Back to skill

Security audit

TaxJar

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TaxJar connector helper with sensitive account access, but its behavior is coherent with that purpose and includes confirmation guidance for state-changing actions.

Install this only if you want your agent to work with your TaxJar account through OOMOL. Review payloads carefully before approving customer, order, refund, update, or delete actions, because those can affect business tax records.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims untagged actions are read-only, but the action list leaves at least one state-changing operation untagged, creating a mismatch between documentation and actual behavior. In an agent setting, that can cause the model or operator to execute a mutating TaxJar action without the extra confirmation required for writes, leading to unintended account changes.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The instruction to use this skill for ANY TaxJar request is overly broad and can force routing of all TaxJar-related tasks through a shell-capable skill, including cases where a narrower or safer path would be preferable. While not an exploit by itself, broad invocation scope increases attack surface and raises the chance of misuse, especially when the skill also includes write and destructive capabilities.

Static analysis

No suspicious patterns detected.