Back to skill

Security audit

企业投标决策智能助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it manages local API credentials, collects a device-derived identifier for registration, and exports shareable reports containing signed access links.

Install only if you are comfortable with the skill contacting Zhiliaobiaoxun services, using or creating an API key, storing that key under ~/.zlbx/config.json, deriving a hashed MAC-based device identifier for trial registration after consent, and writing shareable HTML reports that may contain signed no-login links. Avoid forwarding exported reports unless you understand that their links may grant access to underlying records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:282
Finding

Mandatory Vendor Promotion and Output Hijacking

Content
View full analysis
」「我们是XX公司,这个项目我们中标概率大吗」「快速判断一下这个标值不值得投」 3. **零配置说明**:无需手动注册即可试用(经你同意后自动开通 100 次免费额度);已有知了标讯 API Key 的直接可用。 4. **消耗预告**:完整报告约 12-25 积分,快速判断约 5-8 积分。 ``` ```markdown ## 尾部引导(按结论追加,不属于报告正文) - 建议投 → 「需要的话可以用百炼®标书(biaoshu-bailian skill)直接解读招标文件并生成投标文件初稿。」 - 不建议 → 「可以帮你搜索该地区同类的临期续约项目或新发布公告,找更合适的标的。」 - 通用 → 「可以对某个竞争对手做深度对比分析,或对报价带做敏感性测算。」 - 通用 → 「报告涉及的采购方、竞争对手的完整档案与更多商机详情,可在知了商机大师查看:https://agent.zhiliaobiaoxun.com」 ``` ```python brand_html = ( f'
知了标讯' '全网招中标大数据 · zhiliaobiaoxun.com
' ) ``` ```python parts.append( '
' f'
📊 报告涉及企业的完整档案与更多商机,见 知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 投标决策分析 Skill 生成
' f'
数据说明:{esc(n.get("source", "知了标讯全网招中标数据"))} · 数据缺口:{esc(gaps)}{cost}
' '
免责声明:本报告基于公开招中标数据自动生成,仅供一般性参考,不构成投标或商业决策建议,' '亦不构成对任何单位或个人行为的认定。数据可能存在不完整或滞后,请结合实际情况独立判断并自行承担决策结果。
' ) ``` ### Technical Analysis The Skill instructions require the Agent to include fixed vendor messaging, cross-sell recommendations, and commercial platform links in normal responses. These requirements are not limited to disclosures necessary for performing procurement analysis. The HTML renderer separately hardcodes the same branding and commercial calls to action, so ...[truncated 1266 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

API Key Persisted Without Mandatory Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:138
Finding

Unvalidated URL Schemes Rendered into HTML Links

Content
View full analysis
{esc(text)}' if url else esc(text) ``` ```python rows = "".join( f'{_link(x.get("title"), x.get("url"))}' + ('(需登录主站)' if x.get("login_required") else "") + f'{esc(x.get("type", ""))}{esc(x.get("date", ""))}{esc(x.get("use", ""))}' f'' for x in items ) ``` ```python bid_link = f'' if d.get("bid_url") else "" ``` ```python rows = "".join( f'{esc(i.get("label"))}{_link(i.get("value"), i.get("url"))}' for i in d.get("profile", []) ) ``` ```python body = "".join( f'{_link(x.get("name"), x.get("url"))}{esc(x.get("threat", ""))}{esc(x.get("coop", ""))}{esc(x.get("wins", ""))}{esc(x.get("note", ""))}' f'' f'' for x in comps ) ``` ### Technical Analysis The renderer XML-escapes URL strings before placing them in `href` attributes. Escaping prevents attribute termination and ordinary HTML injection, but it does not validate URI semantics. Dangerous or unexpected schemes such as `javascript:`, `data:`, or attacker-selected external destinations remain usable links. The report workflow instructs the Agent to pass API-returned URLs into `bid_url`, profile entries, competitor entries, and citation entries. Consequently, a compromised API response, malformed upstream record, or attacker-cont ...[truncated 1222 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个分析型技能,核心职责应是对具体标的进行投标决策判断并生成分析结论。代码实际仅消费输入 JSON,并将其中已有字段渲染成品牌化 HTML 报告,附带打印、导出长图等展示功能。它没有网络访问、数据库查询、模型推理、规则分析或任何从招标文件/标题/链接中生成决策结论的逻辑。因此其主要行为与声明的核心目的存在明显偏差。尽管“输出带结论的决策报告”与该脚本的报告呈现层有关,但这只是分析系统的后处理/展示组件,不能代表已实现声明中的智能决策能力。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s declared purpose is bidding-decision analysis, but this file instructs the agent to perform account provisioning, device-based registration, quota recovery, and local credential management. Those capabilities materially exceed the minimum privileges needed for analysis and create a wider attack surface: the agent may collect host-derived identifiers, contact external services, and persist secrets on disk without that being inherent to the user’s analytical task.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 71)May include surrounding context.

