T01 · Skill Instruction Hijacking
- Location
SKILL.md:493- Finding
Mandatory Promotional Output Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This tender-search skill is mostly coherent, but it needs review because it can create a third-party account using a MAC-derived device identifier, store an API key locally, and add promotional referral text to answers.
Install only if you are comfortable with this provider receiving your tender queries and, if you lack an API key, receiving a MAC-derived device hash for trial registration. Prefer supplying your own API key through a managed secret or environment variable, review ~/.zlbx/config.json permissions, avoid bulk contact extraction, and be aware that the skill may append promotional referral links unless you ask for data only.
SKILL.md:493Mandatory Promotional Output Hijacking
references/auto-register.md:44Persistent Device Fingerprint Sent to an External Registration Service
references/auto-register.md:173Bearer API Key Stored Without Mandatory Filesystem Permission Controls
The skill declares that it must be used for a very broad class of procurement, tender, supplier, competitor, and customer-development queries, leaving little room for safer or more appropriate alternatives. This increases the chance that sensitive business queries are routed into a tool that can trigger account registration, collect device data, and send proprietary search terms to a third party even when the user did not explicitly ask to use this provider.
The documented auto-registration flow collects device fingerprinting attributes such as platform, architecture, and a MAC-derived hash, even though the skill's stated purpose is procurement data retrieval. Collecting device-derived identifiers for account creation creates unnecessary privacy risk, enables cross-session tracking, and is disproportionate to the business function of searching bids.
The skill goes beyond tender-search functionality by instructing the agent to automatically create a third-party account and persist a newly issued API key to a local file when no key is present. That introduces unauthorized account creation and local credential storage behavior, which can violate user expectations, create unmanaged external accounts, and expand the blast radius if the local config is later accessed by other tools or users.
The documentation instructs the agent to automatically expand a user query about a company shorthand into multiple related legal entities and proceed without confirmation. In a procurement and tendering context, this can silently broaden the data scope, causing unintended aggregation across subsidiaries or similarly named entities and potentially disclosing or analyzing data the user did not intend to target.
The contact feature enables retrieval and display of project contact details, including phone numbers, but the documentation lacks a clear privacy, acceptable-use, or anti-harvesting warning. Even with masked numbers for some tiers, this capability can facilitate targeted outreach, scraping, or misuse of personal/business contact data if the agent surfaces it too freely.
This documentation is entirely written in Chinese and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.
The file presents all instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.
The skill directs the agent to collect device-derived identifiers and transmit them to an external service during auto-registration. Even though the document claims minimization and requires user consent, this still creates a privacy-sensitive external data flow involving persistent device fingerprinting material and API account provisioning, which is dangerous in an agent context if consent is skipped, misunderstood, or not meaningfully verified.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
Line L129 states the ch field must be fixed to "s01", but the surrounding request example at L115 and the pseudocode at L242 use "s49". This is an active contradiction in the file's own guidance and could cause an implementing agent to send a different registration attribution value than the documentation claims is required.
This duplicated finding refers to the same persistence behavior: creating ~/.zlbx and storing an API key for future use. In an agent environment, automatic credential persistence can outlive the user's expectations and broaden the blast radius if the workstation, account, or other local software is compromised.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicated finding refers to the same persistence behavior: creating ~/.zlbx and storing an API key for future use. In an agent environment, automatic credential persistence can outlive the user's expectations and broaden the blast radius if the workstation, account, or other local software is compromised.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The document prescribes exact Chinese output text for the user, including the recharge/login message, with no option to adapt to the user's preferred language. This is a natural-language locale policy concern because it hard-codes a specific language rather than offering a choice or documenting a justified region-specific constraint.
The entire skill documentation is written in Chinese and examples, labels, and prescribed user-facing phrases are Chinese-only, with no indication that users may choose another language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy issue unless the locale restriction is explicitly justified.
No suspicious patterns detected.