T01 · Skill Instruction Hijacking
- Location
SKILL.md:269- Finding
Mandatory Promotional Content and Referral Injection into Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a real procurement-search skill, but it also performs account setup, device fingerprinting, local API-key storage, and vendor referrals that deserve review before installation.
Review this skill before installing. Prefer configuring your own ZLBX_API_KEY instead of using auto-registration. If you use auto-registration, understand that the agent is instructed to send a stable MAC-derived device hash to the vendor and save an API key under your home directory. Also expect the skill to access procurement contacts, company and market intelligence, account usage data, and to occasionally append vendor referral links.
SKILL.md:269Mandatory Promotional Content and Referral Injection into Agent Responses
references/auto-register.md:7Stable Device Fingerprint Collection and Transmission Exceed Core Search Requirements
references/auto-register.md:173Plaintext API Key Persistence Without Mandatory Restrictive File Controls
The contact lookup endpoint exposes named project contacts and phone numbers, including a workflow encouraging display of masked or full contact data depending on account tier. In a procurement-search skill, this is materially more sensitive than notice retrieval and can enable privacy invasion, unsolicited outreach, profiling, or contact harvesting if invoked without strict purpose limitation and user authorization.
The documented flow collects device fingerprinting data (platform, CPU architecture, MAC-derived hash) and transmits it to an external service to de-duplicate trial accounts. Even if minimized and hashed, this is still host-derived telemetry unrelated to the core user goal of searching tenders, and it enables persistent device tracking across sessions.
The skill’s manifest describes a procurement-search capability, but this file adds account registration, login recovery guidance, quota handling, and credential lifecycle management. That materially expands the trust boundary and can cause the agent to perform sensitive identity and account actions the user did not expect from a search skill.
The file instructs the agent to create a directory in the user’s home folder and persist a newly obtained API key for future use, despite the manifest only advertising search. Writing credentials to disk creates lasting side effects, extends compromise duration, and changes user state beyond a normal search operation.
L003 says that whenever a user needs to search tender notices, procurement information, bid details, or track regional or industry project dynamics, the skill 'must' be used. Although domain-related, this activation description is still broad and lacks negative examples or explicit scope limits, which can cause unintended invocation across a wide range of common business research requests.
The skill’s declared purpose is procurement search, but it also instructs the agent to auto-register accounts and persist newly issued API credentials locally. That expands the trust boundary from read-only data retrieval into identity creation and credential handling, which can create accounts or store secrets on the user’s machine without sufficiently explicit, informed consent about persistence and side effects.
The skill directs collection of device characteristics (platform, architecture, and a MAC-derived hash) to obtain an API key, even though those signals are not necessary for the core procurement-search function. Collecting hardware fingerprints increases privacy risk and enables user/device tracking beyond what is proportionate for a search skill.
The document contains contradictory instructions: one section says auto-registration should occur only when no key is configured, while another says to re-enter the same flow even when an existing key fails. In practice, this ambiguity can cause unintended account creation, credential replacement, or overwriting a valid user-managed setup during ordinary error handling.
The skill instructs writing an API key to ~/.zlbx/config.json without a prominent user-facing disclosure that credentials will be stored persistently on disk. Silent or under-disclosed secret persistence can surprise users, increase exposure to local compromise, and create long-lived credentials that outlast the immediate task.
The file documents account-balance and usage-consumption APIs inside a skill whose declared purpose is procurement/tender search. This creates unnecessary privilege and scope expansion: an agent instructed to use this skill for search tasks may also access billing and account telemetry that is unrelated to the user’s request. In an agent environment, such overbroad capabilities increase the chance of unauthorized data access and cross-function misuse.
Documenting balance, recharge, and cumulative consumption access is not justified by the skill’s stated procurement-search function. Even if the API key is not exposed, the skill grants an agent the ability to inspect sensitive account metadata, which can reveal business usage patterns, account status, and enable actions or disclosures outside user intent. This is a classic excessive-capability / scope-creep issue.
Daily consumption analytics are unrelated to tender/procurement search and expose account operational telemetry such as usage trends and call volumes. In an agent setting, this data can leak organizational behavior, workload patterns, or internal budget/usage information to contexts that only needed search results. The mismatch between declared purpose and implemented/documented capability makes misuse more likely.
The file documents a broad company-intelligence surface far beyond the manifest’s stated purpose of tender/procurement notice retrieval. This kind of scope expansion increases the chance that an agent will access and use sensitive business, registry, relationship, or contact data in contexts the user did not request or expect, undermining least-privilege and informed consent.
The documentation instructs the agent to automatically match a shorthand company name to multiple related entities and proceed with downstream analysis without user confirmation. This can cause misattribution, unintended inclusion of affiliates or subsidiaries, and silent expansion of the query scope, producing inaccurate or privacy-invasive analysis on entities the user did not mean to include.
Registry and company-profile features expand the skill from procurement notice search into broader corporate intelligence, including business status, legal representative, capital, tags, and operational details. While some of this may be publicly sourced, bundling it into a skill advertised for tender retrieval creates a scope mismatch that can mislead users and cause over-collection or overuse of data beyond the requested task.
Competitor analysis and potential bidder recommendation go beyond passive retrieval into strategic intelligence and decision support. In the context of a procurement-search skill, these features can be used to profile rivals, infer market strategy, or automate sensitive commercial targeting that users may not realize the skill is capable of performing.
The file documents market-intelligence APIs such as top purchasers, top suppliers, brand market share, and price trends, which go beyond the declared purpose of a procurement notice search skill. This expands the skill from retrieval into competitive/commercial intelligence, creating a capability mismatch that can enable unintended profiling, market analysis, or sensitive business inference if the agent is instructed to use all documented functions.
The file title and all user-facing documentation are written entirely in Chinese, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule for language/locale constraints, this can constitute a natural-language policy violation when no user opt-in or justification is provided.
The skill inspects environment variables and a config file in the user’s home directory to discover credentials before performing its primary function. Reading local secrets/config outside the declared search scope increases exposure of sensitive material and teaches the agent to probe the local environment for auth state.
The document prescribes exact Chinese text to present to users and later repeats required Chinese output templates, but it does not indicate that the skill is China-specific or provide any user opt-in for language selection. This creates a natural-language policy concern because the skill appears to force a specific language regardless of user preference.
This section documents sending collected device features and agent metadata to an external domain during auto-registration. In context, the danger is not the use of JSON serialization itself, but the exfiltration of local host-derived data and account bootstrap metadata to a third-party service from within a search skill.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
The alternative example using curl likewise represents externally transmitting registration payload data off-host. In this skill’s context, external transmission is more dangerous because it accompanies collection of local system identifiers unrelated to the declared procurement-search function.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
This duplicate finding points to the same persistence behavior: creating ~/.zlbx, merging config, and marking source='auto' so future sessions can silently reuse the credential. In context, that persistence is more dangerous because it is embedded in a skill whose advertised purpose is merely searching procurement notices, not managing durable authentication state.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding points to the same persistence behavior: creating ~/.zlbx, merging config, and marking source='auto' so future sessions can silently reuse the credential. In context, that persistence is more dangerous because it is embedded in a skill whose advertised purpose is merely searching procurement notices, not managing durable authentication state.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
Manifest 说明的范围是招标公告、采购信息、标讯详情及项目动态检索,而这里进一步扩展到官网/新闻/政策等开放互联网分析能力。此类通用网络研究虽可能有助于回答,但并非该技能声明中直接承诺或必要的核心能力。
No suspicious patterns detected.