Back to skill

Security audit

医疗器械投标决策-医院采购投标评估

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed bid-analysis integration, but it needs review because it can register a device with a hardware-derived identifier, store an API key locally, and generate shareable reports containing signed links.

Review before installing. Use a manually provided ZLBX_API_KEY if possible to avoid auto-registration, understand that accepting auto-registration sends a hashed MAC-derived identifier to the vendor, and treat generated HTML reports as sensitive because they may contain signed access links and business analysis. If installed, restrict file permissions on ~/.zlbx/config.json and avoid sharing exported reports outside trusted recipients.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
references/report-template.md:91
Finding

Mandatory Promotional Content Hijacks Report Output

Content
View full analysis
' f'
📊 报告涉及企业的完整档案与更多商机,见 知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 投标决策分析 Skill 生成
' ) ``` ### Technical Analysis The Skill requires promotional referrals to external affiliated services after completing the requested analysis. The HTML renderer goes further by hardcoding these links into every generated report, without checking whether the user requested recommendations or promotional content. This behavior alters the expected output of the agent for a purpose separate from the core bid-analysis task. It constitutes instruction hijacking because loading the Skill imposes mandatory commercial messaging on the current session and generated artifacts. The links are not hidden, and this finding does not imply remote code execution. The security concern is unauthorized control over report content and destination referrals. ### Attack Path 1. A user loads the Skill and requests a bid analysis. 2. The Skill completes the legitimate data-analysis workflow. 3. The report instructions require an external-service referral to be appended. 4. The HTML renderer independently inserts affiliated promotional links into the generated artifact. 5. The user recei ...[truncated 630 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:100
Finding

Stable Hardware-Derived Device Fingerprint Is Transmitted to an External Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting value is sent to an external registration endpoint: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "bid-decision-1.0.5", "ch": "s76" } ``` ### Technical Analysis The registration workflow collects the operating-system platform, CPU architecture, and an unsalted SHA-256 hash of a physical network interface’s MAC address. Although the raw MAC address is not transmitted, hashing does not anonymize a stable hardware identifier. MAC addresses have constrained structure and include known vendor prefixes. A recipient can perform targeted enumeration or dictionary testing, particularly where the vendor or likely address range is known. The hash also remains stable across registrations, allowing persistent correlation of sessions from the same interface. The workflow does include an explicit consent gate and states that collection must not occur before consent. Therefore, this is not covert collection. However, hardware-derived fingerprinting is not necessary to perform bid analysis and exceeds t ...[truncated 1229 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:175
Finding

Plaintext API Key Persistence Lacks Required Filesystem Protections

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:138
Finding

Generated HTML Accepts Unvalidated URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` Representative call sites include: ```python f'{_link(x.get("title"), x.get("url"))}' ``` ```python bid_link = f'' if d.get("bid_url") else "" ``` ```python f'{esc(i.get("label"))}{_link(i.get("value"), i.get("url"))}' ``` ```python f'{_link(x.get("name"), x.get("url"))}
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向医疗招标项目的分析型技能,其核心价值应在于收集/处理历史招中标数据并产出投标决策判断。给定代码却是纯展示层工具:从输入 JSON 中读取已经生成好的分析结果,拼装 HTML,内联 CSS/Logo,并提供打印与保存长图功能。它没有网络访问、数据库查询、医疗领域特定判断、统计建模、规则引擎或任何分析计算逻辑。因此,该代码片段与声明的主要用途存在实质性不一致。虽然它生成的报告页面主题与“投标决策分析”相关,但只是下游渲染器,不足以代表声明中的技能实际能力。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation rule is overly broad because it says the skill must be used even when the user does not mention the medical domain explicitly, as long as hospital procurement is inferred. This can cause unintended invocation in adjacent contexts, leading to unnecessary external API use, unexpected cost consumption, and broader-than-expected transmission of user-supplied procurement data to third-party services.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话报告输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is advertised as a medical bid-decision analysis assistant, but this file adds account provisioning and registration workflows that are unrelated to that declared purpose. Expanding a skill into authentication, trial management, and account lifecycle actions increases attack surface and creates an unjustified capability boundary violation, especially because it changes user state and can initiate networked enrollment behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file directs collection of platform, CPU architecture, and a MAC-derived hash to create a device fingerprint for trial deduplication, despite this being unrelated to medical bidding analysis. Even with hashing, this is still device-derived telemetry sent off-host, and the context makes it particularly problematic because the skill’s declared purpose gives users no reason to expect hardware fingerprinting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section instructs the agent to persist API credentials to ~/.zlbx/config.json and immediately reuse them in-session, which exceeds the stated analytical-report purpose of the skill. Persistent credential writes are security-sensitive actions that alter the host environment and can outlive the user session, making the mismatch between declared capability and actual behavior materially dangerous.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 71)May include surrounding context.

