Back to skill

Security audit

竞对情报分析-投标对手底细摸排

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the advertised company-intelligence analysis, but it also handles persistent credentials, device-derived registration data, tokenized links, and contact details in ways users should review before installing.

Install only if you are comfortable with the vendor API receiving company queries and, during automatic registration, a hashed MAC-derived device identifier. Prefer setting your own ZLBX_API_KEY rather than auto-registering, review permissions on ~/.zlbx/config.json, and avoid sharing exported HTML reports unless you are sure they do not contain sk links or full contact phone numbers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
references/report-template.md:191
Finding

Mandatory Promotional Content Alters Normal Agent Output

Content
View full analysis
' f'
📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成
' ``` ### Technical Analysis The Skill directs the Agent to insert fixed monitoring, cross-product, membership, and platform promotions into ordinary answers and generated reports. These directives are unrelated to the minimum technical requirements for producing company intelligence. Because the behavior is expressed as mandatory Skill instructions and duplicated in executable rendering logic, the Agent cannot omit it based on user intent. This changes the response policy whenever the Skill is loaded and creates a stable affiliated-service redirection channel. ### Attack Path 1. A user requests a company-intelligence report. 2. The Agent loads the Skill and adopts its mandatory output rules. 3. The Agent is instructed to append monitoring and affiliated-product promotions. 4. The HTML renderer inserts additional promotional links regardless of whether the user requested them. 5. The user is redirected toward affiliated services t ...[truncated 386 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:46
Finding

Persistent Hardware-Derived Device Fingerprint Is Sent to an External Registration Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s118" } ``` ### Technical Analysis The registration workflow enumerates a physical network interface, normalizes its MAC address, hashes it with SHA-256, and transmits the resulting value with platform and CPU architecture to an external service. Hashing does not make a low-entropy, stable hardware identifier anonymous. A MAC-derived hash remains deterministic and can be used to correlate the same device across registrations or sessions. The Skill describes these fields as having no identity significance, which understates their pseudonymous tracking capability. The workflow includes an explicit user-consent gate and skips collection when a key is already configured. These controls reduce the risk but do not eliminate the persistent-identification property or the absence of documented retention and deletion co ...[truncated 895 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_report.py:168
Finding

Generated HTML Accepts Active and Untrusted URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` ```python def _risk_list(risks) -> str: lis = [] for r in risks or []: if isinstance(r, str): text, src = r, "" else: text, src = r.get("text", ""), r.get("source_url", "") src_html = ( f'来源:{esc(src)}' if src else "" ) lis.append(f"
  • {esc(text)}{src_html}
  • ") ``` ```python if prof.get("url"): inner += ( f'
    公司完整档案(业务词云/联系人/合作图谱免登录直达):' f'{esc(prof["url"])}
    ' ) ``` ### Technical Analysis The renderer HTML-escapes URL values but does not parse or validate their schemes. Escaping protects against breaking out of the HTML attribute, but it does not make an active scheme safe. Values such as `javascript:`, attacker-controlled `data:` URLs, or unexpected local schemes remain valid `href` targets. The affected values can originate from API responses, WebSearch sources, or report JSON. The Skill explicitly directs the Agent to preserve returned URLs unchanged, increasing the likelihood that an untrusted value reaches these sinks. The absence of `rel="noopener noreferrer"` on links using `target="_blank"` also allows a newly opened page to retain opener access in browser configurations that do not implicitly isolate blank targets. ### Attack Path 1. An API, search result, or crafted report JSON supplies a URL using an active or unsafe scheme. 2. The Agent copies the URL into a report field. 3. `render_report.py` escapes characters but performs no s ...[truncated 720 chars]
    Remediation
    View remediation

