Back to skill

Security audit

供应商资质核查-履约能力一查便知

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent supplier-reporting purpose, but it also collects a device fingerprint, persists service credentials, and emits signed access links in ways users should review before installing.

Install only if you are comfortable using the Zhiliaobiaoxun service for supplier due diligence, sending company search terms to its API, and storing an API key locally. To reduce exposure, configure your own ZLBX_API_KEY instead of auto-registration, avoid forwarding reports with sk signed links unless recipients should have access, and treat contact details and generated HTML reports as business-sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
scripts/render_report.py:477
Finding

Unconditional Promotional Output and External Platform Redirection

Content
View full analysis
' f'
📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成
' ``` ### Technical Analysis The Skill mandates promotional referrals and cross-product recommendations that are not required to perform supplier qualification analysis. The renderer inserts these calls to action and external links into every generated report without checking whether the user requested promotional information or consented to its inclusion. This alters the expected output objective from producing a neutral supplier-assessment report to also advertising the operator's other products. Because the behavior is enforced both by the Skill instructions and by executable rendering code, an agent following the Skill cannot omit it on a per-report basis. ### Attack Path 1. A user asks the agent to investigate a supplier. 2. The agent loads the Skill and follows its mandatory report-generation workflow. 3. The renderer automatically adds promotional calls to action and external platform links. 4. The user receives advertising and redirection content as part of an ostensibly neutral audit report. 5. If the report is shared, the injected promotion propagates to additional recipients. ### Impact Assessment This issue compromises output integrity and user autonomy. It does not grant operating-system privileges or code execution, but it gives the Skill operator persistent influence over agent output and tur ...[truncated 168 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:38
Finding

Persistent MAC-Derived Device Fingerprint Sent to an External Registration Service

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting value is included in the external registration request: ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s117" } ``` ### Technical Analysis The registration workflow reads a physical network interface's MAC address, normalizes it, hashes it with SHA-256, and transmits the resulting stable identifier to `ai.zhiliaobiaoxun.com`. Hashing a MAC address does not make it anonymous. MAC addresses have a constrained input space, include vendor-identifying prefixes, and can often be tested through enumeration. The hash remains a stable cross-session identifier suitable for device correlation. The documentation requires user consent before collection, which mitigates covert execution. However, the fingerprint is not necessary for the Skill's core supplier-intelligence function. It supports the service provider's trial-abuse prevention and therefore exceeds the minimum data access needed to generate a supplier report. ### Attack Path 1. The Skill fails to find an API key in the environment or local configuration. 2. It asks the user to approve automatic trial registration. 3. After approval, the agent reads the host's operating-system type, CPU architecture, and physical-interface MAC address. 4. The MAC address is normalized and hashed locally. 5. The stable hash and other device attributes are sent to the external registr ...[truncated 546 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:170
Finding

API Key Persistence Without Required Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:168
Finding

Generated Reports Accept Executable URL Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` The same pattern is used for risk-source links: ```python src_html = ( f'来源:{esc(src)}' if src else "" ) ``` ### Technical Analysis The renderer HTML-escapes URL values before inserting them into `href` attributes. This prevents direct quote-based attribute breakout, but it does not validate the URL scheme. A value such as `javascript:...` remains a valid HTML attribute after escaping. If a user clicks that link, the browser may execute script in the context of the generated local report. Unsafe `data:` URLs can pose similar risks depending on browser behavior. The affected values can originate from API responses, WebSearch-derived risk sources, or report JSON assembled by the agent. Treating those sources as trusted creates an upstream-content-to-local-HTML execution path. The use of `target="_blank"` without `rel="noopener noreferrer"` also allows a newly opened page to retain a reference to the opener in browser environments that do not implicitly isolate it. ### Attack Path 1. A malicious or compromised upstream source supplies a crafted URL using an executable or otherwise unsafe scheme. 2. The agent includes the URL in report JSON as a company, citation, announcement, or risk-source link. 3. `_link` or `_risk_list` inserts the value into an HTML `href` attribute without scheme validation. 4. A recipient opens the generated report. 5. The recipient clicks the crafted link. 6. The browser processes the dangerous URL, potentially executing script or opening attacker-controlled content with an opener relationship. ### Impact Assessment Successful exploitation ca ...[truncated 403 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/render_report.py:562
Finding