python
THREAT_COLOR = {"高": "#c0392b", "中": "#b9770e", "低": "#0d9463"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill explicitly performs local file writes by generating and saving HTML reports, but it does not declare any tool scope such as permissions or allowed-tools. That creates an authorization gap: an agent runtime or reviewer cannot easily constrain or audit the skill's write capability, increasing the chance of unintended file creation or abuse if the skill is extended or invoked unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file requires a fixed output for post-install self-introduction and provides that required content only in Chinese, with wording such as '固定输出,缺一不可'. This enforces a specific language/locale behavior without user opt-in or an explicit documented regional justification in the instruction itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and all required user-facing example text are in Chinese, and the workflow directs the agent to output specific Chinese messages to users. There is no indication that the skill is region-locked or that users may opt into another language, which creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This finding reflects explicit instructions to send locally collected device features to an external endpoint. External transmission is dangerous here because the data flow is unrelated to the skill’s declared analytical purpose and is part of an undeclared registration pipeline, making the transmission contextually suspicious even if the payload is JSON-serialized safely.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

The skill instructs persistent storage of API keys under the user’s home directory and immediate reuse in the current session. Session persistence of credentials is risky because it modifies local state, can expose secrets to other local processes or future sessions, and is not justified by the skill’s declared purpose as a bid-analysis assistant.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

The skill instructs persistent storage of API keys under the user’s home directory and immediate reuse in the current session. Session persistence of credentials is risky because it modifies local state, can expose secrets to other local processes or future sessions, and is not justified by the skill’s declared purpose as a bid-analysis assistant.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The quota-exhaustion flow adds generation of auto-login and recharge links, which is outside the scope of bid-decision analysis and effectively turns the skill into an account monetization client. While less severe than fingerprinting or credential writes, it still broadens capability scope and encourages the agent to manage authentication and billing-adjacent actions not declared in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions mandate keeping signed sk parameters intact in all returned links while omitting any warning that those URLs may carry access-granting tokens. This encourages widespread redistribution of bearer-style links in reports and exported files, increasing the chance of unauthorized reuse through forwarding, screenshots, browser history, logs, or document sharing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly instructs the agent to preserve and redisclose full signed sk URL parameters in chat output, JSON, and exported HTML. If sk functions as an access-bearing token, this propagates credentials into user-visible artifacts that may be copied, shared, logged, or indexed, enabling unintended access to protected resources.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documentation expands normal conversational behavior into a workflow that writes JSON to disk and executes a local Python script to generate an HTML report. This increases attack surface by introducing file creation and code execution side effects from prompt-driven content, which can lead to unsafe local operations, data persistence, or abuse if inputs are not tightly controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template says full-mode HTML export should run by default and write a file, but provides no user-facing warning or consent step for this side effect. Default file generation can surprise users, leak sensitive bid-analysis data into local storage, and create shareable artifacts containing confidential business intelligence without deliberate approval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title and the entire workflow are written as a prescriptive Chinese-language execution manual, and there is no indication that users may choose another language or locale. Under the policy rule, forcing a specific language without opt-in is a natural-language policy concern unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s natural-language description and all generated UI text are fixed in Chinese, and the HTML output explicitly sets lang='zh-CN'. There is no indication that users can choose another language or that the locale restriction is documented as an intentional region-specific limitation, which conflicts with the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example request body uses "ch": "s76", but the nearby instruction says the ch field must be fixed to "s64". This is an active contradiction in the documentation that could cause the agent to send a different value than intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.