Back to skill

Security audit

政府采购投标决策-政采项目投标评估

Security checks for vulnerabilities and agentic risk

Overview

This procurement-analysis skill is mostly coherent, but it needs review because it stores credentials locally, collects a hardware-derived identifier for registration, and can generate shareable reports containing access-bearing links.

Review before installing. Use a manually created ZLBX_API_KEY if possible to avoid automatic device registration, and be aware that generated reports may be written under ~/zlbx-bid-decision-files/ and can include signed links or auto-login/recharge links that should not be forwarded casually.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/render_report.py:282
Finding

Mandatory promotional content alters report output and redirects users to affiliated services

Content
View full analysis

Vulnerability Details

File Location: scripts/render_report.py:282-289
Vulnerability Type: Mandatory output manipulation and affiliated-service redirection
Risk Level: Medium

Evidence

python
parts.append(
    '<div class="footer">'
    f'<div class="cta">📊 Report-related company profiles and opportunities: <a href="https://agent.zhiliaobiaoxun.com" target="_blank">Affiliated service</a>'
    f' · Generated by <a href="https://ai.zhiliaobiaoxun.com" target="_blank">Affiliated AI platform</a></div>'
    f'<div>Data notes: {esc(n.get("source", "procurement data"))} · Data gaps: {esc(gaps)}{cost}</div>'
    '<div class="disclaim">Disclaimer: This report is generated from public procurement data and is for general reference only.'
    ' It does not constitute procurement or commercial advice.</div></div>'
)

The original source contains equivalent fixed Chinese-language labels. The URLs and unconditional rendering behavior above are unchanged.

Related mandatory recommendation instructions also appear in:

  • SKILL.md:136-147
  • references/report-template.md:91-96

Technical Analysis

The renderer unconditionally inserts calls to action and links to affiliated services into every generated report. Report input cannot disable this behavior. The Skill instructions further require the agent to recommend one of several related products after completing an analysis.

This changes the agent's report-generation objective from providing only the requested procurement analysis to also performing predetermined promotion and redirection. The behavior is not required to calculate bid suitability, pricing, competition, or compliance risk.

Although the links use HTTPS and no remote code execution was identified, the mandatory nature of the content means users cannot distinguish neutral analytical output from operator-directed prom ...[truncated 903 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove unconditional promotional calls to action from the report renderer.
  2. Keep the generated report limited to content necessary for the requested analysis.
  3. Make related-service recommendations opt-in and configurable through explicit report input.
  4. Clearly label any retained link as advertising or an affiliated service.
  5. Do not present an affiliated product as an analytically required next step.
  6. Allow users to generate a report without branding, tracking parameters, or outbound promotional links.
  7. Add tests confirming that neutral report generation produces no unsolicited recommendations.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:47
Finding

Persistent hardware-derived device fingerprint is transmitted during automatic registration

Content
View full analysis

Vulnerability Details

File Location: references/auto-register.md:47-108
Vulnerability Type: Hardware fingerprint collection and external transmission
Risk Level: Medium

Evidence

The Linux collection procedure reads a physical network interface address and creates a stable hash:

bash
iface=$(ls /sys/class/net | grep -vE '^(lo|docker|veth|br-|tun|tap)' | sort | head -n1)
cat "/sys/class/net/$iface/address" 2>/dev/null \
  | tr -d ':-' | tr 'A-Z' 'a-z' \
  | sha256sum | awk '{print $1}'

The resulting value is included in a remote registration request:

text
POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register
Content-Type: application/json

{
  "device_features": {
    "hostname": "",
    "platform": "darwin",
    "arch": "arm64",
    "username": "",
    "home_path": "",
    "mac_hash": "abc123..."
  },
  "agent_kind": "claude-code",
  "agent_version": "...",
  "skill_version": "bid-decision-1.0.5",
  "ch": "s77"
}

Equivalent hardware-interface collection procedures are documented for macOS and Windows.

Technical Analysis

A SHA-256 digest of a MAC address remains a stable pseudonymous hardware identifier. Hashing prevents immediate disclosure of the original address in transit, but it does not make the identifier anonymous. MAC addresses have constrained structure and entropy, and the same normalized address always produces the same digest.

The remote service can therefore correlate registration attempts and activity associated with the same network adapter across sessions. Procurement analysis itself does not require access to physical network-interface identifiers. The collection occurs only after a documented consent prompt, which reduces but does not eliminate the least-privilege concern.

