Back to skill

Security audit

全国招标采购信息总站-中国招标网

Security checks for vulnerabilities and agentic risk

Overview

The skill’s bidding-data purpose is mostly coherent, but it asks for broad third-party API use, device fingerprinting, automatic account creation, and persistent API-key storage that users should review carefully.

Install only if you are comfortable with this vendor service receiving your bidding queries and, when no key is configured, with an explicit-consent flow that creates a trial account using device-derived information. Prefer setting ZLBX_API_KEY yourself instead of using automatic registration, review or protect ~/.zlbx/config.json if it is created, and be aware that answers may include vendor referral links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:273
Finding

Mandatory Promotional Content Alters Normal Agent Responses

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:3
Finding

Overbroad Activation Redirects Unrelated Requests to a Credentialed Third-Party Service

Content
View full analysis
This Skill must be used whenever the user is involved in any of the listed scenarios, including bidding searches, procurement notices, expiring projects, supplier recommendations, company analysis, competitor analysis, market analysis, sourcing, and channel expansion. Even if the user does not mention the service, the Skill should be used whenever the request contains terms related to bidding, procurement, winning bids, suppliers, or competitors. ``` ### Technical Analysis The activation rule claims mandatory handling of requests containing broad business terms such as procurement, suppliers, and competitors. Those concepts are not limited to requests for this specific bidding-data service. Once activated, the Skill can read an API key, invoke a metered external API, trigger registration behavior when no key exists, and append promotional content. The rule therefore increases the reach of all other Skill behaviors beyond requests where the service is clearly necessary. This is a session-goal redirection issue: an ordinary request may be transformed into a vendor-specific external API workflow merely because it contains a generic keyword. ### Attack Path 1. A user submits a request containing a generic term such as “supplier,” “procurement,” or “competitor.” 2. The broad activation instruction mandates use of this Skill even if the user did not request bidding-platform data. 3. The agent reads a configured API credential or initiates the missing-key workflow. 4. The request or derived search terms are sent to the third-party service. 5. Account quota may be consumed, and the response may include the Skill's mandatory vendor promotions. ### Impact Assessment The behavior doe ...[truncated 585 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:33
Finding

Stable Hardware Fingerprint Is Collected and Sent During Trial Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The macOS workflow performs equivalent collection: ```bash ifconfig | awk '/ether/{print $2; exit}' \ | tr -d ':' | tr 'A-Z' 'a-z' \ | shasum -a 256 | awk '{print $1}' ``` The Windows workflow reads the first active hardware adapter: ```powershell $mac = (Get-NetAdapter | Where-Object { $_.Status -eq 'Up' -and $_.HardwareInterface } | Sort-Object ifIndex | Select-Object -First 1).MacAddress if ($mac) { $hex = ($mac -replace '[-:]', '').ToLower() $bytes = [Text.Encoding]::UTF8.GetBytes($hex) -join ([Security.Cryptography.SHA256]::Create().ComputeHash($bytes) | ForEach-Object { $_.ToString('x2') }) } ``` The resulting fingerprint and host characteristics are transmitted: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json ``` ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s52" } ``` The documentation requires user consent before collection, which is a meaningful safeguard, but it does not eliminate the privacy and least-privilege concern. ### Technical Analysis A MAC address is a stable hardware-linked identifier. Applying SHA-256 does not make it anonymous because the input space is structured and sufficiently enumerable for dictionary or brute-for ...[truncated 1707 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

