Back to skill

Security audit

企业情报-招投标视角的企业背调

Security checks for vulnerabilities and agentic risk

Overview

This skill largely does the advertised company-intelligence work, but it also collects a stable device identifier, stores an API key locally, and creates shareable reports with access-bearing links, so it needs review before installation.

Install only if you are comfortable sending company search terms to the vendor, letting the skill create a local config file containing an API key, and sharing reports that may contain signed access links. Prefer providing your own API key, protect ~/.zlbx/config.json, avoid forwarding generated HTML reports outside intended recipients, and use contact data only for authorized business purposes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
references/report-template.md:189
Finding

Mandatory Vendor Promotion Hijacks Report Output

Content
View full analysis
' f'
...' f'...' f' ... ... ...
' # Remaining footer content omitted because it does not alter the finding. ) ``` The template additionally labels the monitoring prompt as fixed output and directs the Agent to append a general commercial-platform recommendation after reports. ### Technical Analysis The Skill's core declared function is to produce company-intelligence reports. However, its instructions require the Agent to append vendor promotion, cross-selling recommendations, recurring-monitoring suggestions, and external platform links. This behavior changes the Agent's normal response policy when the Skill is loaded and is not necessary to fulfill the requested company analysis. The output manipulation is implemented at two levels: 1. Instruction-level requirements direct the Agent to append promotional recommendations. 2. The HTML renderer hardcodes vendor calls to action, making them unavoidable for generated reports. This is instruction hijacking because the Skill imposes unrelated output goals on the active session. It does not appear to override safety controls, but it persistently modifies the user's requested output for the vendor's benefit. ### Attack Path 1. A user invokes the Skill for a company-intelligence report. 2. The Agent loads the mandatory report-template instructions. 3. The ...[truncated 721 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:56
Finding

Stable Hardware Fingerprint Is Transmitted During Automatic Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The resulting hash is included in an external registration request: ```json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "company-intel-1.0.2", "ch": "s107" } ``` The documented destination is: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register ``` ### Technical Analysis A SHA-256 hash of a MAC address is still a stable hardware-derived identifier. MAC addresses have a constrained structure and limited entropy, so hashing does not provide strong anonymization. A party that knows or guesses a candidate MAC address can hash it and compare the result. The identifier is not necessary to perform company-intelligence searches or render reports. It is used for trial-account deduplication, which is a vendor account-management objective rather than a minimum technical requirement of the report function. The documentation does include a meaningful mitigation: collection and transmission are gated on explicit user consent when no API key is present. Nevertheless, the consent language characterizes the fields as having no identity significance, which understates the persistent correlation capability of `mac_hash`. ### Attack Path 1. The Skill checks for an API key in the environment and local configuration. 2. If no key exists, it asks the user to approve automatic trial registration. 3 ...[truncated 901 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Plaintext API Key Is Persisted Without Required File-Permission Protections

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:168
Finding

Untrusted URLs Are Inserted into HTML Attributes Without Quote Escaping or Scheme Validation

Content
View full analysis
str: return _esc(str(s if s is not None else "")) ``` ```python def _link(text, url): return f'{esc(text)}' if url else esc(text) ``` ```python def _risk_list(risks) -> str: lis = [] for r in risks or []: if isinstance(r, str): text, src = r, "" else: text, src = r.get("text", ""), r.get("source_url", "") src_html = ( f'Source: {esc(src)}' if src else "" ) lis.append(f"
  • {esc(text)}{src_html}
  • ") return f'
      {"".join(lis)}
    ' if lis else "" ``` Equivalent URL insertion is also used for company-profile, contact-note, comparison, bid, and citation links. ### Technical Analysis `xml.sax.saxutils.escape()` escapes `&`, `<`, and `>` by default, but it does not escape quotation marks unless a custom entity mapping is supplied. The renderer places escaped values inside double-quoted `href` attributes. A URL containing a double quote can therefore terminate the `href` value and inject a new HTML attribute. For example, a malicious value structurally equivalent to the following can add an event handler: ```text https://example.invalid/" onmouseover="ATTACKER_CODE ``` The renderer also does not validate the URL scheme. Therefore, values using dangerous or unintended schemes may be rendered as clickable links, depending on browser handling. The URLs originate from API responses and public web-search results. Those sources should not be considered inherently safe, partic ...[truncated 1345 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    • Rogue AgentSelf-Modification, Session Persistence
    Findings (19)

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

    md
    默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版报告并告知保存路径(详见 report-template.md「HTML 报告导出」)。
    

    Obfuscated Code

    High
    Category
    Supply Chain
    Confidence
    50% confidence
    Finding

    Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

    Content

    Scanner excerpt · scripts/render_report.py (reported line 93)May include surrounding context.

    python
    # 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
    _LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP78wvsqTlz7SHIwnHFIBMFwasSixrOMY2qVS92yUcKi2zFnt02f/tOW757j23PO2hZxL
    ...[truncated 27 chars]
    

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    88% confidence
    Finding