The fallback behavior can also produce weak or empty identifiers. The document acknowledges that unavailable MAC data can cause multiple system ...[truncated 1139 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the MAC-derived fingerprint with a cryptographically random installation identifier.
  2. Generate the identifier locally using a secure random-number generator.
  3. Store it in a Skill-specific configuration file with restrictive permissions.
  4. Make the identifier revocable and provide a documented deletion or reset mechanism.
  5. Avoid collecting platform and architecture unless the registration protocol demonstrably requires them.
  6. Explain retention period, server-side use, deletion policy, and correlation scope before requesting consent.
  7. Do not treat any device identifier as authentication or sufficient proof of account ownership.
  8. Offer a registration method that does not require device fingerprinting.
  9. If abuse prevention is necessary, prefer short-lived, privacy-preserving server challenges and rate limits.

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:190
Finding

API key persistence lacks mandatory restrictive permissions and symlink protections

Content
View full analysis

Vulnerability Details

File Location: references/auto-register.md:190-205
Vulnerability Type: Insecure local credential storage
Risk Level: Medium

Evidence

The documented persistence procedure writes the API key to a regular JSON file:

json
{
  "api_key": "zlbx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
  "source": "auto",
  "registered_at": "2026-05-10T10:30:00Z"
}

Its implementation requirements are limited to:

text
Create ~/.zlbx if the directory does not exist.
Merge with an existing file rather than replacing unrelated configuration.
Write source as "auto".

The accompanying pseudocode performs a direct configuration write:

python
write_json("~/.zlbx/config.json", {
    "api_key": resp["api_key"],
    "source": "auto",
    "registered_at": iso_now(),
})

No requirement is provided for directory mode 0700, file mode 0600, atomic file creation, ownership verification, or symlink rejection.

Technical Analysis

The returned API key is a bearer credential used in the X-API-Key request header. Any process or user able to read it can impersonate the account for the capabilities exposed by the API.

Creating the directory and file without explicit modes relies on the runtime's umask and the behavior of whichever tool implements write_json. On a permissive system, the file may become group-readable or world-readable. Updating the file through a normal path also creates a potential symlink-following issue if an attacker can pre-create or replace the path.

A non-atomic read-modify-write operation can additionally corrupt configuration during concurrent writes or temporarily expose incomplete content. No direct exploit implementation is shipped in the repository, but the documented procedure instructs agents to persist a sensitive credential without required safeguards.

Attack Path

  1. Automatic registration returns an API key.
  2. The Skill crea ...[truncated 1020 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create ~/.zlbx with mode 0700 and verify that it is owned by the current user.
  2. Create config.json with mode 0600, independent of the process umask.
  3. Reject symbolic links and non-regular files for both the directory and destination.
  4. Use an atomic write:
    • Create a temporary file in the same directory.
    • Open it with exclusive creation and mode 0600.
    • Write and flush the JSON.
    • Call fsync where appropriate.
    • Atomically replace the destination.
  5. Preserve owner-only permissions when merging an existing configuration.
  6. Validate ownership and permissions before reading an existing key.
  7. Prefer an operating-system credential store where available.
  8. Never print the key, include it in report output, or place it in command-line arguments.
  9. Document key revocation and rotation procedures in case local disclosure is suspected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description explicitly mandates use even when the user does not mention government procurement, making the trigger scope overly broad. Over-broad activation can hijack unrelated workflows, cause unintended network/API use and billing, and expose user queries or project details to an external service without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file defines an auto-registration, local credential storage, and recharge flow inside a skill whose declared purpose is procurement bid-decision analysis. That scope expansion gives the skill account lifecycle and persistence capabilities unrelated to user-requested analysis, increasing the chance of silent credential handling and unauthorized external interactions in a context where users would not reasonably expect them.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs collection of device fingerprints (platform, arch, mac_hash) and transmission to a remote service even though the skill is presented as a government-procurement analysis assistant. Hardware-derived identifiers can support tracking and account linkage across sessions, and the mismatch between stated purpose and actual collection makes the behavior more dangerous because users are unlikely to anticipate host-level fingerprinting from a bidding-analysis workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs the agent to write API keys into ~/.zlbx/config.json, merge with existing configuration, and immediately reuse the key in-session. Persisting credentials on the local host is a sensitive capability unrelated to bid analysis and can expose secrets to other local processes, future prompts, backups, or users of the same environment.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 71)May include surrounding context.