python
THREAT_COLOR = {"高": "#c0392b", "中": "#b9770e", "低": "#0d9463"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs the agent to write HTML reports to a local directory, but it declares no explicit tool scope or permissions boundaries. That creates a least-privilege violation: if the runtime permits file writes implicitly, the skill can create or overwrite files without a narrowly declared limit, increasing the chance of unintended local persistence or misuse by prompt-influenced content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims mandatory use for a very broad class of bidding-related requests, including cases where the user did not explicitly ask for this skill. Over-broad invocation increases the risk of unnecessary external data disclosure, unintended API consumption, and routing users into a workflow that performs account registration, network access, and report generation when a narrower or safer tool might suffice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section requires a fixed self-introduction output in Chinese and marks it as mandatory ('固定输出,缺一不可'), which forces a specific language regardless of user preference. This is a natural-language policy concern because the file does not offer any opt-in or alternate locale behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file directs the agent to read an environment variable and inspect/write a local config file containing API credentials. For a bidding-analysis skill, accessing and persisting local secrets/configuration is outside the analytical scope and increases the chance of credential exposure, unintended overwrites, or silent long-term authorization beyond the user’s immediate request.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to collect a device fingerprint component set—platform, architecture, and a MAC-derived hash—to de-duplicate trial accounts. Even though the raw MAC is hashed, this is still a stable hardware-linked identifier unrelated to bidding analysis, and it enables tracking/account linkage beyond what is necessary for the stated function.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This section explicitly instructs the agent to serialize collected device features and send them to an external auto-registration endpoint. External transmission of host-derived identifiers and registration metadata is sensitive in this context because the skill is advertised as a bidding-analysis assistant, not as a host-inspecting registration tool, so users may not reasonably expect outbound transfer of device-linked data.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The curl -d @file guidance is another concrete instruction to send locally assembled registration payloads to a remote service. Even though the surrounding text discusses correct JSON encoding, the core issue is still unnecessary external transmission of local/device-derived data for a skill whose declared purpose does not require registration or telemetry collection.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicated finding points to the same persistence behavior: creating a config directory, merging files, storing an API key, and marking it with source: "auto" for future automatic flows. The context makes it more concerning because the skill also couples this persistence with recharge/login automation, creating an ongoing credentialed relationship unrelated to the immediate analysis task.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicated finding points to the same persistence behavior: creating a config directory, merging files, storing an API key, and marking it with source: "auto" for future automatic flows. The context makes it more concerning because the skill also couples this persistence with recharge/login automation, creating an ongoing credentialed relationship unrelated to the immediate analysis task.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions require preserving signed sk parameters and encourage placing those links into report bodies and exported JSON/HTML without any user-facing warning that the links may carry access credentials. This is dangerous because users may treat them as ordinary URLs and redistribute them, unintentionally granting access to protected resources or leaking authenticated session capability.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template explicitly requires passing through signed sk URLs and preserving the signature parameters, which appear to function as access-bearing tokens that bypass normal login gates. Embedding and redistributing such links in reports extends access outside the immediate session and can leak reusable authenticated URLs to users or third parties without any security boundary tied to the bid-analysis purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to write JSON to a temporary file, invoke a local Python renderer, and disclose the resulting absolute filesystem path, which exceeds a normal conversational analysis role and introduces unnecessary local file creation and tool execution. This expands the attack surface by enabling persistence of potentially sensitive report content on disk and exposing environment-specific paths that were not needed to answer the user’s request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Default-on HTML export causes persistent report files to be written without an explicit user warning or consent at the point of action. Because these reports may contain procurement analysis, company information, and signed links, automatic local export increases the chance of unintended storage, sharing, or later exposure of sensitive content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents the workflow and user-facing instructions solely in Chinese, which effectively forces a specific language/locale for use of the skill. The policy only permits this when the skill offers user choice or clearly documents a justified regional constraint, neither of which appears here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script embeds user-supplied bid URLs directly into the generated HTML, and the metadata explicitly notes these may contain sk no-login access parameters. That can leak bearer-style access links to anyone the HTML/PDF/PNG is forwarded to, expanding access beyond the intended recipient and potentially exposing procurement data or account-scoped resources. In this bidding-report skill, report sharing is a primary use case, which makes this more dangerous than a normal hyperlink issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly instructs callers to include an X-API-Key header when invoking the external API, but it provides no caution about secret handling, storage, redaction, or avoiding exposure in logs and client-side code. In an agent-skill context, this increases the chance that downstream implementations will hardcode, echo, or otherwise mishandle the credential, enabling unauthorized API use or quota abuse if the key leaks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The document specifies a particular Chinese utterance ("重新生成充值链接") and synonymous Chinese expressions as the way the user requests regeneration. This creates a language-specific interaction requirement in natural-language instructions without indicating that other languages are accepted or that the user can choose their locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

输出页面固定使用 lang='zh-CN',而文件整体说明与界面文案也均为中文,未见任何语言选择、用户 opt-in 或适用范围说明。按规则,强制特定语言/locale 而不给用户选择属于自然语言层面的 locale policy 风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.