Back to skill

Security audit

智慧交通与轨道交通采招分析-基建商机雷达

Security checks for vulnerabilities and agentic risk

Overview

The skill provides procurement data lookup, but it deserves review because it can register devices with a stable hardware-derived identifier, persist an API key locally, expose contact data, and add tracked promotional links.

Install only if you are comfortable with this service making external procurement-data requests, creating or using a local API credential, and, for automatic free-trial setup, sending a stable MAC-derived hash for device de-duplication. Prefer manually setting ZLBX_API_KEY if you want to avoid auto-registration, and review contact-data use for compliance before retrieving or exporting business contacts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:472
Finding

Mandatory Promotional Output and External Referral Tracking

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:42
Finding

Deterministic Hardware Fingerprint Collection and Remote Transmission

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` ```powershell # Windows $mac = (Get-NetAdapter | Where-Object { $_.Status -eq 'Up' -and $_.HardwareInterface } | Sort-Object ifIndex | Select-Object -First 1).MacAddress if ($mac) { $hex = ($mac -replace '[-:]', '').ToLower() $bytes = [Text.Encoding]::UTF8.GetBytes($hex) -join ([Security.Cryptography.SHA256]::Create().ComputeHash($bytes) | ForEach-Object { $_.ToString('x2') }) } ``` The derived value is transmitted in this registration request: ```http POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json ``` ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s58" } ``` ### Technical Analysis The workflow reads the MAC address of a physical network interface, normalizes it, calculates an unsalted SHA-256 digest, and transmits that digest to a third-party registration service together with platform, CPU architecture, Agent metadata, Skill version, and channel attribution. An unsalted hash of a MAC address is pseudonymous rather than anonymous. MAC addresses have constrained structure and include manufacturer ...[truncated 1991 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Plaintext API Key Persistence Without Required File-Permission Hardening

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
references/auto-register.md:96
Finding

Contradictory Registration Channel Attribution Values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s activation criteria are intentionally expansive, including cases where the user does not explicitly mention transportation as long as the request is vaguely related to procurement, bidding, or equipment. This can cause inappropriate auto-invocation on unrelated enterprise or procurement queries, leading to unnecessary data access, account actions such as prompting for auto-registration, and reduced user control over tool usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill content is written to operate in Chinese and provides fixed Chinese-language guidance without any indication that it should respect the user’s language preference. This can mislead users, reduce informed consent around registration/privacy prompts, and increase the chance that important account or data-handling notices are not understood.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented flow performs automatic semantic matching on short company names and then expands analysis across headquarters and subsidiaries without user confirmation. This can cause over-collection, incorrect attribution, and unintended querying of multiple entities, especially when abbreviations are ambiguous or commercially sensitive.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The get_company_contacts API enables retrieval of named project contacts and phone numbers tied to bidding activity, which goes beyond aggregate transit market analysis into personal contact discovery. Even with masked numbers for trial users, the feature facilitates targeted outreach and harvesting of individual contact data, increasing privacy and misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The contact lookup documentation describes returning personal contact information but does not foreground a strong privacy warning, acceptable-use restriction, or consent/legal-basis requirement. In a procurement intelligence skill, this makes it easy for users to treat personal contact retrieval as a routine enrichment step, increasing privacy and outreach abuse risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire API documentation is written in Chinese, including headings, parameter descriptions, and examples, with no indication that the skill supports other languages or that Chinese is a required locale. Under the policy, a skill that effectively mandates a specific language without user opt-in or explicit justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest frames this skill as a rail transit / smart transportation / highway / ETC / signaling procurement analysis assistant, but this file documents generic market-analysis endpoints using examples and schemas for unrelated domains such as ventilators, servers, and large language models. That indicates the skill's described behavior is broader than the transport-focused purpose users are told to expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest emphasizes transportation procurement and bidding analysis, but this section documents historical pricing and brand/model analysis for arbitrary products, with concrete examples for medical devices and servers. This is a semantic scope expansion of the skill's claimed purpose rather than an implementation detail necessary for transport analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document provides mandatory user-facing wording in Chinese and repeatedly instructs the agent to output specific Chinese text to the user. There is no indication that the user can choose another language or that the locale restriction is justified as region-specific, which conflicts with the language/locale policy rule.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill instructs the agent to transmit device-derived identifiers and metadata to an external service during auto-registration. Even though the document claims privacy minimization and requires user consent, this is still external data transmission of host fingerprints, which is security-relevant because it expands the trust boundary and can leak persistent device correlation data.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The explicit curl-based guidance reinforces that the workflow is designed to send registration payloads to an external endpoint. The danger is contextual: the payload contains persistent device-linked data and creates an account automatically, so a compromised or overly permissive agent could transmit system-derived information without the user fully understanding the consequences.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding points to the same persistence behavior: creating ~/.zlbx, merging config, writing source metadata, and continuing to use the stored API key without restart. The risky part is credential persistence and session continuity, which can outlive the user's expectation and broaden the blast radius if the local environment is shared or compromised.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate finding points to the same persistence behavior: creating ~/.zlbx, merging config, writing source metadata, and continuing to use the stored API key without restart. The risky part is credential persistence and session continuity, which can outlive the user's expectation and broaden the blast radius if the local environment is shared or compromised.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This section requires the agent to present a fixed Chinese message and link-handling instructions to the user. Because the file does not offer a language choice or document a justified locale constraint, it constitutes a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The entire skill documentation, examples, parameter descriptions, and prescribed user-facing phrases are presented only in Chinese, including explicit output text such as '充值可查看完整联系方式'. There is no indication that users may choose another language or locale, which can constitute a language-policy issue when no opt-in is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions, parameter descriptions, and examples exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.