Back to skill

Security audit

確定申告アシスタント

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only Japanese tax guidance skill with no code, API access, or government-system integration; its main caveat is that users may enter sensitive financial details into its optional memory template.

Install only if you want tax-related prompts and optional tax memory in your agent. Treat any stored tax profile, expense log, or income summary as sensitive financial data, avoid entering My Number or unnecessary personal identifiers, and verify tax conclusions against a tax professional or official sources before filing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This memory template explicitly stores sensitive tax and financial profile data, including filing type, income classification, invoice registration status, expense logs, and annual income summaries, but provides no privacy notice, retention guidance, or handling restrictions. In a tax-preparation context, users may reasonably enter highly sensitive personal and business financial information, increasing the risk of over-collection, unintended persistence, or disclosure.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrase at this line is a very generic help request ('フリーランスの確定申告を手伝ってください'), which can match broad, ordinary user language rather than a narrowly scoped invocation. That increases the chance this skill is activated unintentionally in unrelated conversations about taxes or freelance work, causing unexpected behavior or disclosure of user financial context to the skill when the user did not explicitly intend to invoke it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.