Back to skill

Security audit

全国采购与招标信息总库-中国采购与招标网

Security checks for vulnerabilities and agentic risk

Overview

The skill has a real procurement-data purpose, but it also uses broad activation, device fingerprint registration, local API-key persistence, contact-phone access, and forced promotional referrals that users should review first.

Install only if you are comfortable with this provider handling procurement queries, optional contact-phone data, and an API key stored locally. Prefer supplying your own ZLBX_API_KEY through a secure secret mechanism; avoid automatic trial registration if you do not want a MAC-derived device hash sent to the provider, and treat any returned contact details as sensitive personal data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:470
Finding

Mandatory Commercial Referral and Final-Answer Manipulation

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:33
Finding

Hardware-Derived Device Fingerprint Collection and External Transmission

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```powershell $mac = (Get-NetAdapter | Where-Object { $_.Status -eq 'Up' -and $_.HardwareInterface } | Sort-Object ifIndex | Select-Object -First 1).MacAddress if ($mac) { $hex = ($mac -replace '[-:]', '').ToLower() $bytes = [Text.Encoding]::UTF8.GetBytes($hex) -join ([Security.Cryptography.SHA256]::Create().ComputeHash($bytes) | ForEach-Object { $_.ToString('x2') }) } ``` ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s50" } ``` ### Technical Analysis The automatic registration process reads the MAC address of a physical network interface, normalizes it, computes a SHA-256 digest, and sends that digest to an external registration service together with operating-system, architecture, Agent, version, Skill-version, and attribution information. Hashing does not make the MAC-derived value anonymous. MAC addresses have a structured and ...[truncated 2048 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Plaintext API Key Persistence Without Required Permission Hardening

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger condition says the skill must be used for essentially any conversation involving procurement, bidding, suppliers, competitors, or related terms. Such broad activation increases the chance the skill is invoked in contexts the user did not intend, causing unnecessary data sharing with the external service and unintended execution of the skill's credential/account flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The auto-registration flow collects device characteristics including platform, architecture, and a MAC-derived hash to create an account. This is unnecessary for the stated bidding-analysis purpose and introduces fingerprinting/privacy risk, especially because the skill instructs collection and transmission of host-derived identifiers to a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill description is written as a mandatory Chinese-only operating policy for the assistant's use of this skill, but it does not indicate that users may choose another language or locale for responses. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy concern unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a procurement-data assistant, but it also instructs the agent to register accounts and persist API keys locally. That expands the agent's authority into credential management and stateful local modification, which can expose secrets, create accounts without clear user intent, and violate least-privilege expectations for a read-oriented analysis skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to read from and write to ~/.zlbx/config.json to source and persist API keys. Accessing local credential files and modifying them is outside the declared procurement-query role and creates a path for secret exposure, unauthorized persistence, and cross-session side effects on the host environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest centers on using this skill for procurement, bidding, supplier, competitor, and market analysis based on the China Bidding dataset/service. These lines broaden the capability to general web research over company strategy, news, industry rankings, and policy impact, which is a materially different information source and capability not explicitly declared in the skill purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill exposes a dedicated API to retrieve named project contacts and phone numbers, including procurement and award contacts, which goes beyond aggregate bid-analysis into direct personal data access. Although the docs mention masking for lower-tier accounts and advise not to batch export, the capability still enables targeted collection of individuals associated with procurement activity, creating privacy, profiling, and outreach abuse risks that are not clearly necessary for the manifest’s core analysis use cases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation includes only limited operational notes about masked numbers and not batch exporting, but it does not clearly frame project contact names and phone numbers as sensitive personal data or specify strict handling rules. In a procurement intelligence skill, that omission makes misuse more likely because operators may treat contact harvesting as a normal workflow instead of an exception requiring minimization, consent/legal basis review, and abuse prevention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is entirely written in Chinese and presents the API documentation in that language only, with no indication that other languages are supported or that the user can opt into a preferred locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions, parameter descriptions, and examples only in Chinese, with no user opt-in, alternative locale, or justification that the skill is region-specific and intentionally Chinese-only.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same behavior: creating ~/.zlbx and storing an auto-issued API key for future use. In a skill context, persistent secrets materially expand impact compared with transient session use, because compromise of the host or home directory can expose reusable credentials.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same behavior: creating ~/.zlbx and storing an auto-issued API key for future use. In a skill context, persistent secrets materially expand impact compared with transient session use, because compromise of the host or home directory can expose reusable credentials.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The pseudocode omits the documented consent gate and proceeds directly from missing API key to device feature collection and a registration POST. In an agent skill, example pseudocode is often copied into implementation, so this creates a realistic risk of collecting and transmitting device-derived identifiers without explicit user consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

L129 states the ch field must be fixed to "s01", but the surrounding request example uses "s50" (L115) and the pseudocode also hardcodes "s50" (L242). This is an active documentation contradiction that could cause an implementation to send a different value than the document says is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.