Back to skill

Security audit

企业背调助手-给个公司名出份报告

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the advertised company due-diligence work, but its account setup collects a MAC-derived device identifier and stores an API key locally, so it needs Review before installation.

Install only if you are comfortable using Zhiliaobiaoxun's external service, sending company queries to it, and either providing an API key or explicitly approving trial registration that transmits a hashed MAC-derived identifier. Review local credential and report file permissions before use, and avoid generating reports with sensitive contacts on shared machines.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:475
Finding

Mandatory Promotional Content and Vendor Referral Injection

Content
View full analysis
' f'
📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成
' ``` The associated Skill instructions require fixed promotional material in several contexts, including installation introductions, report endings, monitoring offers, other Skill recommendations, and links to the vendor’s commercial services. ### Technical Analysis The Skill changes the agent’s output policy by requiring promotional content and vendor referral links that are not necessary to answer a company-background request. The instructions describe some of this material as fixed or mandatory, while the renderer hard-codes it into every generated HTML report. Because the advertising is implemented both as instructions and executable rendering logic, the user cannot reliably suppress it by requesting a neutral report. This is a form of instruction hijacking: loading the Skill imposes a persistent commercial output objective in addition to the user’s actual research objective. ### Attack Path 1. The user installs or loads the Skill. 2. The user requests a company report or asks what the Skill does. 3. Mandatory response-template instructions activate. 4. The agent adds vendor promotions, cross-Skill recommendations, monitoring offers, or membership guidance. 5. When an HTML report is generated, the renderer unconditionally embeds vendor calls to action and external links. 6. The generated artifact therefore promotes unrelated services r ...[truncated 501 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:43
Finding

Hardware-Derived Device Fingerprint Transmitted During Automatic Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting identifier is included in an external registration request: ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s119" } ``` ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json ``` ### Technical Analysis The automatic-registration workflow identifies a physical network interface, reads its MAC address, normalizes it, computes a SHA-256 hash, and sends that hash together with operating-system and CPU-architecture information to an external service. A hash of a MAC address remains a stable hardware-derived identifier. SHA-256 prevents immediate disclosure of the original text but does not make the value anonymous. MAC addresses have a constrained structure and can be correlated across registrations or tested against candidate values. The workflow does include a meaningful mitigation: registration is entered only when no configured API key exists, and the instructions require explicit user consent before collection. Nevertheless, the fingerprint is not required to perform company-background research; it serves the vendor’s trial-account deduplication process and therefore exceeds the minimum data needed for the Skill’s core functionality. ### Attack Path 1. The Skill checks the environment variable and loca ...[truncated 1014 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:168
Finding

Generated HTML Accepts Unvalidated Active URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` Risk-source links use the same unsafe construction pattern: ```python def _risk_list(risks) -> str: lis = [] for r in risks or []: if isinstance(r, str): text, src = r, "" else: text, src = r.get("text", ""), r.get("source_url", "") src_html = ( f'来源:{esc(src)}' if src else "" ) lis.append(f"
  • {esc(text)}{src_html}
  • ") return f'
      {"".join(lis)}
    ' if lis else "" ``` ### Technical Analysis The renderer applies XML escaping to link values, which prevents quotation-mark attribute breakout and conventional HTML-tag injection. However, escaping does not validate the URI scheme. Consequently, a value such as `javascript:...`, `data:...`, or another active or unexpected scheme remains a syntactically valid `href`. The report accepts URLs originating from API responses, report JSON, and public-risk search results. If any upstream source is malicious, compromised, or incorrectly normalized, the resulting local HTML report contains an active link. The renderer also opens links using `target="_blank"` without `rel="noopener noreferrer"`, leaving avoidable opener-related risk in browser environments where implicit protections are unavailable or inconsistent. ### Attack Path 1. An upstream API response, WebSearch result, or report JSON contains a crafted URL using an active scheme. 2. The URL is passed to `_link`, `_risk_ ...[truncated 954 chars]
    Remediation
    View remediation

    T09 · Insecure Skill Coding Practices

    Warning
    Location
    references/auto-register.md:173
    Finding

    API Credentials and Contact-Bearing Reports Lack Explicit Restrictive File Permissions

    Content
    View full analysis
    |\s]+', "_", data.get("report_title", "企业情报"))[:60] suffix = "企业对比" if data.get("mode") == "compare" else "企业情报" out = os.path.join(args.outdir, f"{safe}_{suffix}.html") with open(out, "w", encoding="utf-8") as f: f.write(render(data)) print(out) ``` ### Technical Analysis The workflow stores a bearer API key in `~/.zlbx/config.json` without requiring mode `0600` or requiring its parent directory to use mode `0700`. Likewise, generated HTML reports are created with the default permissions determined by the current process umask. Reports may include complete telephone numbers for paid accounts because the Skill instructs the renderer to preserve the API response’s contact format. Therefore, both credentials and personal contact data may be written to files whose confidentiality depends on external system c ...[truncated 1270 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    • Rogue AgentSelf-Modification, Session Persistence
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    Findings (21)

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Description-Behavior Mismatch

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The referenced file defines an auto-registration, account recovery, quota handling, recharge-link generation, and local API-key persistence workflow that is materially unrelated to the declared company background-check purpose of the skill. This expands the skill's effective capability surface into credential and account lifecycle management, increasing the chance of unauthorized data collection, unexpected network actions, and user confusion about what the skill is actually allowed to do.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    High
    Category
    Not specified by scanner
    Confidence
    99% confidence
    Finding

    The skill instructs collection of device fingerprint attributes, including architecture and a hashed MAC-derived identifier, before using the service. Even with hashing and stated minimization, this is still persistent device fingerprinting unrelated to the business purpose of company due diligence, and it enables cross-session tracking and account binding based on host characteristics.

