Back to skill

Security audit

税务计算

Security checks for vulnerabilities and agentic risk

Overview

This is a static Chinese tax-calculation reference skill with broad tax triggers but no code execution, credential access, persistence, or automatic external actions.

Install this only if you want Chinese tax calculation and filing-assistance reference material. Confirm the applicable jurisdiction, taxpayer type, tax year, and current policy before relying on results, and have a qualified tax professional review real filings or payment decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The instruction to use this skill for essentially any tax-related task is overly broad and can cause the agent to invoke it without confirming jurisdiction, policy date, or whether the user actually wants PRC tax treatment. In a tax domain, incorrect automatic invocation can lead to materially wrong compliance guidance, filing logic, or tax calculations rather than just a poor user experience.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger list contains very generic tax terms such as VAT, corporate income tax, and personal income tax, which are common across many jurisdictions and contexts. This increases the chance the skill is selected when the user's request is unrelated to PRC rules or needs broader legal/accounting nuance, producing inaccurate or unsafe financial advice.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill is written entirely around Chinese tax law, rates, forms, and filing timelines, but it does not explicitly require user opt-in to that jurisdictional context. If invoked for users in other locales, it can silently provide authoritative-looking but inapplicable tax guidance, which is especially risky in a compliance-heavy finance skill.

Static analysis

No suspicious patterns detected.