering can cause unnecessary external calls, unintended data processing, unexpected cost incurrence, and accidental use of credentialed capabilities in contexts where the user only wanted general advice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill goes beyond due-diligence lookups by initiating account registration flows when no API key is present. Even with a consent prompt, this expands the skill into identity/account lifecycle actions and external data submission, which creates privacy, consent, and abuse risks if the gate is bypassed or misunderstood.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The mandated self-introduction content is fully specified in Chinese and presented as fixed output, with no indication that the user may choose another language. This can violate language/locale policy when interacting with users who did not opt into Chinese responses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explicitly instructs use of an X-API-Key header and says returned URLs contain sk login-bypass signatures that must be output unchanged, but it does not include any warning to treat those credentials and signed links as secrets. In an agent skill context, this increases the chance that downstream agents, logs, transcripts, or end users will inadvertently expose reusable authentication material or privileged URLs, enabling unauthorized access or quota abuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a due-diligence/reporting assistant, but the referenced document operationalizes account creation and monetization workflows instead. This mismatch is dangerous because it can cause users or agents to approve actions they would not expect from a business-analysis skill, reducing informed consent and masking sensitive side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document provides required user-facing copy in Chinese and directs the agent to use it when seeking consent and guiding the user. There is no indication that the user may choose another language or that this locale restriction is justified as region-specific policy, which creates a natural-language policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This guidance explicitly instructs the agent to serialize collected device features and send them to an external endpoint for automatic account registration. Even though the file claims minimization and consent requirements, it still operationalizes outbound transmission of device-linked identifiers from within a skill whose declared business purpose does not require such exfiltration.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The curl -d guidance is another concrete path for sending collected device-derived data to a third-party service. The risk is not the serialization method itself, but that the skill contains actionable instructions to exfiltrate local environment-derived information for account creation unrelated to the advertised task.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding points to the same credential persistence behavior: writing API keys under ~/.zlbx/config.json and using them for subsequent requests. In the context of a due-diligence skill, hidden session persistence is especially risky because it extends access beyond the immediate task and can outlive user awareness.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding points to the same credential persistence behavior: writing API keys under ~/.zlbx/config.json and using them for subsequent requests. In the context of a due-diligence skill, hidden session persistence is especially risky because it extends access beyond the immediate task and can outlive user awareness.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill mandates exact Chinese output for recharge guidance and recognizes a Chinese trigger phrase such as “重新生成充值链接,” but does not offer equivalent behavior in the user's preferred language. This can violate language/locale policy because the skill implicitly forces one language for operational interaction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template explicitly requires preserving and sharing API-returned URLs containing sk免登录 parameters, which function as access-bearing tokens. Embedding these links in reports broadens token exposure to anyone who receives, forwards, logs, or screenshots the report, potentially granting unintended access beyond the immediate due-diligence use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Requiring the agent to preserve sk login-bypass parameters in shared links, while giving no warning that these URLs are sensitive, encourages unsafe redistribution of access-bearing links. In a due-diligence context, reports are likely to be shared internally or externally, making silent token propagation especially risky and increasing the chance of unauthorized viewing or continued access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to run a local Python script by default to generate HTML output, introducing an execution side effect unrelated to simply drafting a due-diligence report. Any default file generation or script invocation expands the attack surface by enabling local code execution paths, file writes, dependency abuse, and misuse in contexts where the user only asked for conversational output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template mandates exporting an HTML report to a local filesystem path and then disclosing the absolute path to the user without warning. This can leak environmental details such as usernames, home directory structure, or storage conventions, and normalizes side-effectful file creation that may expose sensitive report contents to other local users or systems.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow tells the agent to output company-page URLs 'with sk' unchanged, which strongly suggests inclusion of an access-scoped token or secret-bearing parameter in normal responses. Emitting such links into chat can leak credentials to end users, logs, downstream integrations, screenshots, or shared transcripts, enabling unauthorized access or replay.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section repeats the instruction to include announcement links carrying 'sk' verbatim, creating a systematic credential-leak pattern rather than an isolated mistake. Repeated disclosure increases the chance that scoped access tokens are copied, indexed, logged, or shared broadly outside the intended trust boundary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow adds a contact-lookup step that explicitly serves as a conversion hook and exposes project contacts on request, which goes beyond the stated due-diligence function into lead generation. That creates a privacy and purpose-limitation risk by encouraging disclosure of personal contact data unrelated to the minimum information needed for diligence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow instructs the agent to reveal full phone numbers to certain users without any visible privacy notice, lawful-use warning, or restriction in the skill description. Even if the backend gates access by account tier, the skill still operationalizes disclosure of personal contact data and can facilitate misuse or non-compliant processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.