    Content

    No source excerpt is available for this finding.

    Obfuscated Code

    High
    Category
    Supply Chain
    Confidence
    50% confidence
    Finding

    Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

    Content

    Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

    python
    # 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
    _LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
    ...[truncated 27 chars]
    

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    86% confidence
    Finding

    The skill explicitly performs local file writes for report generation (~/zlbx-company-intel-files/) but does not declare a restrictive tool scope such as permissions or allowed-tools. In an agent environment, missing tool scoping can allow broader-than-intended file operations or make reviewers unable to verify that writes are confined to the documented path.

    Content

    No source excerpt is available for this finding.

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The trigger conditions are extremely broad ('whenever the user wants to understand a company's business, strength, or risk, this skill must be used'), which can cause unintended activation for loosely related requests. That increases the chance of unnecessary external API calls, surprise account consumption, and collection/transmission of company queries when the user did not explicitly ask for this skill.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    88% confidence
    Finding

    L126-L130 规定安装后回复“必须包含”固定中文话术,整体文件也以中文固定输出示例和交互要求为主,但未说明可根据用户语言偏好切换。这构成语言/locale 强制要求,缺少用户选择或 opt-in。

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    87% confidence
    Finding

    This markdown file applies to SQP-2 because it is a .md file. Line L04 instructs use of an external HTTPS API with an X-API-Key header, but the document does not warn users that requests send data to a third-party service and require sensitive credentials, which can affect privacy and system security.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The document prescribes exact Chinese text for consent and later user interactions, and the rest of the workflow similarly assumes Chinese-only communication. There is no indication that the user may choose another language or that the locale restriction is justified as region-specific policy.

    Content

    No source excerpt is available for this finding.

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    95% confidence
    Finding

    This instruction explicitly directs the agent to transmit collected device features to an external service endpoint as part of auto-registration. External transmission of host-derived identifiers is security-relevant because it sends persistent tracking data off-device, and in this skill context it is not necessary for performing company background checks.

    Content

    Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    92% confidence
    Finding

    The curl-based alternative likewise enables outbound transmission of registration payloads to a third-party endpoint. The risk is not the serialization guidance itself, but that the skill operationalizes exfiltration of local device-derived data to an external account service unrelated to the core background-check task.

    Content

    Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    > 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
    

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    Persisting API keys to local config and generating recharge or auto-login links introduces credential handling and session-management behavior outside the stated scope of a background-check skill. These behaviors can create durable secrets on disk, expand the attack surface around token theft or misuse, and blur the trust boundary between content analysis and account operations.

    Content

    No source excerpt is available for this finding.

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    94% confidence
    Finding

    This duplicate finding refers to the same persistence behavior: creation/merging of ~/.zlbx/config.json and continued use of the stored key. In context, durable credential storage is unrelated to the declared company-background-check function and creates a broader local security footprint than users would reasonably expect from this skill.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    94% confidence
    Finding

    This duplicate finding refers to the same persistence behavior: creation/merging of ~/.zlbx/config.json and continued use of the stored key. In context, durable credential storage is unrelated to the declared company-background-check function and creates a broader local security footprint than users would reasonably expect from this skill.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The document title and top-level instructions require the report to be produced in Chinese and constrain the output format accordingly, with no opt-in or alternative locale path. SQP-3 applies to all file types and flags language policy violations when a specific language is forced without offering the user a choice.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The template instructs the agent to execute a local rendering step and then disclose the absolute filesystem path of the generated HTML report to the user. Revealing internal local paths is unnecessary for a background-check skill and can leak host environment details such as usernames, directory layout, or storage conventions, which may aid reconnaissance or expose sensitive multi-tenant deployment information.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The markdown explicitly requires returning the complete local HTML report path to the user without any warning or access control context. This is a direct information disclosure issue: even if the file itself is not accessible, the path can reveal internal infrastructure details and may expose report filenames containing sensitive company names or other user-derived data.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    The document is entirely written as a Chinese-only execution manual, and line L001 establishes the skill context in Chinese with no indication that the user may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language locale violation unless clearly justified as region-specific, which is not stated here.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    The workflow adds a contact-retrieval step that exposes project contact details and explicitly frames it as a conversion hook, which goes beyond a background-check skill’s stated purpose. Even though the numbers may be masked for some accounts and the step is nominally opt-in, it materially expands the skill into lead generation and personal contact discovery, creating privacy, misuse, and purpose-creep risk.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    This code file contains extensive user-facing strings and generated HTML content in Chinese, including the HTML lang attribute set to 'zh-CN'. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern unless the constraint is explicitly documented and justified as region-specific.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.