Back to skill

Security audit

Argentina Fiscal Calendar (ARCA)

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed offline Argentine tax-calendar skill with limited local personalization and no evidence of hidden execution, credential use, or data transmission.

Safe to install for offline fiscal reminders. Treat the dates as guidance only and verify legally binding deadlines on ARCA. If you use the optional config files, store only the minimum needed, avoid full CUITs, credentials, bank data, or client/employee information, and review local payment-history notes before sharing backups or workspaces.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation triggers are broad enough that the skill may engage on generic tax or payment-related queries without clear user intent, causing over-triggering and unsolicited fiscal guidance. In a tax context, this increases the chance of irrelevant or incorrect advice being injected into conversations, which can mislead users making compliance decisions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs storage of personal fiscal profile data, including CUIT-related information and tax regime, in local files without a prominent install-time consent or retention warning. Even if stored locally, such tax data is sensitive and can be exposed to other local processes, backups, shared accounts, or future skills that read the same workspace.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal