Back to skill

Security audit

信创与IT信息化采招分析-数字政府国产化选型情报

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a procurement-data assistant, but it also asks agents to register accounts, collect and transmit a device fingerprint, persist API keys locally, and append promotional links.

Review this skill carefully before installing. It can query procurement data, but if you have not configured an API key it may ask to create a trial account by sending a MAC-derived device hash to the provider and storing the returned key in ~/.zlbx/config.json. Prefer manually configuring your own API key if you do not want device-based registration or local plaintext credential persistence.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/auto-register.md:21
Finding

Collection and External Transmission of a Persistent Hardware Fingerprint

Content
View full analysis
continue to Step 1. Before consent, do not execute collection commands or send a registration request. mac_hash · Linux: iface=$(ls /sys/class/net | grep -vE '^(lo|docker|veth|br-|tun|tap)' | sort | head -n1) cat "/sys/class/net/$iface/address" 2>/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "tender-search-2.5.0", "ch": "s57" } ``` ### Technical Analysis The registration workflow instructs the agent to inspect physical network interfaces, read a MAC address, normalize it, calculate an unkeyed SHA-256 digest, and transmit that digest with operating-system and processor-architecture information to an external registration service. Hashing a MAC address does not anonymize it effectively. MAC addresses have limited entropy and structured vendor prefixes, making offline enumeration and correlation practical. The resulting stable digest remains a persistent pseudonymous device identifier that can correlate registrations or activity across sessions. The workflow does include an important consent gate and prohibits collection before approval. It also avoids transmitting the raw MAC address, hostname, username, home path, or file contents. These safeguards reduce the risk, but they do not eliminate it: - The description characterizes the fingerprint as having no identi ...[truncated 2347 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:497
Finding

Skill Instructions Force Promotional Redirection Into User Responses

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation rule is extremely broad, requiring use of the skill for nearly any IT, informationization, cloud, software, server, or security procurement discussion, even when the user does not mention the domain explicitly. Overbroad triggering increases the chance of unnecessary invocation of external data services, accidental disclosure of user queries, and execution of the skill in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs collection of device characteristics (platform, architecture, MAC-derived hash) and uses them to auto-register an account unrelated to the core procurement-analysis task. Collecting fingerprint-like identifiers and transmitting them to an external service increases privacy risk and can enable cross-session tracking or unintended account binding, especially when bundled into a default recovery flow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This document instructs the agent to perform automatic account registration, credential acquisition, and local credential persistence even though the skill’s stated purpose is procurement-data analysis. That scope expansion creates unnecessary security and privacy risk by turning a read/analysis skill into one that can create external accounts and modify local state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill collects device fingerprinting material—platform, architecture, and a hashed MAC-derived identifier—for trial deduplication, which is unrelated to procurement analysis. Even with hashing, this is still a stable device identifier suitable for tracking and correlating users across sessions, and the collection is initiated by the skill itself.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document directs the agent to call external registration and account-recovery endpoints, handle 401/429 lifecycle states, and guide users through login/account recovery flows. Those behaviors are outside the declared procurement-analysis function and increase the attack surface by enabling unsolicited external account actions and remote data transmission.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a procurement-analysis assistant, but it also instructs the agent to automatically register third-party accounts and persist API credentials to a local file when no key exists. That is a scope expansion into credential lifecycle management and local state mutation, which can create privacy, consent, and secret-handling risks if performed automatically or unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs automatic registration, device-feature collection, and writing a key to ~/.zlbx/config.json, while minimizing prompts and encouraging continuation after partial collection failures. Even though it mentions asking for consent, the overall flow does not provide a robust upfront warning about privacy implications, persistence on disk, retention, and how the credential will be used afterward.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file adds account-balance and usage-query functionality to a skill whose stated purpose is IT procurement and bid analysis, creating clear scope drift. Even though it does not directly expose the API key, it enables access to account metadata and usage telemetry unrelated to the user-facing task, which can leak operational/business information and broaden the attack surface if invoked by untrusted prompts or users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented get_company_contacts capability enables retrieval and display of project contact names, phone numbers, and recent bid links, which are privacy-sensitive business contact data. Although the doc mentions masked output for lower-tier accounts and says not to batch export, it does not require purpose limitation, user authorization checks, minimization, or stronger safeguards around collection and disclosure, so the skill could be used for unsolicited outreach, profiling, or data harvesting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, but it does not state that the skill is China-specific or offer users a language/locale option. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest frames this skill as focused on 信创、国产化、IT信息化 procurement scenarios such as servers, databases, operating systems, cloud, cybersecurity, and software. However, the documented capabilities for get_top_brands are centered on generic product analysis and repeatedly use 呼吸机 and medical-device examples, indicating the tool supports broader non-IT procurement analysis that is not justified by the stated skill purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest states this skill should be used for IT、信息化、国产化, and related procurement/bid analysis. In contrast, get_price_trends is documented with generic brand/model/product fields and primary examples for 呼吸机 and 迈瑞 SV300, showing a capability for general procurement price analysis rather than specifically IT procurement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents the skill documentation entirely in Chinese, starting from the title and continuing throughout, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file prescribes exact Chinese wording for user-facing consent text and later user messages, implying the skill should communicate in Chinese regardless of the user's preferred language. This is a natural-language locale policy concern because the document does not provide an opt-in, fallback, or alternative-language path.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This section explicitly instructs the agent to serialize collected device features and send them to an external auto-registration endpoint. Because the transmitted data includes a persistent hardware-derived identifier and initiates account creation unrelated to the skill’s core purpose, the outbound transmission is security-relevant and increases privacy risk.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The curl example reinforces and operationalizes the same external transmission behavior, making it easier to implement unsanctioned outbound registration requests. The danger is not the curl syntax itself but that it enables exfiltration of device-derived identifiers and external account actions outside the stated skill purpose.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill persists API keys to ~/.zlbx/config.json and instructs the agent to reuse them immediately. Storing long-lived credentials on disk from within a content-analysis skill is not inherent to its purpose and creates credential exposure risk if file permissions, local compromise, or multi-user environments are involved.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a local config directory and storing/reusing a credential plus metadata source marker. The security concern is durable credential retention and reuse in a skill that should not manage authentication state at this level.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a local config directory and storing/reusing a credential plus metadata source marker. The security concern is durable credential retention and reuse in a skill that should not manage authentication state at this level.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill generates auto-login/recharge links and steers users into phone-binding and payment-related flows, which are unrelated to procurement analysis. This broadens the skill from analysis into monetization/account management and can facilitate phishing-like user journeys or unintended account actions if misused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file requires outputting specific Chinese text to the user for recharge/login flow and even constrains formatting, but it does not offer language selection or say this skill is limited to Chinese-speaking users. That creates a language-policy issue applicable to all file types.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest emphasizes procurement/tender/bid data analysis for IT and Xinchuang scenarios. These lines expand the skill into broader web research such as company strategy, industry rankings, and policy impact analysis, which are not clearly grounded in the stated bid-data assistant role and introduce a broader capability surface than the manifest describes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The entire skill documentation, including headings, parameter explanations, examples, and usage instructions, is presented only in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.