Back to skill

Security audit

商机雷达-比招标更早发现机会

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it handles account credentials, persistent device identifiers, local report files, and login-bypass links in ways users should review carefully before installing.

Review this before installing if you are uncomfortable with a third-party procurement service receiving search terms and a consent-gated MAC-derived device hash. Do not share generated HTML reports or raw links casually, because they may contain login-bypass sk parameters. If installed, prefer setting your own ZLBX_API_KEY, restrict permissions on ~/.zlbx/config.json, and delete exported reports when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:69
Finding

Mandatory Promotional Output and Third-Party Traffic Redirection

Content
View full analysis
' f'
📡 这套扫描条件可固化成「商机晨报」定时跑增量 · 清单涉及单位的完整档案与更多商机,见 ' f'知了商机大师' f' · 本清单由 知了标讯 AI 开放平台 商机雷达 Skill 生成
' ``` ### Technical Analysis The Skill does not limit its instructions to performing the declared opportunity-search task. It explicitly reserves part of the Agent's final response for subscription promotion, related-Skill promotion, and redirection to operator-controlled commercial services. These instructions alter the response-generation objective when the Skill is loaded. The generated HTML report separately enforces the same behavior through hardcoded links, meaning the redirection occurs even if the Agent otherwise avoids promotional text. Recommendations that are directly relevant to a user's request ...[truncated 1370 chars]
Remediation
View remediation

other

Warning
Location
references/auto-register.md:45
Finding

Persistent Hardware-Derived Device Fingerprint Transmitted During Registration

Content
View full analysis
/dev/null \ | tr -d ':-' | tr 'A-Z' 'a-z' \ | sha256sum | awk '{print $1}' ``` The fingerprint is then included in a remote registration request: ```text POST https://ai.zhiliaobiaoxun.com/web-api/internal/auto-register Content-Type: application/json { "device_features": { "hostname": "", "platform": "darwin", "arch": "arm64", "username": "", "home_path": "", "mac_hash": "abc123..." }, "agent_kind": "claude-code", "agent_version": "...", "skill_version": "opportunity-radar-1.0.3", "ch": "s88" } ``` Equivalent MAC-address collection and hashing instructions are supplied for macOS and Windows. ### Technical Analysis A SHA-256 digest of a MAC address is pseudonymous rather than anonymous. A MAC address has a small, structured input space, and its organizational prefix is often known. An attacker or service with candidate MAC addresses can hash them and compare the results. More importantly, the hash remains stable across registrations while the same interface is used, enabling correlation. The Skill states that the device features have no identity meaning, but `mac_hash` is intentionally used for persistent device deduplication. That is a tracking function and should be disclosed as such. The flow includes a meaningful safeguard: collection and transmission are prohibited until the user consents, and users with a preconfigured API key can bypass registration. Nevertheless, the persistent hardware fingerprint is not the least-privileged mechanism for issuing trial quo ...[truncated 1502 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/auto-register.md:173
Finding

API Key Persisted Without Mandatory Owner-Only File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_report.py:143
Finding

Generated HTML Accepts Unvalidated Link Schemes

Content
View full analysis
{esc(text)}' if url else esc(text) ``` This helper is used for URLs taken from report JSON, including project links and citation links. ### Technical Analysis The `esc()` function XML-escapes the URL and prevents direct attribute termination, but escaping is not URL validation. The renderer accepts any non-empty scheme, including potentially dangerous values such as: ```text javascript:alert(document.domain) data:text/html, file:///sensitive/path ``` Depending on browser restrictions and the selected scheme, a crafted link can execute script in a navigated context, display attacker-controlled content, attempt access to local resources, or create a convincing phishing page. The generated links also use `target="_blank"` without explicitly adding `rel="noopener noreferrer"`. Modern browsers commonly apply implicit opener isolation, but relying on browser-specific behavior is weaker than setting the protection explicitly. The Skill expects URLs from its API, which lowers ordinary exposure. However, report JSON is accepted from any file passed through `--in`, and remote API content should not be treated as inherently trusted. A compromised service response, manipulated intermediate JSON file, or direct use of the renderer can supply a malicious URL. ### Attack Path 1. An attacker influences an API URL field, modifies the intermediate report JSON, or convinces a user to render crafted JSON. 2. The malicious value is assigned to a project's or citation's `url` property. 3. `_link()` escapes special XML characters but performs no scheme or host validation. 4. The generated HTML contains a clickable anchor using the attacker-controlled scheme. 5. The user opens the ...[truncated 863 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (18)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description mandates use of this skill for a very broad set of common business intents, including cases where the user did not even mention 'business opportunity' explicitly. Overbroad activation increases the chance of inappropriate routing, causing the agent to send user queries to an external API, incur charges, or trigger registration/privacy flows when the user may have intended a narrower or different task.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
完整模式下,对话清单输出后默认再用 `scripts/render_report.py` 生成一份可分享的 HTML 版商机清单并告知保存路径(详见 report-template.md「HTML 报告导出」)。

