T01 · Skill Instruction Hijacking
- Location
SKILL.md:273- Finding
Mandatory Promotional Content Alters Normal Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s bidding-data purpose is mostly coherent, but it asks for broad third-party API use, device fingerprinting, automatic account creation, and persistent API-key storage that users should review carefully.
Install only if you are comfortable with this vendor service receiving your bidding queries and, when no key is configured, with an explicit-consent flow that creates a trial account using device-derived information. Prefer setting ZLBX_API_KEY yourself instead of using automatic registration, review or protect ~/.zlbx/config.json if it is created, and be aware that answers may include vendor referral links.
SKILL.md:273Mandatory Promotional Content Alters Normal Agent Responses
SKILL.md:3Overbroad Activation Redirects Unrelated Requests to a Credentialed Third-Party Service
references/auto-register.md:33Stable Hardware Fingerprint Is Collected and Sent During Trial Registration
references/auto-register.md:175API Key Is Persisted Without Mandatory Restrictive File Permissions
The activation rule is extremely broad and says the skill must be used for many common procurement, supplier, and competitor-analysis intents. Overbroad mandatory activation increases the chance the skill is invoked in situations that do not need it, expanding data exposure to the external service and making the unsafe registration/credential behaviors easier to trigger.
The skill instructs the agent to collect device characteristics and automatically register an account when credentials are unavailable. That behavior exceeds the core bidding-search purpose and causes identity/account creation plus device fingerprint collection, which can expose user privacy and create unauthorized third-party accounts from the user's environment.
The skill is entirely authored as a Chinese-only experience and gives no indication that users may choose another language or locale. Under the policy, a skill should not force a specific language unless it offers user choice or clearly documents a justified region-specific constraint.
The skill directs the agent to read a local file at ~/.zlbx/config.json for credentials even though the manifest declares environment-variable-based secret usage. Accessing undeclared local credential files expands the trust boundary, may expose unrelated secrets, and bypasses the platform's explicit secret-management model.
The skill contains conflicting rules: one section limits auto-registration to when no key exists, while the error-handling section later recommends re-registration even if a key already exists. This inconsistency can cause the agent to create replacement accounts unnecessarily, overwrite valid credential state, and trigger repeated identity/device-registration flows.
The manifest focuses on bidding/procurement search and analysis using this skill's domain dataset. This section adds a broader capability to supplement with open-web searches across company websites, media, policy sites, and industry analysis. That broader web-research behavior is not explicitly declared in the skill purpose.
This skill includes account-management capabilities (balance and daily consumption queries) that are outside the declared bidding/procurement analysis purpose. Scope expansion is dangerous because it grants the agent access to operational account metadata tied to the API key, increasing the chance of unnecessary sensitive-data exposure and unauthorized use of adjacent functionality when users only intended procurement analysis.
The skill exposes project contact data, including names and phone numbers, and the guidance focuses on display/upsell behavior rather than privacy, lawful basis, minimization, retention, or downstream use restrictions. In a bidding/procurement context, this can enable targeted scraping, profiling, unsolicited outreach, or abuse of personal/business contact information even if some numbers are masked for lower-tier accounts.
This markdown file contains user-facing natural-language instructions exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file contains all instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in is a reportable natural-language policy concern unless the locale constraint is explicitly documented and justified.
The skill embeds an account lifecycle workflow—device fingerprint collection, automatic registration, API key retrieval, local credential persistence, and auto-login link generation—that exceeds the stated bidding-search business purpose. This broadens the trust boundary and enables the skill to collect host-derived identifiers and establish ongoing authenticated access on the user's machine, increasing privacy and credential-management risk.
The file prescribes exact Chinese wording to present to the user and the rest of the interaction guidance is also written as mandatory Chinese output. This creates a locale policy issue because the skill does not offer the user a language choice or document that the Chinese-only behavior is justified by a region-specific constraint.
L115 的请求示例将 ch 设为 "s52",但 L129 又明确声明 ch 字段“固定填 "s01"”。这是同一流程文档中的主动性指令冲突,可能导致实现者向不同渠道值发送注册或登录请求,与文档意图不一致。
The document instructs the agent to transmit device-derived fingerprints (platform, arch, mac_hash) to an external service during automatic registration. Even with consent language and hashing, this is still external exfiltration of host metadata outside the core bidding-query function, and the skill context makes it more concerning because users may not expect local device inspection from a procurement search assistant.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
This finding is another instance of the same external transmission behavior, showing alternative implementation guidance (curl -d @file) for sending the registration payload off-host. The risk is not the serialization advice itself, but that the skill operationalizes outbound transfer of device fingerprint material and account-creation metadata to a third-party endpoint.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
This duplicate finding points to the same credential persistence behavior: creating ~/.zlbx, merging config, storing source: auto, and reusing the API key in the active session. The security concern is durable authentication state established by the skill on the user's machine, which is broader than the expected one-off behavior of a search/analysis assistant.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding points to the same credential persistence behavior: creating ~/.zlbx, merging config, storing source: auto, and reusing the API key in the active session. The security concern is durable authentication state established by the skill on the user's machine, which is broader than the expected one-off behavior of a search/analysis assistant.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
前文所有注册与手动登录流程均使用 https://ai.zhiliaobiaoxun.com 域名,但 L211 的自动登录链接写成了 https://ai.zhiliaobiaoxun.com/auto-login?sid=<sid> 以外需核对整体站点一致性;结合 L029、L162、L215 等处反复强调固定引导地址,若该链接与实际登录入口策略不同,会使“按固定入口引导”的文档意图与执行动作偏离。
A language or locale policy violation applies to all file types when the skill forces a specific language without user opt-in. This file's instructions and examples are entirely in Chinese, and there is no indication that users may choose another language or that the restriction is intentionally limited to a Chinese-only regional context.
No suspicious patterns detected.