T01 · Skill Instruction Hijacking
- Location
SKILL.md:470- Finding
Mandatory Commercial Referral and Final-Answer Manipulation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a real procurement-data purpose, but it also uses broad activation, device fingerprint registration, local API-key persistence, contact-phone access, and forced promotional referrals that users should review first.
Install only if you are comfortable with this provider handling procurement queries, optional contact-phone data, and an API key stored locally. Prefer supplying your own ZLBX_API_KEY through a secure secret mechanism; avoid automatic trial registration if you do not want a MAC-derived device hash sent to the provider, and treat any returned contact details as sensitive personal data.
SKILL.md:470Mandatory Commercial Referral and Final-Answer Manipulation
references/auto-register.md:33Hardware-Derived Device Fingerprint Collection and External Transmission
references/auto-register.md:173Plaintext API Key Persistence Without Required Permission Hardening
The trigger condition says the skill must be used for essentially any conversation involving procurement, bidding, suppliers, competitors, or related terms. Such broad activation increases the chance the skill is invoked in contexts the user did not intend, causing unnecessary data sharing with the external service and unintended execution of the skill's credential/account flows.
The auto-registration flow collects device characteristics including platform, architecture, and a MAC-derived hash to create an account. This is unnecessary for the stated bidding-analysis purpose and introduces fingerprinting/privacy risk, especially because the skill instructs collection and transmission of host-derived identifiers to a third-party service.
The skill description is written as a mandatory Chinese-only operating policy for the assistant's use of this skill, but it does not indicate that users may choose another language or locale for responses. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy concern unless the regional constraint is explicitly documented and justified.
The skill is presented as a procurement-data assistant, but it also instructs the agent to register accounts and persist API keys locally. That expands the agent's authority into credential management and stateful local modification, which can expose secrets, create accounts without clear user intent, and violate least-privilege expectations for a read-oriented analysis skill.
The skill directs the agent to read from and write to ~/.zlbx/config.json to source and persist API keys. Accessing local credential files and modifying them is outside the declared procurement-query role and creates a path for secret exposure, unauthorized persistence, and cross-session side effects on the host environment.
The manifest centers on using this skill for procurement, bidding, supplier, competitor, and market analysis based on the China Bidding dataset/service. These lines broaden the capability to general web research over company strategy, news, industry rankings, and policy impact, which is a materially different information source and capability not explicitly declared in the skill purpose.
The skill exposes a dedicated API to retrieve named project contacts and phone numbers, including procurement and award contacts, which goes beyond aggregate bid-analysis into direct personal data access. Although the docs mention masking for lower-tier accounts and advise not to batch export, the capability still enables targeted collection of individuals associated with procurement activity, creating privacy, profiling, and outreach abuse risks that are not clearly necessary for the manifest’s core analysis use cases.
The documentation includes only limited operational notes about masked numbers and not batch exporting, but it does not clearly frame project contact names and phone numbers as sensitive personal data or specify strict handling rules. In a procurement intelligence skill, that omission makes misuse more likely because operators may treat contact harvesting as a normal workflow instead of an exception requiring minimization, consent/legal basis review, and abuse prevention.
This markdown file is entirely written in Chinese and presents the API documentation in that language only, with no indication that other languages are supported or that the user can opt into a preferred locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is clearly documented and justified.
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions, parameter descriptions, and examples only in Chinese, with no user opt-in, alternative locale, or justification that the skill is region-specific and intentionally Chinese-only.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
This duplicate finding points to the same behavior: creating ~/.zlbx and storing an auto-issued API key for future use. In a skill context, persistent secrets materially expand impact compared with transient session use, because compromise of the host or home directory can expose reusable credentials.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding points to the same behavior: creating ~/.zlbx and storing an auto-issued API key for future use. In a skill context, persistent secrets materially expand impact compared with transient session use, because compromise of the host or home directory can expose reusable credentials.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The pseudocode omits the documented consent gate and proceeds directly from missing API key to device feature collection and a registration POST. In an agent skill, example pseudocode is often copied into implementation, so this creates a realistic risk of collecting and transmitting device-derived identifiers without explicit user consent.
L129 states the ch field must be fixed to "s01", but the surrounding request example uses "s50" (L115) and the pseudocode also hardcodes "s50" (L242). This is an active documentation contradiction that could cause an implementation to send a different value than the document says is required.
No suspicious patterns detected.