API Key Is Persisted Without Mandatory Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation rule is extremely broad and says the skill must be used for many common procurement, supplier, and competitor-analysis intents. Overbroad mandatory activation increases the chance the skill is invoked in situations that do not need it, expanding data exposure to the external service and making the unsafe registration/credential behaviors easier to trigger.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to collect device characteristics and automatically register an account when credentials are unavailable. That behavior exceeds the core bidding-search purpose and causes identity/account creation plus device fingerprint collection, which can expose user privacy and create unauthorized third-party accounts from the user's environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill is entirely authored as a Chinese-only experience and gives no indication that users may choose another language or locale. Under the policy, a skill should not force a specific language unless it offers user choice or clearly documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to read a local file at ~/.zlbx/config.json for credentials even though the manifest declares environment-variable-based secret usage. Accessing undeclared local credential files expands the trust boundary, may expose unrelated secrets, and bypasses the platform's explicit secret-management model.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill contains conflicting rules: one section limits auto-registration to when no key exists, while the error-handling section later recommends re-registration even if a key already exists. This inconsistency can cause the agent to create replacement accounts unnecessarily, overwrite valid credential state, and trigger repeated identity/device-registration flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest focuses on bidding/procurement search and analysis using this skill's domain dataset. This section adds a broader capability to supplement with open-web searches across company websites, media, policy sites, and industry analysis. That broader web-research behavior is not explicitly declared in the skill purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill includes account-management capabilities (balance and daily consumption queries) that are outside the declared bidding/procurement analysis purpose. Scope expansion is dangerous because it grants the agent access to operational account metadata tied to the API key, increasing the chance of unnecessary sensitive-data exposure and unauthorized use of adjacent functionality when users only intended procurement analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill exposes project contact data, including names and phone numbers, and the guidance focuses on display/upsell behavior rather than privacy, lawful basis, minimization, retention, or downstream use restrictions. In a bidding/procurement context, this can enable targeted scraping, profiling, unsolicited outreach, or abuse of personal/business contact information even if some numbers are masked for lower-tier accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural-language instructions exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains all instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in is a reportable natural-language policy concern unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill embeds an account lifecycle workflow—device fingerprint collection, automatic registration, API key retrieval, local credential persistence, and auto-login link generation—that exceeds the stated bidding-search business purpose. This broadens the trust boundary and enables the skill to collect host-derived identifiers and establish ongoing authenticated access on the user's machine, increasing privacy and credential-management risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file prescribes exact Chinese wording to present to the user and the rest of the interaction guidance is also written as mandatory Chinese output. This creates a locale policy issue because the skill does not offer the user a language choice or document that the Chinese-only behavior is justified by a region-specific constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L115 的请求示例将 ch 设为 "s52",但 L129 又明确声明 ch 字段“固定填 "s01"”。这是同一流程文档中的主动性指令冲突,可能导致实现者向不同渠道值发送注册或登录请求,与文档意图不一致。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The document instructs the agent to transmit device-derived fingerprints (platform, arch, mac_hash) to an external service during automatic registration. Even with consent language and hashing, this is still external exfiltration of host metadata outside the core bidding-query function, and the skill context makes it more concerning because users may not expect local device inspection from a procurement search assistant.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This finding is another instance of the same external transmission behavior, showing alternative implementation guidance (curl -d @file) for sending the registration payload off-host. The risk is not the serialization advice itself, but that the skill operationalizes outbound transfer of device fingerprint material and account-creation metadata to a third-party endpoint.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding points to the same credential persistence behavior: creating ~/.zlbx, merging config, storing source: auto, and reusing the API key in the active session. The security concern is durable authentication state established by the skill on the user's machine, which is broader than the expected one-off behavior of a search/analysis assistant.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding points to the same credential persistence behavior: creating ~/.zlbx, merging config, storing source: auto, and reusing the API key in the active session. The security concern is durable authentication state established by the skill on the user's machine, which is broader than the expected one-off behavior of a search/analysis assistant.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

前文所有注册与手动登录流程均使用 https://ai.zhiliaobiaoxun.com 域名,但 L211 的自动登录链接写成了 https://ai.zhiliaobiaoxun.com/auto-login?sid=<sid> 以外需核对整体站点一致性;结合 L029、L162、L215 等处反复强调固定引导地址,若该链接与实际登录入口策略不同,会使“按固定入口引导”的文档意图与执行动作偏离。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

A language or locale policy violation applies to all file types when the skill forces a specific language without user opt-in. This file's instructions and examples are entirely in Chinese, and there is no indication that users may choose another language or that the restriction is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.