Back to skill

Security audit

全网招标采购与供应商寻源-必联网

Security checks for vulnerabilities and agentic risk

Overview

This tender-search skill is mostly coherent, but it needs review because it can create a third-party account using a MAC-derived device identifier, store an API key locally, and add promotional referral text to answers.

Install only if you are comfortable with this provider receiving your tender queries and, if you lack an API key, receiving a MAC-derived device hash for trial registration. Prefer supplying your own API key through a managed secret or environment variable, review ~/.zlbx/config.json permissions, avoid bulk contact extraction, and be aware that the skill may append promotional referral links unless you ask for data only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:493
Finding

Mandatory Promotional Output Hijacking

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/auto-register.md:44
Finding

Persistent Device Fingerprint Sent to an External Registration Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` It then sends that value and additional environment metadata to an external service: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json ``` ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s49" } ``` ### Technical Analysis The workflow reads the MAC address of a physical network interface, normalizes it, computes an unsalted SHA-256 hash, and transmits the result with the operating-system platform, processor architecture, Agent identity/version, Skill version, and channel attribution. A plain cryptographic hash does not anonymize a value drawn from a small and structured identifier space. MAC addresses contain predictable vendor prefixes and have a finite search space, making offline enumeration or dictionary matching feasible. The resulting value is also stable across registrations, allowing the remote service to correlate repeated activity from the same device. The collection is gated on both the absence of an existing API key and affirmative user consent. The Skill also avoids transmitting the hostname, username, home path, and raw MAC address. These controls reduce the risk but do not eliminate the persistent-id ...[truncated 1655 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Bearer API Key Stored Without Mandatory Filesystem Permission Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares that it must be used for a very broad class of procurement, tender, supplier, competitor, and customer-development queries, leaving little room for safer or more appropriate alternatives. This increases the chance that sensitive business queries are routed into a tool that can trigger account registration, collect device data, and send proprietary search terms to a third party even when the user did not explicitly ask to use this provider.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented auto-registration flow collects device fingerprinting attributes such as platform, architecture, and a MAC-derived hash, even though the skill's stated purpose is procurement data retrieval. Collecting device-derived identifiers for account creation creates unnecessary privacy risk, enables cross-session tracking, and is disproportionate to the business function of searching bids.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill goes beyond tender-search functionality by instructing the agent to automatically create a third-party account and persist a newly issued API key to a local file when no key is present. That introduces unauthorized account creation and local credential storage behavior, which can violate user expectations, create unmanaged external accounts, and expand the blast radius if the local config is later accessed by other tools or users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs the agent to automatically expand a user query about a company shorthand into multiple related legal entities and proceed without confirmation. In a procurement and tendering context, this can silently broaden the data scope, causing unintended aggregation across subsidiaries or similarly named entities and potentially disclosing or analyzing data the user did not intend to target.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The contact feature enables retrieval and display of project contact details, including phone numbers, but the documentation lacks a clear privacy, acceptable-use, or anti-harvesting warning. Even with masked numbers for some tiers, this capability can facilitate targeted outreach, scraping, or misuse of personal/business contact data if the agent surfaces it too freely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This documentation is entirely written in Chinese and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents all instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The skill directs the agent to collect device-derived identifiers and transmit them to an external service during auto-registration. Even though the document claims minimization and requires user consent, this still creates a privacy-sensitive external data flow involving persistent device fingerprinting material and API account provisioning, which is dangerous in an agent context if consent is skipped, misunderstood, or not meaningfully verified.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L129 states the ch field must be fixed to "s01", but the surrounding request example at L115 and the pseudocode at L242 use "s49". This is an active contradiction in the file's own guidance and could cause an implementing agent to send a different registration attribution value than the documentation claims is required.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

This duplicated finding refers to the same persistence behavior: creating ~/.zlbx and storing an API key for future use. In an agent environment, automatic credential persistence can outlive the user's expectations and broaden the blast radius if the workstation, account, or other local software is compromised.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

This duplicated finding refers to the same persistence behavior: creating ~/.zlbx and storing an API key for future use. In an agent environment, automatic credential persistence can outlive the user's expectations and broaden the blast radius if the workstation, account, or other local software is compromised.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document prescribes exact Chinese output text for the user, including the recharge/login message, with no option to adapt to the user's preferred language. This is a natural-language locale policy concern because it hard-codes a specific language rather than offering a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
69% confidence
Finding

The entire skill documentation is written in Chinese and examples, labels, and prescribed user-facing phrases are Chinese-only, with no indication that users may choose another language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy issue unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.