    The skill explicitly instructs the agent to write HTML reports to a local directory and references a renderer script, but it declares no tool-scope restriction such as allowed-tools or permissions. That mismatch increases the chance an agent with broader ambient capabilities could perform unintended filesystem writes beyond the intended report output, especially because the skill is treated as executable guidance.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    83% confidence
    Finding

    The fixed self-introduction content is entirely prescribed in Chinese and marked as mandatory, which effectively forces a specific language for at least one required response path. The file does not indicate that users may choose another language or locale, nor does it justify a Chinese-only constraint as a region-specific requirement.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The documentation explicitly enables retrieval and display of project contact phone numbers, including full numbers for paid accounts, and instructs the agent to show them to users. This creates a real privacy and compliance risk because it operationalizes access to personal contact data without requiring purpose limitation, consent verification, minimization, or a user-facing warning about sensitive personal data handling.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The skill documents an automatic registration flow that collects device fingerprinting material (platform, architecture, MAC-derived hash) and transmits it to a third-party service to create trial accounts. That behavior is not necessary for the stated enterprise-intelligence/reporting purpose and expands data collection beyond user-requested analysis, creating privacy, consent, and tracking risk even though the document claims minimization.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    85% confidence
    Finding

    The file instructs the agent to use fixed Chinese-language user-facing text such as the consent prompt and subsequent guidance, and later requires exact Chinese phrases like the recharge-link trigger. This imposes a specific language/locale behavior without user opt-in or an explicit justification that the skill is region-specific.

    Content

    No source excerpt is available for this finding.

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    93% confidence
    Finding

    The documentation explicitly directs the agent to send collected device features to an external endpoint for auto-registration. External transmission of locally derived identifiers is sensitive in this context because it occurs as part of a non-authentication skill and creates privacy and account-linking risk, especially when tied to trial-account issuance and persistent key storage.

    Content

    Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    

    External Transmission

    Medium
    Category
    Data Exfiltration
    Confidence
    89% confidence
    Finding

    This finding is substantively the same external-transmission issue: the skill prescribes use of curl or equivalent to POST registration data to a remote service. The risk is not the serialization method itself, but that the skill normalizes outbound exfiltration of device-derived identifiers and account bootstrap data in a context where users may expect only reporting assistance.

    Content

    Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

    md
    > ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
    >
    > 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
    > 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
    > (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
    >
    > 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
    

    Description-Behavior Mismatch

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The file instructs the agent to persist API keys locally, manage session state, and drive login/monetization flows despite the skill being presented as a company-intelligence assistant. This hidden credential-management behavior increases the attack surface: secrets are written to disk and reused automatically, which can surprise users and expose credentials if the local environment is shared or insecure.

    Content

    No source excerpt is available for this finding.

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    95% confidence
    Finding

    This duplicate finding points to the same session-persistence behavior: creating ~/.zlbx and merging configuration to retain an auto-issued API key. The danger is durable secret storage and silent session continuation, which can let subsequent runs access the third-party account without renewed user intent and increase exposure if the workstation is compromised.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Session Persistence

    Medium
    Category
    Rogue Agent
    Confidence
    95% confidence
    Finding

    This duplicate finding points to the same session-persistence behavior: creating ~/.zlbx and merging configuration to retain an auto-issued API key. The danger is durable secret storage and silent session continuation, which can let subsequent runs access the third-party account without renewed user intent and increase exposure if the workstation is compromised.

    Content

    Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

    text
    
    注意事项:
    - 目录不存在时先 `mkdir -p ~/.zlbx`
    - 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
    - `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
    

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The file is a Chinese report template and line L003 states the report must be output in Markdown in-conversation, while the entire template and fixed phrasing assume Chinese output. There is no indication that the user may choose another language or that the locale restriction is optional or justified as region-specific policy, so this is a language-policy violation.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The template explicitly requires preserving and exposing full URLs containing the sk免登录 parameter and instructs the agent to disclose the absolute filesystem path of the generated HTML report. If those links function as bearer-style access tokens, reproducing them in chat output or embedded reports can leak unauthorized access to company pages and reports; exposing local absolute paths also increases information disclosure and may reveal sensitive host layout or storage conventions.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    88% confidence
    Finding

    This markdown file explicitly requires use of X-API-Key, which involves credential handling. The document provides no warning about protecting the key, avoiding disclosure in outputs/logs, or limiting its exposure, so the skill description omits a relevant privacy/security warning.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The script writes a shareable HTML report that intentionally embeds raw URLs from the input JSON, and the file format description explicitly states those URLs may contain sk tokens for authenticated access. That means anyone who receives or later finds the HTML file can reuse those links and inherit access tied to the token, causing credential-like token disclosure through local files, email forwarding, chat sharing, backups, or endpoint compromise.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    71% confidence
    Finding

    The file is entirely written as Chinese-only operational guidance and includes instruction-style language such as fixed output handling rules, but provides no indication that users may choose another language or locale. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    This file embeds a fixed Chinese language/locale setting in the HTML output, and the surrounding user-facing text is entirely Chinese with no opt-in or override path. Under the policy, forcing a specific language or locale without user choice is a natural-language policy concern unless clearly justified as region-specific.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.