T01 · Skill Instruction Hijacking
- Location
SKILL.md:269- Finding
Mandatory Promotional Output and Tracked Vendor Redirection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill provides legitimate procurement-data analysis, but its onboarding path collects a hardware-derived device identifier and stores a bearer API key locally in ways users should review before installing.
Install only if you are comfortable with this vendor's API, local API-key storage, and the opt-in auto-registration flow that sends a MAC-derived hash for trial-account deduplication. Prefer setting your own ZLBX_API_KEY manually and review ~/.zlbx/config.json permissions if you use the skill.
SKILL.md:269Mandatory Promotional Output and Tracked Vendor Redirection
references/auto-register.md:33Transmission of a Stable Hardware-Derived Device Fingerprint
references/auto-register.md:173Plaintext API Key Persistence Without Required File-Permission Controls
The activation rule is overly broad and mandates use whenever loosely related government/procurement terms appear, even if the user did not request this specific service. Over-broad invocation increases unnecessary data exposure to the third-party backend and raises the chance the skill is triggered in contexts where its credential handling and account bootstrap logic become active without clear user expectation.
The skill instructs collection of device fingerprint attributes (platform, arch, mac_hash) for auto-registration even though its primary purpose is procurement analytics. Collecting hardware-derived identifiers for account provisioning creates unnecessary privacy risk and enables persistent tracking; the instruction to substitute empty strings on failure also normalizes collection attempts rather than data minimization.
The document instructs the agent to collect device fingerprints, create remote trial accounts, and persist credentials locally before performing the advertised procurement-analysis function. This is a material scope expansion: even with disclosure text, the skill is embedding identity/account bootstrapping and host-level data collection that are not necessary to answer procurement queries, increasing privacy and security risk if the workflow is triggered automatically or implemented incorrectly.
The workflow directs the agent to write an API key to ~/.zlbx/config.json and immediately reuse it in the current session. Persisting authentication material on disk from within a data-analysis skill creates credential-handling and local secret-storage behavior outside the skill's stated purpose, and can expose the key to other local processes, accidental disclosure, or misuse if file permissions and lifecycle controls are not enforced.
The natural-language description is entirely in Chinese and instructs mandatory use behavior, but does not offer any language or locale choice for users who may be interacting in another language. Under the policy, forcing a specific language without opt-in is a locale/language policy issue unless clearly justified and documented.
The skill’s documented behavior goes beyond procurement-data querying and includes credential acquisition, account creation, and local API key persistence. That materially expands the trust boundary: a data-analysis skill is being authorized to provision access and write secrets to disk, which can surprise users and create opportunities for unauthorized account creation or misuse of credentials.
The manifest centers this skill on government procurement and bidding data queries and analysis. The documentation adds broader internet research on company strategy, news, industry rankings, and policy impacts via WebSearch, which goes beyond the described procurement-data platform role.
This file adds account-balance and usage-consumption functionality to a skill whose declared purpose is government procurement and bid-data analysis. That scope expansion enables access to billing and account metadata unrelated to the user task, violating least privilege and increasing the chance an agent will disclose or act on sensitive account information without a procurement-specific need.
The documentation instructs the agent to read an API key from environment variables or agent configuration to perform account queries unrelated to the stated procurement-analysis function. Even though it says not to reveal the key, teaching a broadly scoped skill to access ambient credentials for out-of-scope actions increases the risk of unauthorized use of privileged secrets and unintended access to account data.
The skill explicitly tells the agent to automatically aggregate all semantically matched companies, including headquarters and affiliates, and continue analysis without user confirmation. In a procurement context, this can easily cause entity-mixup, overbroad data collection, and incorrect competitive or supplier intelligence about the wrong legal person, which may mislead business decisions or expose data beyond the user's intended scope.
The contact lookup feature enables retrieval of named project contacts and phone numbers, but the documentation only discusses masking tiers and upsell behavior, not privacy, purpose limitation, or restrictions on handling personal data. In this government procurement and business-intelligence skill, that omission increases the risk of using personal contact data for unsolicited outreach, bulk harvesting, or other privacy-invasive uses.
This markdown file presents all usage instructions, parameters, and examples only in Chinese. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.
The skill contains account lifecycle functions such as signup, recovery handling, and recharge-link generation that are unrelated to procurement analysis and expand the attack surface into authentication and billing flows. Even if intended for user convenience, embedding these flows in a skill increases the chance of phishing-like UX, unintended account manipulation, or unsafe handling of auth artifacts such as recovery hints and auto-login links.
This section explicitly instructs external transmission of collected device features to a remote auto-registration endpoint. Although the text attempts data minimization, the skill context makes this more dangerous because a procurement-analysis assistant is not expected to exfiltrate host-derived identifiers to third-party infrastructure, and users may not anticipate such network activity from a search/analysis tool.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
The curl-based instruction is another explicit path for sending the registration payload to an external service, reinforcing that the skill operationalizes outbound transfer of locally derived identifiers. The risk is not the serialization advice itself, but that a non-authentication skill is directing transmission of device-linked data off-host as part of normal operation.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
This duplicate finding refers to the same persistence behavior: creating ~/.zlbx and preserving secret-bearing configuration for future automatic reuse. The danger is the same—local credential persistence beyond the user's immediate procurement query needs, with attendant risks of theft, unintended sharing, or opaque session continuation.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding refers to the same persistence behavior: creating ~/.zlbx and preserving secret-bearing configuration for future automatic reuse. The danger is the same—local credential persistence beyond the user's immediate procurement query needs, with attendant risks of theft, unintended sharing, or opaque session continuation.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The document prescribes exact Chinese text for the user-facing quota-exhausted message and says it must be output in that form. This is a natural-language policy issue because it enforces a specific language without indicating that the user can choose their preferred language or opt in to Chinese output.
This markdown file presents all instructions, parameter descriptions, and examples only in Chinese. Under the language/locale policy rule, forcing a single language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not stated here.
The example request body at L115 uses "ch": "s56", but the later mandatory instruction at L129 says the ch field must be fixed to "s01". This is an active contradiction in the documentation that could cause the agent to send a different attribution value than intended.
No suspicious patterns detected.