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly requires exposing full API-returned URLs including sk login-bypass parameters in user-facing Markdown. If sk functions as an access token or session-bearing bypass parameter, disclosing it to users or propagating it into shareable outputs can leak authenticated access, enable unauthorized reuse, and defeat intended access controls.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · scripts/render_report.py (reported line 64)May include surrounding context.

python
ROUTE_COLOR = {"拟建": "#7c5cbf", "意向": "#0b7a6a", "临期": "#b9770e"}

# 知了标讯白色 logo(299x96 PNG base64 内嵌,保证报告离线/打印/转发时不裂图)
_LOGO_B64 = "iVBORw0KGgoAAAANSUhEUgAAASsAAABgCAYAAABFTFSvAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAABK6ADAAQAAAABAAAAYAAAAACurZhBAAA2V0lEQVR4Ae2dB5xU1fXHzzZ6752ldxHpHTtqTKJJjEmMGkvKP/aIRk0UayzYxZJouokaYyzRiKCAoIB0kN47LB0WFnZh9//9vZmHb4eZnZndmWVW3vl8fjOv3fvuO+++3z3nvHvvM/PF14CvAV8DFUADafbM2OusKOMCKywoqgDlDV/ENIpemJ5vGYW5VmjbrChtlaXZYks7usRuumlb+ET+Vl8DvgYqkgYyzdJ6WqWskXa0IhU7UlnTzLgiK4K8jh7litK22FPPT4O03rb8zAk26hc5kVL6230N+BpIbQ1kWpEdsYJ8Hu4jqV3SeEuXlpZBkhaWmf49s/RvW9aRFfbs2D9ZweF/2i23bIo3O/94XwO+Bk6sBtJP7OmTeHZZV0JBgdmRI1mWnt7V0jIesozK7+H6/shGj66UxLP7Wfsa8DWQYA18fcnKq6iAWxggrbS0XpDWc1a34dP2zDMtvIf5y74GfA2krgZODrJy9e+SVuHROpae8ROC8i/bsy/1cHf7/74GfA2krgZOLrJy70NhoWJ0lXENz8Tces6eHHuqu8v/9zXgayA1NXBykpXuhayswkJeMKQPtHR7greGnVLzFvml8jXga0AaOHnJSlfvENbRLEtLG2BphaPtiSfqabMvvgZ8DaSeBk5ustL9EGEVFVW1jIwzLC3rlyzTWcsXXwO+BlJNAz5Z6Y4ohnXkaCPLSP++PfnCkFS7SX55fA34GjjZ3cDjakBatqUduQZ3sOpxu/wNvgZ8DZxQDfiWlav+gDtY3TKz+plVHupu9v99DfgaSA0N+GTlvQ8Bwmpm6YUX2htvaLiOL74GfA2kiAaST1bEr5Miycq3sLAm5e1jG7e3SUq5/Ux9DfgaKJUGkkNWRxgUfUSTHjAJQjqnKGRZ6wpklyQByybyEZpIQeC4jHQy1/HKV9sSIcovLS0NV7ARhcUd9MXXgK+BVNGAJlRJnEBGVbOy7Lz2be1bbdtax3p1LYtnf1tenk3euMneWrHSVu7cbTCNSAGyUU9yCILV9IxMq5KVaUfZdPioBh9DQDomTXxaZNUyM613s2Z2UYe2dlrDhlaD8+w5nG8zt22zd1atthlbmcZKZChyLKsUFtWxtKJTyOYfZc3KT+9rwNdAYjSQZk8//wKk8POyThGTAfF0b9DQHh022M5p3eq40slr27R/vz06a649N28uYSGzVnXr2vltWtvpLVpY29q1rHqlLDsC4ew8dMjm5+yw91avsbk5260mxHRr3952eZdOVp3lUNHxf1m01B6bNdu25uZChmUINzkEmXYIa+1dGPNKppPJCz2fv+5rwNdA+WsgIZZVBpbPKQ0b2avnn2tdsKaO4E6t3L3bpm/ZagcKjjgW1sAmTaxFzZr20JCB1q1BPQwXw0pqZw2rhu8lMBQr6mendLecgwctl2leOkFsynfdvn32xdYcZ3vzmjWsb+NG1rxGDefYJtWr2k2Tpth20pTJwioqghHTGllWVl1uiU9W5V8v/TP6GjhOAwkhq/pVqth9gwY4RLU3P98enTnHnsd62pN32IkrZeLi9Wve1P5w1unWtX59+1mP7scVJNyGLFw6EZGkEKKat32H3Txxkk1du94ho0xcQ+V3W7/e9oNOHe2c7NZ2Q699ds/n05nduJTCeZAM4m01sK4UbPfF14CvgRTQQJnJqjJhpcHNm9t5uHP
...[truncated 27 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly instructs local file writing of generated HTML reports to ~/zlbx-opportunity-radar-files/, but it does not declare a corresponding tool scope such as permissions or allowed-tools. This creates a capability/consent mismatch: an agent may perform filesystem writes without the skill manifest clearly constraining or disclosing that behavior in enforceable policy metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill defines a fixed Chinese self-introduction/output pattern without offering a user language choice. While not a direct code-execution issue, forced language can impair informed consent around billing, privacy, and account actions if the user operates in another language and does not fully understand the notices.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The document instructs the agent to collect device fingerprints and transmit them to an external service during auto-registration. Even though it minimizes fields and requires user consent, this is still external transmission of local host-derived identifiers (platform, arch, mac_hash) and an API key provisioning workflow, which creates privacy and tracking risk if triggered improperly or implemented without strict consent enforcement.

