Back to skill

Security audit

个税汇算清缴助手(Tax Assistant)

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate local tax calculator, but it asks for sensitive tax data and tax-app screenshots without enough consent, redaction, or minimization guidance.

Review before installing. Use it only if you are comfortable having the agent process sensitive tax information, prefer entering only the required numbers manually, and redact names, ID numbers, employer identifiers, addresses, QR codes, account details, and unrelated records from any screenshot.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions are broad enough to activate on common tax-related phrases, which can cause the skill to engage outside a narrowly intended workflow. In a tax assistant, this increases the chance of collecting sensitive financial data from users who did not explicitly intend to enter a detailed tax-processing flow, creating privacy and over-collection risk.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill explicitly instructs extraction of highly sensitive tax and income data from text or tax-app screenshots without any user-facing privacy warning, consent checkpoint, or data-minimization guidance. Because the requested fields include income, deductions, prepaid tax, and multi-employer details, accidental oversharing or unauthorized processing could expose comprehensive personal financial information.

Static analysis

No suspicious patterns detected.