Back to skill

Security audit

Singapore SME Compliance

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it gives conflicting privacy assurances while showing external financial-data and tax-filing API actions.

Review before installing in any production accounting or tax workflow. Do not let the skill send real invoice values, turnover, Xero data, bearer tokens, CorpPass tokens, or GST F5 return data unless you have approved the exact endpoint, token scope, and filing environment. Prefer the local calculator path for GST arithmetic.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:22
Finding

Unnecessary External Disclosure of Financial Data and Authentication Tokens

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:22-30, SKILL.md:190-205, README.md:52-71
Vulnerability Type: Privacy misrepresentation and unnecessary sensitive-data transmission
Risk Level: Medium

The Skill presents examples that transmit business turnover, invoice amounts, accounting data, tax-return figures, and bearer credentials to external services. These instructions conflict with the README's unconditional claims that no external data is sent and no sensitive data leaves the machine.

Vulnerable Code Snippets

SKILL.md:22-30:

bash
# Check if business needs GST registration (threshold: S$1M annual turnover)
curl -s "https://www.iras.gov.sg/api/gst-threshold-check" -d '{"turnover": 1000000}'
bash
# Calculate GST (9% as of 2024)
curl -s "https://api.gstcalculator.sg/calculate" -d '{"amount": 1000, "rate": 0.09}'
# Returns: {amount: 1000, gst: 90, total: 1090}

SKILL.md:190-205:

bash
# Export sales data
curl -s "https://api.xero.com/api/Invoices?status=PAID" \
  -H "Authorization: Bearer TOKEN"

# Export purchase data
curl -s "https://api.xero.com/api/Bills?status=PAID" \
  -H "Authorization: Bearer TOKEN"
bash
# Submit GST return (requires CorpPass authentication)
curl -s "https://apiservices.iras.gov.sg/gst/f5" \
  -X POST \
  -H "Authorization: Bearer CORPPASS_TOKEN" \
  -d '{"period": "202403", "box1": 100000, "box4": 9000, ...}'

README.md:52-71:

markdown
## External Endpoints

| Endpoint | Data Sent | Purpose |
|----------|-----------|---------|
| https://www.iras.gov.sg/api/* | None (reference only) | GST registration info |
| https://api.gstcalculator.sg/* | Amount, rate | GST calculation |

## Security & Privacy

- **No sensitive data leaves your machine** - All calculations are local
- **No API keys required** - Uses public IRAS reference data
- **Scripts are open source** - Review before installi
...[truncated 3370 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the third-party GST calculator request and perform GST arithmetic exclusively with the bundled local script.
  2. Implement the registration threshold comparison locally rather than transmitting turnover.
  3. Require explicit, per-operation user confirmation before contacting Xero, IRAS, or any other external service.
  4. Clearly identify each recipient, transmitted field, purpose, and applicable retention policy before sending data.
  5. Replace the unconditional privacy statements with accurate disclosures that distinguish local calculations from optional integrations.
  6. Do not place real tokens directly in documentation, prompts, command history, or agent transcripts. Retrieve them from a protected credential store at execution time.
  7. Use short-lived, least-privilege tokens restricted to the precise read or filing operation required.
  8. Prevent authorization headers and request bodies from being written to logs, error messages, or telemetry.
  9. Validate external endpoint ownership and use only documented official APIs. Remove or disable endpoints whose authenticity and operational necessity cannot be established.
  10. Make network access opt-in by default rather than relying on users to configure routing rules to opt out.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/gst_calculator.sh:5
Finding

Unvalidated Arguments Are Evaluated as bc Programs

Content
View full analysis

Vulnerability Details

File Location: scripts/gst_calculator.sh:5-15
Vulnerability Type: Expression injection and denial of service
Risk Level: Low

The calculator interpolates user-controlled command-line arguments directly into input interpreted by bc. It does not verify that the amount and rate are decimal numbers.

Vulnerable Code Snippet

bash
AMOUNT=${1:-0}
RATE=${2:-0.09}

if [ "$AMOUNT" = "0" ]; then
    echo "Usage: ./gst_calculator.sh <amount> [rate]"
    echo "Example: ./gst_calculator.sh 1000 0.09"
    exit 1
fi

# Calculate GST
GST=$(echo "$AMOUNT * $RATE" | bc -l)
TOTAL=$(echo "$AMOUNT + $GST" | bc -l)

Technical Analysis

Quoting shell variables prevents ordinary shell word splitting but does not make their contents safe for a downstream interpreter. Here, echo constructs a program that is subsequently parsed and executed by bc. Because AMOUNT and RATE can contain bc separators, operators, functions, loops, and other language syntax, an attacker can alter the intended arithmetic expression.

This is not direct shell-command injection: the supplied text is not reevaluated by the shell, and the reviewed code does not provide a demonstrated path to arbitrary operating-system command execution. It is nevertheless an interpreter injection flaw. Crafted input can change results, trigger parser failures, produce very large computations, or construct a nonterminating bc calculation.

The resulting GST is then embedded in a second bc expression without validation, propagating malformed or attacker-influenced output into another interpreter invocation.

