Back to skill

Security audit

知了标讯官方招投标助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent tender-data assistant, but it asks for broad automatic use, stores a reusable API key in a local file, and can relay server-controlled notices and vendor referrals into user responses.

Install only if you are comfortable sending procurement and company-analysis queries to zhiliaobiaoxun.com and storing a ZLBX API key locally. Prefer setting your own ZLBX_API_KEY or protecting ~/.zlbx/config.json with restrictive permissions, and treat any update notices, auto-login links, recharge links, or vendor referrals as untrusted content to verify before acting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:497
Finding

Mandatory Vendor Promotion Hijacks User-Facing Responses

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:454
Finding

Untrusted Server-Controlled Notice Is Relayed Verbatim

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

Persisted API Key Lacks Mandatory Filesystem Protection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger scope is extremely broad and mandates invocation for loosely related topics such as suppliers, competitors, and market share. Over-broad mandatory routing can cause unnecessary transmission of user queries to this external service, increasing data exposure and reducing the agent's ability to apply least-privilege tool selection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs automatic account registration using collected device characteristics and then persists the returned API key to a local file. That expands the skill from data retrieval into credential provisioning and storage, creating privacy risk, local secret exposure risk, and the possibility of unauthorized account creation or misuse if the config file is accessible to other local processes or users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Forcing use of the skill without user opt-in for broad classes of requests undermines informed consent and can silently route sensitive business queries to an external API. In a tool-enabled agent setting, this increases the chance of unnecessary disclosure of company names, procurement plans, competitor analysis, or other commercially sensitive prompts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes an official assistant centered on bidding/procurement data and related analytics from the platform. L458-L468 expands capability to open-ended internet-enhanced analysis using WebSearch for company strategy, industry ranking, policy impact, and market outlook, which goes beyond the clearly stated platform-data role and introduces unrelated information gathering capability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description at L003 presents this skill as the mandatory tool for any bidding, procurement, supplier, competitor, or market-share need. However, L472-L489 and L493-L514 direct the agent to recommend or defer those same classes of tasks to sibling skills and an external '知了商机大师' Agent, including competitor, customer, market analysis, opportunity discovery, and bidding strategy contexts. This is a semantic mismatch between the skill's declared scope/obligation and its documented operational behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file title and all user-facing documentation are written exclusively in Chinese, with no indication that the user may choose another language or that the locale restriction is intentional for a region-specific tool. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly tells the agent to automatically select matching companies and continue downstream queries without user confirmation. In a procurement and company-analysis context, ambiguous names can map to multiple legal entities, so silent auto-selection can produce incorrect analysis, disclose data about the wrong company, or drive decisions based on mistaken identity. The risk is amplified because the same file elsewhere recognizes ambiguity for registry lookups and warns not to self-select a candidate, showing inconsistent safety handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains all user-facing instructions and API descriptions in Chinese only. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation unless the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill instructs the agent to transmit locally collected device fingerprint data (platform, arch, mac_hash) to an external service as part of automatic registration. Even though the document emphasizes minimization and user consent, this is still outbound transmission of host-derived identifiers and creates privacy and tracking risk, especially because it persists an API key afterward for continued use.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same persistence behavior: writing an API key to a predictable location in the user's home directory for future automatic reuse. In the context of an agent skill, that persistence can outlive the user's immediate action and may be consumed by later workflows without renewed consent, increasing credential exposure risk.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same persistence behavior: writing an API key to a predictable location in the user's home directory for future automatic reuse. In the context of an agent skill, that persistence can outlive the user's immediate action and may be consumed by later workflows without renewed consent, increasing credential exposure risk.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs the agent to output a fixed Chinese message to the user when quota is exhausted. This is a natural-language locale policy concern because it mandates a specific language without indicating that the user's preferred language should be respected or that Chinese is optional.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example request body shows "ch": "s131" at L115, but the normative instruction at L129 says the ch field must be fixed to "s01". This is not merely incomplete documentation; it gives two incompatible values for the same required field, so an agent following the document could do the opposite of what the surrounding example demonstrates.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.