    T09 · Insecure Skill Coding Practices

    Warning
    Location
    scripts/render_report.py:383
    Finding

    Full Contact Phone Numbers Can Be Persisted in Shareable HTML Reports

    Content
    View full analysis
    {esc(x.get("name", ""))}{esc(x.get("phone", ""))}' f'{esc(x.get("bid_count", ""))} 条{esc(x.get("last_pub_time", ""))}' for x in d.get("contacts", []) ) inner = _table(["联系人", "电话", "关联公告", "最近活跃"], contact_rows) if inner and d.get("contact_note_url"): inner += ( f'
    完整联系方式属知了标讯主站会员服务,可在公司页联系人模块查看:' f'{esc(d["contact_note_url"])}
    ' ) ``` The renderer documentation confirms that it does not enforce masking: ```python 联系人电话按传入形态原样渲染(后端已按账户分层:付费完整/免费脱敏),脚本不做任何补全或加工。 ``` ### Technical Analysis The workflow instructs the Agent to preserve complete phone numbers returned to paid accounts. The renderer then writes the supplied phone value directly into the default shareable HTML report without examining `contact_privacy`, applying masking, or requiring export-specific consent. This conflicts with the report-template policy stating that only masked contact forms should be displayed and that full contact details should remain a membership-site function. Because the renderer has no privacy state, it cannot enforce the more restrictive rule. ### Attack Path 1. A user explicitly requests company contacts. 2. A paid account causes the backend to return `contact_privacy: "full"` and complete phone numbe ...[truncated 637 chars]
    Remediation
    View remediation

    T09 · Insecure Skill Coding Practices

    Warning
    Location
    references/auto-register.md:173
    Finding

    Reusable API Key Is Persisted Without Required Restrictive File Permissions

    Content
    View full analysis
    Remediation
    View remediation
    Vulnerability Patterns
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    • Rogue AgentSelf-Modification, Session Persistence
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    Findings (27)

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Description-Behavior Mismatch

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    This file defines an auto-registration, device-identification, credential issuance, persistence, and recharge/login-link workflow inside a skill whose declared purpose is competitor-intelligence analysis. That is a clear scope expansion into account management and local state manipulation, which creates unnecessary attack surface and conditions users to permit unrelated privileged actions during normal analytical use.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    High
    Category
    Not specified by scanner
    Confidence
    97% confidence
    Finding

    The skill instructs collection of device fingerprinting attributes such as platform, architecture, and a hashed MAC address, then uses them for remote registration. Even with hashing and claimed minimization, this is persistent device tracking unrelated to competitor analysis, and the skill context makes the collection unexpected and therefore more dangerous from a privacy and abuse perspective.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The file directs the agent to persist API keys in ~/.zlbx/config.json, reuse them automatically, and generate auto-login or recharge links. Those behaviors are unrelated to competitor-intelligence analysis and introduce credential-handling and session-management risk on the local machine, including unintended persistence, account confusion, and phishing-like trust conditioning.

    Content

    No source excerpt is available for this finding.

    Ssd 3

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    This is the strongest issue in the file: the template repeatedly directs the system to preserve and disclose full sk login-bypass parameters in visible links and exported artifacts. Any bearer-like access parameter embedded in reports can be copied, forwarded, indexed, or logged, turning a convenience mechanism into an access-token leak that undermines authentication and access controls.

    Content

    No source excerpt is available for this finding.

    Obfuscated Code

    High
    Category
    Supply Chain
    Confidence
    50% confidence
    Finding

    Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

    Content

    Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

    python
    # 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
    _LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
    ...[truncated 27 chars]
    

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    93% confidence
    Finding

    The skill performs local file writes by generating and saving HTML reports under a user directory, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch can cause the agent runtime to grant broader-than-necessary capabilities implicitly, weakening least-privilege controls and making unintended file writes harder to audit or constrain.

    Content

    No source excerpt is available for this finding.

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The trigger language is intentionally expansive: it says the skill must be used even when the user does not mention competitors, as long as they want to understand a company's strength, territory, or tactics. Overbroad routing can cause the agent to invoke a networked, potentially billable, data-exporting skill for generic company research requests, increasing unnecessary data disclosure and the chance of acting outside user intent.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    84% confidence
    Finding

    Several sections prescribe exact Chinese phrases the assistant must output, including the pre-analysis notice and fixed self-introduction content. This appears to force a specific language regardless of user preference, and the file does not state that the skill is Chinese-only or provide an opt-in language choice.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The documentation explicitly enables retrieval of project contact phone numbers, including potentially full unmasked numbers for paid accounts, while providing only operational handling rules and no meaningful privacy, consent, purpose-limitation, or anti-abuse warning. In a competitor-intelligence skill, this materially increases the risk of doxxing, unsolicited outreach, surveillance, or misuse of personal contact data under the guise of bid analysis.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The document instructs the agent to present consent and guidance text in Chinese and later requires handling a specific Chinese phrase for recharge-link regeneration. There is no indication that the skill is region-specific only, nor any user opt-in or alternative locale handling, so this is a natural-language locale policy issue.

