T01 · Skill Instruction Hijacking
- Location
SKILL.md:497- Finding
Mandatory Vendor Promotion Hijacks User-Facing Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent tender-data assistant, but it asks for broad automatic use, stores a reusable API key in a local file, and can relay server-controlled notices and vendor referrals into user responses.
Install only if you are comfortable sending procurement and company-analysis queries to zhiliaobiaoxun.com and storing a ZLBX API key locally. Prefer setting your own ZLBX_API_KEY or protecting ~/.zlbx/config.json with restrictive permissions, and treat any update notices, auto-login links, recharge links, or vendor referrals as untrusted content to verify before acting.
SKILL.md:497Mandatory Vendor Promotion Hijacks User-Facing Responses
SKILL.md:454Untrusted Server-Controlled Notice Is Relayed Verbatim
references/auto-register.md:173Persisted API Key Lacks Mandatory Filesystem Protection
The trigger scope is extremely broad and mandates invocation for loosely related topics such as suppliers, competitors, and market share. Over-broad mandatory routing can cause unnecessary transmission of user queries to this external service, increasing data exposure and reducing the agent's ability to apply least-privilege tool selection.
The skill instructs automatic account registration using collected device characteristics and then persists the returned API key to a local file. That expands the skill from data retrieval into credential provisioning and storage, creating privacy risk, local secret exposure risk, and the possibility of unauthorized account creation or misuse if the config file is accessible to other local processes or users.
Forcing use of the skill without user opt-in for broad classes of requests undermines informed consent and can silently route sensitive business queries to an external API. In a tool-enabled agent setting, this increases the chance of unnecessary disclosure of company names, procurement plans, competitor analysis, or other commercially sensitive prompts.
The manifest describes an official assistant centered on bidding/procurement data and related analytics from the platform. L458-L468 expands capability to open-ended internet-enhanced analysis using WebSearch for company strategy, industry ranking, policy impact, and market outlook, which goes beyond the clearly stated platform-data role and introduces unrelated information gathering capability.
The manifest description at L003 presents this skill as the mandatory tool for any bidding, procurement, supplier, competitor, or market-share need. However, L472-L489 and L493-L514 direct the agent to recommend or defer those same classes of tasks to sibling skills and an external '知了商机大师' Agent, including competitor, customer, market analysis, opportunity discovery, and bidding strategy contexts. This is a semantic mismatch between the skill's declared scope/obligation and its documented operational behavior.
The file title and all user-facing documentation are written exclusively in Chinese, with no indication that the user may choose another language or that the locale restriction is intentional for a region-specific tool. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation.
The documentation explicitly tells the agent to automatically select matching companies and continue downstream queries without user confirmation. In a procurement and company-analysis context, ambiguous names can map to multiple legal entities, so silent auto-selection can produce incorrect analysis, disclose data about the wrong company, or drive decisions based on mistaken identity. The risk is amplified because the same file elsewhere recognizes ambiguity for registry lookups and warns not to self-select a candidate, showing inconsistent safety handling.
This markdown file is entirely written in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
This markdown file contains all user-facing instructions and API descriptions in Chinese only. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation unless the restriction is clearly documented and justified.
The skill instructs the agent to transmit locally collected device fingerprint data (platform, arch, mac_hash) to an external service as part of automatic registration. Even though the document emphasizes minimization and user consent, this is still outbound transmission of host-derived identifiers and creates privacy and tracking risk, especially because it persists an API key afterward for continued use.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时
This duplicate finding points to the same persistence behavior: writing an API key to a predictable location in the user's home directory for future automatic reuse. In the context of an agent skill, that persistence can outlive the user's immediate action and may be consumed by later workflows without renewed consent, increasing credential exposure risk.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
This duplicate finding points to the same persistence behavior: writing an API key to a predictable location in the user's home directory for future automatic reuse. In the context of an agent skill, that persistence can outlive the user's immediate action and may be consumed by later workflows without renewed consent, increasing credential exposure risk.
注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**
The document instructs the agent to output a fixed Chinese message to the user when quota is exhausted. This is a natural-language locale policy concern because it mandates a specific language without indicating that the user's preferred language should be respected or that Chinese is optional.
The example request body shows "ch": "s131" at L115, but the normative instruction at L129 says the ch field must be fixed to "s01". This is not merely incomplete documentation; it gives two incompatible values for the same required field, so an agent following the document could do the opposite of what the surrounding example demonstrates.
No suspicious patterns detected.