Attack Path

  1. An attacker supplies or influences an invoice amount or GST rate passed to gst_calculator.sh.
  2. The script stores the raw text in AMOUNT or RATE without validating its numeric format.
  3. The text is concatenated with operators to form a bc program.
  4. bc -l evaluates the injecte ...[truncated 925 chars]
Remediation
View remediation

Remediation Suggestions

  1. Validate both arguments before invoking bc. Accept only a strict decimal representation, for example:

    bash
    decimal_re='^[0-9]+([.][0-9]+)?$'
    
    if [[ ! $AMOUNT =~ $decimal_re ]] || [[ ! $RATE =~ $decimal_re ]]; then
        printf '%s\n' 'Error: amount and rate must be non-negative decimal numbers.' >&2
        exit 2
    fi
    
  2. Enforce business-appropriate bounds, including a maximum invoice amount and a rate constrained to an expected range.

  3. Reject excessive input length and decimal precision to prevent pathological calculations.

  4. Pass only validated values into a fixed bc expression using printf rather than relying on unrestricted textual input:

    bash
    GST=$(printf '%s * %s\n' "$AMOUNT" "$RATE" | bc -l)
    
  5. Check the exit status of every bc invocation and terminate on calculation errors.

  6. Apply an execution timeout where the script is used in an automated or externally reachable workflow.

  7. Consider using a calculator implementation that parses decimal values as data rather than evaluating an expression language.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README makes strong privacy assurances that no sensitive data leaves the machine and that all calculations are local, yet it also documents an external GST calculator endpoint that receives amount and rate and states the skill may autonomously invoke API calls. This mismatch can mislead users into exposing financial invoice data under false assumptions, undermining informed consent and creating a real privacy and trust boundary issue.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code only implements a narrow GST calculation utility. While GST calculation is one stated use, the declared description presents a broader compliance automation skill covering invoice validation, reporting, filing preparation, registration checks, and deadline tracking. None of those additional capabilities appear in the supplied code chunk. There is no evidence of undeclared risky behavior or inconsistent resource access, but the description materially overstates the implemented functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation describes submitting a GST F5 return via API but does not clearly warn that this may perform a real filing that changes official regulatory records. In a tax/compliance skill, this is especially dangerous because users could trigger unintended submissions, inaccurate filings, penalties, or audit issues.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The documented external endpoint indicates business data such as invoice amount and tax rate may be sent to a third-party service. External transmission is not inherently malicious, but in this context it becomes security-relevant because the README downplays or contradicts that behavior, preventing users from properly evaluating privacy risk.

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

md
| Endpoint | Data Sent | Purpose |
|----------|-----------|---------|
| https://www.iras.gov.sg/api/* | None (reference only) | GST registration info |
| https://api.gstcalculator.sg/* | Amount, rate | GST calculation |

## Security & Privacy

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as performing GST calculations locally, but nearby documentation indicates that GST calculation may be offloaded to an external API. Even if the transmitted fields are limited to amount and rate, this is still a material discrepancy because users may choose the skill specifically to avoid sending financial data off-device.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Conflicting statements about whether data is transmitted externally create an unsafe user experience because operators cannot reliably determine the skill's trust boundaries. In a compliance and tax context, even limited business-financial metadata can be sensitive, so ambiguity increases the risk of accidental disclosure and inappropriate deployment in regulated environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill includes example API calls that send turnover and invoice-related financial data to external services without warning users that potentially sensitive business data will leave their environment. In a compliance context, users may assume the examples are safe defaults, increasing the risk of unintentional disclosure to third parties.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example transmits business turnover data to an external IRAS endpoint. Even if the destination is legitimate, external transmission of potentially sensitive financial information without clear disclosure, consent flow, or validation of endpoint authenticity creates privacy and operational risk.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Check GST registration requirements:

bash
# Check if business needs GST registration (threshold: S$1M annual turnover)
curl -s "https://www.iras.gov.sg/api/gst-threshold-check" -d '{"turnover": 1000000}'

GST calculation:

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This example sends invoice amount data to a third-party GST calculator service. While the sample uses a simple amount, in practice users may substitute real invoice values, causing unnecessary disclosure of financial information to an external provider for a calculation that could be performed locally.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

GST calculation:

bash
# Calculate GST (9% as of 2024)
curl -s "https://api.gstcalculator.sg/calculate" -d '{"amount": 1000, "rate": 0.09}'
# Returns: {amount: 1000, gst: 90, total: 1090}

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The referenced Xero API endpoint is part of an authenticated external integration for invoice export, which inherently involves movement of potentially sensitive accounting data. The danger is amplified by the compliance context, where users may connect production systems and process regulated financial records.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

Xero/QuickBooks integration:

bash
# Export sales data
curl -s "https://api.xero.com/api/Invoices?status=PAID" \
  -H "Authorization: Bearer TOKEN"

# Export purchase data

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The referenced Xero API endpoint is part of an authenticated external integration for invoice export, which inherently involves movement of potentially sensitive accounting data. The danger is amplified by the compliance context, where users may connect production systems and process regulated financial records.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

Xero/QuickBooks integration:

bash
# Export sales data
curl -s "https://api.xero.com/api/Invoices?status=PAID" \
  -H "Authorization: Bearer TOKEN"

# Export purchase data

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This endpoint retrieves bill/purchase data from Xero, exposing potentially sensitive supplier and financial records through an external integration. Without accompanying guidance on authorization scope, secure handling, and user awareness, the example encourages risky treatment of regulated business data.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

-H "Authorization: Bearer TOKEN"

Export purchase data

curl -s "https://api.xero.com/api/Bills?status=PAID"
-H "Authorization: Bearer TOKEN"

text

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The content is entirely tailored to Singapore tax and compliance workflows, including IRAS, GST F5, UEN, and CorpPass. Although the title signals Singapore context, the skill text does not explicitly state that it should only be used for Singapore entities or that users outside this locale should not rely on it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.