Predictable Report Output File Can Follow a Symbolic Link

Content
View full analysis
|\s]+', "_", data.get("report_title", "企业情报"))[:60] suffix = "企业对比" if data.get("mode") == "compare" else "企业情报" out = os.path.join(args.outdir, f"{safe}_{suffix}.html") with open(out, "w", encoding="utf-8") as f: f.write(render(data)) print(out) ``` ### Technical Analysis The output filename is predictably derived from the report title. The file is then opened with ordinary write mode, which follows symbolic links and truncates an existing target. If another local principal can write to the output directory, or if the directory itself has unsafe ownership or permissions, that principal can pre-create the expected filename as a symbolic link. The renderer will follow the link and overwrite the linked file. Filename sanitization prevents straightforward path traversal through the title, but it does not prevent symbolic-link attacks, unsafe preexisting output directories, or replacement of an existing report. ### Attack Path 1. An attacker predicts the sanitized report filename from the company name. 2. The attacker creates that filename in the output directory as a symbolic link to another file writable by the victim. 3. The victim runs the renderer. 4. `open(out, "w")` follows the symbolic link and truncates the target. 5. The renderer replaces the target's contents with generated HTML. ### Impact Assessment The attacker can overwrite files that the victim process is authorized to modify. The attack does not increase the victim's operating-system privileges, so it cannot overwrite files beyond the victim's existing permissions. Its scope depends on whether an attacker can modify the report output directory. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (25)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document claims that no collection or registration may happen before user consent, but the pseudocode later performs feature collection and auto-registration directly when no key is found. This mismatch is dangerous because implementers may follow the pseudocode and silently collect/transmit device data without the promised consent gate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file instructs the agent to collect device fingerprints such as platform, architecture, and a hashed MAC address, then use them to create or recover accounts. Even with hashing, this is device-derived tracking data unrelated to supplier due diligence, and it enables identity binding and external transmission beyond the skill's stated purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This document adds account provisioning, credential storage, session continuation, and recharge-link generation to a skill whose declared purpose is supplier qualification checking. That scope expansion is dangerous because it gives the skill authority to persist secrets and alter user account state without being necessary for the business function, increasing the attack surface for credential abuse and unauthorized account actions.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The template explicitly requires preserving and exposing full URLs containing sk login-bypass or bearer-style access parameters in user-visible output and exported artifacts. These tokenized links can function as access credentials; disclosing them broadly enables unauthorized sharing, replay, indexing, or leakage through logs, chat history, screenshots, and third-party referrers.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

python
# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill performs local file writes by generating HTML reports in a user directory, but it does not declare any tool scope such as permissions or allowed-tools. That creates a least-privilege gap: an agent may be allowed broader filesystem capabilities than the skill actually needs, increasing the blast radius if the skill is misrouted, prompt-injected, or modified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill repeatedly states it 'must' be used for a wide range of supplier, partner, and company-verification requests, including cases where the user did not explicitly ask for qualification review. This broad routing scope can cause over-invocation, sending company names and related queries to an external API in situations where a narrower or local workflow would suffice, increasing privacy, billing, and unintended-action risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The self-introduction section mandates fixed reply content in Chinese and marks it as required, but does not provide user opt-in or language alternatives. This is a locale/language policy concern because it imposes a specific language regardless of the user's preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly instructs operators to output signed url values "as-is" and not modify them, but provides no warning that these links may function as bearer-style access tokens via the embedded sk parameter. In a supplier due-diligence skill, those links may expose company or procurement records to unintended recipients if copied into reports, chats, or external systems, creating access-control and data-sharing risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents retrieval and display of project contact phone numbers, including instructions to show the returned number exactly as provided, but does not require any privacy notice, lawful-basis check, or purpose limitation before exposing personal contact data. In this procurement intelligence context, the feature materially increases the chance of doxxing, unsolicited outreach, or bulk harvesting of individuals' phone numbers from bidding records.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example required before consent is written as fixed Chinese user-facing copy, and later sections also prescribe fixed Chinese output text for user interactions. The document does not indicate that the agent should match the user's language or ask for language preference, which can violate language/locale policy when used with users in other languages.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example request body uses "ch": "s117" at L115, but L129 states the ch field must be fixed to "s105". This is an active documentation contradiction about what value the code should send, affecting request behavior and intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The file explicitly instructs the agent to send collected device features to an external service. External transmission of device-derived identifiers is sensitive in this skill context because supplier qualification checking does not require outbound registration telemetry, and the transmission can occur as part of hidden onboarding behavior.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The curl -d @file guidance is another path for external transmission of the same device-derived payload to the registration endpoint. The risk is not the serialization advice itself, but that the skill operationalizes sending fingerprinting data off-device for unrelated account creation.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicated finding points to the same credential-persistence behavior: creating ~/.zlbx and merging in an auto-obtained API key for later use. In the context of a supplier-checking skill, hidden token storage is unjustified and creates ongoing exposure of account credentials beyond the immediate task.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicated finding points to the same credential-persistence behavior: creating ~/.zlbx and merging in an auto-obtained API key for later use. In the context of a supplier-checking skill, hidden token storage is unjustified and creates ongoing exposure of account credentials beyond the immediate task.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file begins with a Chinese-language report template and instructs a fixed output format without offering any language selection. This can violate language/locale policy because it forces a specific language regardless of user preference or locale.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template instructs the agent to write JSON to a temporary file and execute a local Python script to generate an HTML report by default. That expands the skill from information analysis into filesystem write and code-execution behavior, which increases attack surface and can be abused for unauthorized file creation, unsafe script invocation, or execution in environments where tool use should remain read-only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template requires creating an HTML file on the local system by default and disclosing its path to the user, without explicit consent or clear warning. Silent file creation can violate user expectations, leak local environment details, and create persistence or data-handling risks in contexts where the user only requested an on-screen supplier review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Line L096 uses a mandatory instruction ('强制') that fixes the response wording for risk statements, and the document as a whole is written as a prescriptive Chinese-language execution manual. This can violate language/locale policy when a skill forces a specific language or phrasing without offering the user a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Natural-language strings throughout the script, including the module description, UI labels, and generated HTML metadata, are fixed in Chinese, and the document language is set to zh-CN. This enforces a specific language/locale policy without any mechanism for user selection or documented justification of a locale restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L004 states the full report should be output only once and then stop, implying a single-pass conversational output. Lines L178-L185 then instruct the skill to additionally generate an HTML report by default and tell the user the filesystem path, which contradicts the earlier 'write once and stop' instruction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code creates an output directory and writes a rendered HTML file that may include contacts, risks, and company profile data. Although file output is the script's purpose, there is no explicit user-facing disclosure in the execution flow about where sensitive report content will be stored beyond printing the path afterward.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.