Back to skill

Security audit

中国企业报税员

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed China-mainland tax preparation helper with a local calculator and explicit limits around policy checking, filing, and payments.

Install only if you need China-mainland tax preparation support and are comfortable giving the agent relevant business or payroll records. Treat outputs as draft workpapers, verify current policy and local rules before filing, and give separate explicit approval before any official submission, correction, refund, or payment action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares executable capabilities via Python/shell usage and implicitly relies on file access, but it does not define an explicit tool permission scope. That creates an authorization gap where an agent runtime may grant broader shell or file-read access than the task actually requires, increasing the chance of unintended data exposure or command misuse when processing sensitive tax records.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file contains user-facing operational instructions only in Chinese, and there is no statement that the skill is limited to Chinese-speaking users or a China-specific deployment context. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/test_calculate.py (reported line 167)May include surrounding context.

python
def test_cli_batch_examples_and_failure(self):
        root = Path(__file__).resolve().parents[1]
        run = subprocess.run([sys.executable, str(root / 'scripts/calculate.py'), str(root / 'assets/examples.json')], capture_output=True, text=True)
        self.assertEqual(run.returncode, 0, run.stdout + run.stderr)
        results = json.loads(run.stdout)['calculations']
        self.assertEqual(len(results), 8)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/test_calculate.py (reported line 172)May include surrounding context.

python
results = json.loads(run.stdout)['calculations']
        self.assertEqual(len(results), 8)
        self.assertTrue(all(r['status'] == 'draft_calculation_not_filed' for r in results))
        bad = subprocess.run([sys.executable, str(root / 'scripts/calculate.py'), '-'], input='{}', capture_output=True, text=True)
        self.assertEqual(bad.returncode, 2)
        self.assertFalse(json.loads(bad.stdout)['success'])

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.md (reported line 12)May include surrounding context.

md
Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README presents the skill as exclusively for '中国大陆' enterprises and primarily in Chinese, with no explicit opt-in or language-choice mechanism. Under the policy rule, forcing a specific language or locale can be a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example records embed natural-language values such as the id labels entirely in Chinese across the file. Because SQP-3 applies to all file types, this creates a locale-specific assumption without any visible user choice or justification in the file itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill file is written in Chinese and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire policy reference is written in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file uses Chinese throughout and does not indicate that the user can choose another language or that the skill is intentionally restricted to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring is entirely in Chinese and the program's validation and output messages throughout the file are Chinese-only, which constitutes a language/locale constraint in natural-language behavior. The file does not present this as an optional locale choice or explicit user opt-in, so it may violate a language policy requiring user-selectable language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.