Back to skill

Security audit

政府采购招标大数据分析-政采商机与中标洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill provides legitimate procurement-data analysis, but its onboarding path collects a hardware-derived device identifier and stores a bearer API key locally in ways users should review before installing.

Install only if you are comfortable with this vendor's API, local API-key storage, and the opt-in auto-registration flow that sends a MAC-derived hash for trial-account deduplication. Prefer setting your own ZLBX_API_KEY manually and review ~/.zlbx/config.json permissions if you use the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:269
Finding

Mandatory Promotional Output and Tracked Vendor Redirection

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/auto-register.md:33
Finding

Transmission of a Stable Hardware-Derived Device Fingerprint

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The macOS workflow similarly hashes the first discovered hardware address: ```bash ifconfig | awk '/ether/{print $2; exit}' \ | tr -d ':' | tr 'A-Z' 'a-z' \ | shasum -a 256 | awk '{print $1}' ``` The resulting identifier is transmitted with operating-system and architecture information: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s56" } ``` ### Technical Analysis A SHA-256 hash of a MAC address remains a stable hardware-derived identifier. MAC addresses have a small, structured input space and are not secrets, so hashing them does not provide the same anonymity as hashing high-entropy random data. A service that receives the digest can use it to recognize repeated registrations from the same physical interface. The workflow also transmits the operating-system platform, CPU architecture, agent type, agent version, Skill version, and a channel-attribution value. Together, these attributes provide a persistent device and client fingerprint. The collection is limited to the missing-key registration branch and the documentation requires explicit consent before collection. It also avoids tra ...[truncated 1864 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Plaintext API Key Persistence Without Required File-Permission Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation rule is overly broad and mandates use whenever loosely related government/procurement terms appear, even if the user did not request this specific service. Over-broad invocation increases unnecessary data exposure to the third-party backend and raises the chance the skill is triggered in contexts where its credential handling and account bootstrap logic become active without clear user expectation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs collection of device fingerprint attributes (platform, arch, mac_hash) for auto-registration even though its primary purpose is procurement analytics. Collecting hardware-derived identifiers for account provisioning creates unnecessary privacy risk and enables persistent tracking; the instruction to substitute empty strings on failure also normalizes collection attempts rather than data minimization.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document instructs the agent to collect device fingerprints, create remote trial accounts, and persist credentials locally before performing the advertised procurement-analysis function. This is a material scope expansion: even with disclosure text, the skill is embedding identity/account bootstrapping and host-level data collection that are not necessary to answer procurement queries, increasing privacy and security risk if the workflow is triggered automatically or implemented incorrectly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow directs the agent to write an API key to ~/.zlbx/config.json and immediately reuse it in the current session. Persisting authentication material on disk from within a data-analysis skill creates credential-handling and local secret-storage behavior outside the skill's stated purpose, and can expose the key to other local processes, accidental disclosure, or misuse if file permissions and lifecycle controls are not enforced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language description is entirely in Chinese and instructs mandatory use behavior, but does not offer any language or locale choice for users who may be interacting in another language. Under the policy, forcing a specific language without opt-in is a locale/language policy issue unless clearly justified and documented.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s documented behavior goes beyond procurement-data querying and includes credential acquisition, account creation, and local API key persistence. That materially expands the trust boundary: a data-analysis skill is being authorized to provision access and write secrets to disk, which can surprise users and create opportunities for unauthorized account creation or misuse of credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest centers this skill on government procurement and bidding data queries and analysis. The documentation adds broader internet research on company strategy, news, industry rankings, and policy impacts via WebSearch, which goes beyond the described procurement-data platform role.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file adds account-balance and usage-consumption functionality to a skill whose declared purpose is government procurement and bid-data analysis. That scope expansion enables access to billing and account metadata unrelated to the user task, violating least privilege and increasing the chance an agent will disclose or act on sensitive account information without a procurement-specific need.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs the agent to read an API key from environment variables or agent configuration to perform account queries unrelated to the stated procurement-analysis function. Even though it says not to reveal the key, teaching a broadly scoped skill to access ambient credentials for out-of-scope actions increases the risk of unauthorized use of privileged secrets and unintended access to account data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly tells the agent to automatically aggregate all semantically matched companies, including headquarters and affiliates, and continue analysis without user confirmation. In a procurement context, this can easily cause entity-mixup, overbroad data collection, and incorrect competitive or supplier intelligence about the wrong legal person, which may mislead business decisions or expose data beyond the user's intended scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The contact lookup feature enables retrieval of named project contacts and phone numbers, but the documentation only discusses masking tiers and upsell behavior, not privacy, purpose limitation, or restrictions on handling personal data. In this government procurement and business-intelligence skill, that omission increases the risk of using personal contact data for unsolicited outreach, bulk harvesting, or other privacy-invasive uses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all usage instructions, parameters, and examples only in Chinese. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill contains account lifecycle functions such as signup, recovery handling, and recharge-link generation that are unrelated to procurement analysis and expand the attack surface into authentication and billing flows. Even if intended for user convenience, embedding these flows in a skill increases the chance of phishing-like UX, unintended account manipulation, or unsafe handling of auth artifacts such as recovery hints and auto-login links.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This section explicitly instructs external transmission of collected device features to a remote auto-registration endpoint. Although the text attempts data minimization, the skill context makes this more dangerous because a procurement-analysis assistant is not expected to exfiltrate host-derived identifiers to third-party infrastructure, and users may not anticipate such network activity from a search/analysis tool.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The curl-based instruction is another explicit path for sending the registration payload to an external service, reinforcing that the skill operationalizes outbound transfer of locally derived identifiers. The risk is not the serialization advice itself, but that a non-authentication skill is directing transmission of device-linked data off-host as part of normal operation.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding refers to the same persistence behavior: creating ~/.zlbx and preserving secret-bearing configuration for future automatic reuse. The danger is the same—local credential persistence beyond the user's immediate procurement query needs, with attendant risks of theft, unintended sharing, or opaque session continuation.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding refers to the same persistence behavior: creating ~/.zlbx and preserving secret-bearing configuration for future automatic reuse. The danger is the same—local credential persistence beyond the user's immediate procurement query needs, with attendant risks of theft, unintended sharing, or opaque session continuation.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document prescribes exact Chinese text for the user-facing quota-exhausted message and says it must be output in that form. This is a natural-language policy issue because it enforces a specific language without indicating that the user can choose their preferred language or opt in to Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructions, parameter descriptions, and examples only in Chinese. Under the language/locale policy rule, forcing a single language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not stated here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example request body at L115 uses "ch": "s56", but the later mandatory instruction at L129 says the ch field must be fixed to "s01". This is an active contradiction in the documentation that could cause the agent to send a different attribution value than intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.