python
THREAT_COLOR = {"高": "#c0392b", "中": "#b9770e", "低": "#0d9463"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill performs local file writes by generating and saving an HTML report, but it does not declare an explicit tool/permission scope such as allowed file operations. This creates a least-privilege gap: an agent runtime may grant broader filesystem access than necessary, increasing the chance of unintended writes, path misuse, or abuse if other instructions in the skill are later modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This section requires the reply to include fixed Chinese wording and sample utterances '原样展示', which imposes a specific language/locale in user-facing output. The file does not indicate user opt-in or provide a language choice, so it conflicts with the policy against forcing a locale without consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This section explicitly instructs the agent to serialize and transmit collected device features to an external endpoint. External transmission of host-derived identifiers and agent metadata is sensitive on its own, and in this skill context it is especially risky because the data flow is not necessary for procurement analysis and may surprise users.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The curl -d @file example is another explicit instruction to send data externally, reinforcing that the skill operationalizes outbound transfer rather than merely documenting it abstractly. In combination with device fingerprint collection and account creation, this creates an unnecessary exfiltration path within a non-authentication skill.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states that the ch field must be fixed to "s64", but the request example above uses "s77" and later pseudocode also uses "s77". This is an active contradiction in the skill's own instructions that could cause the agent to send a different value than the documentation claims is required.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This duplicate finding points to the same persistence behavior: creating ~/.zlbx, merging config, marking source: auto, and continuing to use the stored key. In the context of a bid-analysis skill, this persistence is unjustified and increases the attack surface for local secret disclosure or unintended reuse.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This duplicate finding points to the same persistence behavior: creating ~/.zlbx, merging config, marking source: auto, and continuing to use the stored key. In the context of a bid-analysis skill, this persistence is unjustified and increases the attack surface for local secret disclosure or unintended reuse.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Generating auto-login and recharge links extends the skill into account access and billing operations outside its procurement decision-support purpose. Such links can become sensitive session artifacts; if exposed in logs, transcripts, or shared terminals, they may enable unintended account access or manipulation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The prescribed user-facing output is written as fixed Chinese copy and is presented as the required message to show the user. This forces a specific language/locale in user communication without any opt-in or alternative, which violates the language-choice policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template explicitly requires preserving signed sk parameters in shared URLs because they bypass a login wall. That means the agent is instructed to redistribute access-bearing links or tokens, which can unintentionally grant access to protected resources and facilitate unauthorized sharing beyond the analysis task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template requires inclusion of signed URLs with sk parameters in both the Markdown report and exported JSON/HTML, but provides no warning that these links may embed access-related tokens. Embedding such URLs in shareable outputs increases the chance of token leakage through chat logs, files, forwarding, browser history, or third-party systems that receive the report.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template instructs the agent to create a local HTML file by default and then disclose its absolute filesystem path to the user. This exceeds the stated purpose of bid-decision analysis, creates an unnecessary side effect on the host environment, and leaks internal path information that can reveal filesystem structure, usernames, or storage conventions useful for follow-on probing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow mandates default HTML generation, JSON serialization to a temporary file, and local output without prior user-facing warning or consent. This is a risky side effect because it writes potentially sensitive procurement analysis data to disk, may persist artifacts unexpectedly, and changes system state in a way the user did not request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow mandates sending an API key in request headers for all requests, but provides no safeguards for secret storage, redaction, scope limitation, or warnings about transmitting credentials to external services. In an agent environment, this increases the risk of credential leakage through logs, prompt injection, debugging output, or misuse of a privileged external API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s docstring and the report template are written entirely in Chinese, and the generated HTML explicitly sets lang='zh-CN'. There is no indication that users can choose another language or that the locale restriction is an intentional region-specific limitation, which conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The entire skill reference is presented only in Chinese, with no indication that users may choose another language or that the locale restriction is intentional and justified. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file instructs users to include an X-API-Key header when calling the API, which involves use of sensitive credentials. The quick reference does not include any warning about protecting the key, avoiding exposure in logs or shared snippets, or treating it as secret material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow explicitly tells the agent to read a local bidding document when the user provides one, but it does not require confirming the file source, scope, or user consent for local file access. In an agent setting, this can normalize accessing local files beyond the user's clear expectation and may expose sensitive procurement documents or adjacent local data if file handling is overly broad.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.