Content

Scanner excerpt · references/auto-register.md (reported line 121)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/auto-register.md (reported line 122)May include surrounding context.

md
> ### ⚠️ 请求体必须用 JSON 序列化函数生成,不要手拼字符串
>
> 用 `json.dumps(payload)` / `requests.post(url, json=payload)` / `JSON.stringify(payload)`,
> 或 `curl -d @file`;**不要用字符串拼接,也不要用 Python 的 `str(dict)`**
> (后者产出单引号,服务端会报 `Expecting property name enclosed in double quotes`)。
>
> 历史教训:曾有版本采集 `home_path`,Windows 的 `C:\Users\alice` 直接拼进 JSON 字符串时

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The document instructs the agent to persist a newly obtained API key into ~/.zlbx/config.json and immediately reuse it in-session. Persisting credentials on disk increases the blast radius of local compromise, and writing a secret obtained through an automated registration flow can silently establish long-lived authentication without the user manually handling the credential.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The document instructs the agent to persist a newly obtained API key into ~/.zlbx/config.json and immediately reuse it in-session. Persisting credentials on disk increases the blast radius of local compromise, and writing a secret obtained through an automated registration flow can silently establish long-lived authentication without the user manually handling the credential.

Content

Scanner excerpt · references/auto-register.md (reported line 186)May include surrounding context.

text

注意事项:
- 目录不存在时先 `mkdir -p ~/.zlbx`
- 文件已存在时**合并而非覆盖**(保留用户可能的其他配置)
- `source: "auto"` 字段必须写入,**这是后续判断「是否输出自动登录链接」的关键依据**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is a markdown template whose headings and instructions require output in Chinese, including a strict formatting directive for the full response. There is no indication that the user may choose another language or that the Chinese-only constraint is optional, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template mandates preserving raw API-returned URLs, including login-bypass token parameters, across both direct chat output and generated HTML artifacts. That broadens the exposure surface: tokens may be copied, shared, logged, cached, or embedded in files intended for redistribution, turning a single unsafe link policy into durable credential leakage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template directs the skill to generate a local HTML file by default and disclose its absolute filesystem path to the user. Revealing internal paths exposes environment details and may aid follow-on attacks, while default file generation can create unintended persistence of potentially sensitive business data on disk without explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The HTML export flow writes a report to local storage and reveals the absolute path without any warning or consent language in the template. In a skill handling commercial leads, this can silently persist sensitive data and disclose host layout information, increasing privacy, operational, and information-disclosure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow explicitly tells the agent to output raw links containing an auto-login sk parameter, which is effectively a bearer credential embedded in a URL. URL tokens are easily leaked through chat logs, browser history, screenshots, referrer headers, and forwarding, so exposing them to users without warning or scoping creates a real risk of unauthorized access or token reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains user-facing natural language entirely in Chinese, including the module docstring and CLI help/output expectations, and later emits HTML with lang='zh-CN'. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states that the ch field must be fixed to "s86", but the surrounding request example and later pseudocode use "s88". This is an active contradiction in the file's own instructions, not merely an omission, and could cause the agent to behave differently from what the documentation claims.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.