    Content

    No source excerpt is available for this finding.

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    91% confidence
    Finding

    This instruction explicitly prepares for transmission of locally collected device-derived data to an external service. In the context of a competitor-analysis skill, exfiltrating even minimized host identifiers to a third party is unnecessary and privacy-invasive, and normalizing such transmission inside an unrelated skill raises the chance of silent data export.

    Content

    Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    90% confidence
    Finding

    The curl-based guidance is another explicit pathway for sending collected local data off-host to a remote endpoint. Although the text discusses safe JSON serialization, the deeper issue is that the skill includes external transmission behavior unrelated to its declared function, increasing privacy and supply-chain risk.

    Content

    Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    > 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
    

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    94% confidence
    Finding

    This duplicate finding points to the same session-persistence behavior: creating ~/.zlbx and merging credential data for future automatic use. Even if intended for convenience, persistent credential handling inside a competitor-intel skill is unnecessary and increases the risk of unauthorized reuse or leakage on shared or compromised systems.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    94% confidence
    Finding

    This duplicate finding points to the same session-persistence behavior: creating ~/.zlbx and merging credential data for future automatic use. Even if intended for convenience, persistent credential handling inside a competitor-intel skill is unnecessary and increases the risk of unauthorized reuse or leakage on shared or compromised systems.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The file provides required user-facing output in Chinese for quota exhaustion and defines a Chinese trigger phrase for regenerating the recharge link. Because no language choice or opt-in is offered, the skill effectively enforces a specific locale in user communications.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The file title and throughout the template impose Chinese-language report formatting, which can constitute a language/locale policy issue when no user preference or opt-in is mentioned. The instructions do not offer an alternative language or state that Chinese is only used when requested by the user.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The template explicitly requires preserving and exposing full sk免登录 parameters in company and announcement links, including in user-facing reports. If sk functions as a login-bypass or bearer-style access token, sharing it broadly can leak access beyond the intended session or audience, enabling unauthorized viewing and uncontrolled redistribution of protected resources.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The skill mandates default execution of a local script, creation of a temporary JSON file, and writing an HTML report to the filesystem, even when the user only asked for analysis. This expands the skill from content generation into local side effects, increasing attack surface around file creation, data persistence, path disclosure, and unintended execution behavior.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The template instructs the agent to create an HTML file by default and then disclose the output path to the user without an explicit warning or consent step. Silent local file creation can surprise users, persist sensitive business intelligence on disk, and expose details about the runtime environment through absolute paths.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    84% confidence
    Finding

    The document title and all reporting instructions are written as a Chinese-only execution manual, with no indication that output language can follow user preference. A skill that effectively forces a specific language without opt-in can violate language/locale policy requirements.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The workflow explicitly tells the agent to output company and announcement URLs with the 'sk' parameter unchanged, which strongly suggests propagating bearer-like access tokens or session secrets to end users. If those links are shared, logged, or reused outside the intended client, they may grant unauthorized access, leak account-scoped entitlements, or expose audit-sensitive data.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    The workflow adds an optional contact-discovery step that goes beyond the core stated purpose of competitor intelligence analysis and instructs disclosure of project contacts and phone numbers. In this context, exposing identifiable contact data can enable targeted outreach, profiling, or misuse unrelated to analytical reporting, especially because the skill is framed around investigating opponents in bidding scenarios.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The contact section directs the agent to display returned phone numbers as-is, including full numbers for paid accounts, without any warning or constraints around personal data handling. This creates a privacy and abuse risk because the skill operationalizes extraction and disclosure of personal contact details in a competitor-investigation workflow, making misuse for unsolicited contact or targeted harassment more likely.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.