Back to skill

Security audit

corporate-tax

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent for corporate finance and tax work, but it can persist sensitive financial, tax, and audit outputs to Notion without clear per-write consent or destination controls.

Install only if you are comfortable using it for sensitive corporate finance workflows. Before connecting Notion or uploading records, confirm the exact workspace/page/database, redact unnecessary personal or confidential fields, and have a qualified finance/tax reviewer validate outputs before filing, reporting, or audit use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README states the skill can be triggered through natural conversation and automatically matched to sub-skills, but it does not define clear routing boundaries or confirmation gates. In a finance/tax skill, broad automatic invocation can cause the assistant to enter a sensitive workflow unintentionally, leading to inappropriate handling of accounting or tax data and higher risk of wrong task execution.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords include very common accounting terms such as '记账', '会计分录', '内审', '增值税', '预算', and '财务报表', which are likely to appear in ordinary discussion without intent to invoke a specific skill. Because this skill operates in a sensitive corporate finance context, ambiguous routing could cause accidental activation, collection of confidential business data, or generation of authoritative-seeming tax/accounting output in the wrong context.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill mandates use of CAS for vouchers and financial statements without requiring confirmation that CAS is the correct accounting framework for the user's entity or jurisdiction. In a corporate finance context, applying the wrong standard can produce materially incorrect accounting treatment, tax workpapers, or reports, leading to compliance, audit, or regulatory issues.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly supports writing tax adjustment reports and filing working papers to Notion, which can contain sensitive financial, tax, payroll, and potentially personally identifiable business data. Without an explicit privacy warning, consent step, data-minimization guidance, or destination scoping, users may unintentionally export confidential tax records to a third-party SaaS workspace or the wrong shared page.

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill states that, when Notion is connected, it can write the financial analysis report back into a Notion page, but it does not require an explicit user confirmation before modifying external workspace content. In a corporate finance context, this can cause unintended disclosure of sensitive financial analysis, accidental overwrites, or creation of persistent records in shared workspaces.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly promotes writing audit reports and remediation items to Notion, but it does not warn that audit materials may contain highly sensitive financial, control, employee, or investigation data that will be transmitted to a third-party service. In an internal-audit context, this omission is more dangerous than usual because the content commonly includes confidential findings, potential fraud indicators, and compliance deficiencies, so users may unintentionally exfiltrate sensitive corporate data.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The execution instructions say to write the audit report and remediation items into Notion, but they omit any privacy, confidentiality, or approval gate before uploading. Because this skill is for internal audit, the uploaded material may include control weaknesses, management responses, and potentially legally sensitive findings, making silent transmission to a SaaS platform a meaningful confidentiality and governance risk.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly processes uploaded Excel/PDF financial records and can write generated vouchers into Notion, but it does not disclose any privacy, consent, retention, or third-party exposure considerations. Because the data involved likely contains bank transactions, invoices, payroll, tax, and other sensitive corporate financial information, silent transfer or storage in external systems can create confidentiality and compliance risk.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill advertises automated file processing and code execution for voucher generation, validation, and document parsing without warning users that uploaded documents will be programmatically analyzed. While this is presented as normal functionality, the absence of transparency increases the risk of users exposing sensitive financial material without informed consent.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill is designed to read uploaded Excel tax records and write analysis outputs into Notion, which can expose sensitive financial, invoice, and taxpayer data if handling expectations are not explicitly defined. Without a privacy and data-handling warning, users may disclose confidential records without understanding retention, sharing, connector scope, or downstream exposure risks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.