Back to skill

Security audit

ZJZ Workflow

Security checks across malware telemetry and agentic risk

Overview

This is a real bookkeeping and tax workflow skill, but it can expose or change sensitive payroll, tax, invoice, and bank data under broad activation rules.

Install only if you intend to let the agent operate your 自记账 account. Confirm the company uid before every action, review all payroll, tax, invoice, audit, bank, and upload actions before approval, and avoid exposing full ID numbers, bank account numbers, payroll tables, or financial documents in shared chats or logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (23)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description says it should trigger even when the user does not explicitly mention the app, as long as the request involves broad accounting, tax filing, reporting, or todo handling topics. In a financial operations skill that can invoke write-capable CLI actions, overly broad activation increases the chance of the wrong tool being invoked on unrelated or ambiguous requests, potentially exposing sensitive company context or steering users into unintended business actions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The 'When to Use This Skill' section lists common finance and tax scenarios without strong app-specific constraints or exclusions. Because this skill supports account binding, company switching, and multiple write operations, ambiguous activation can lead to unnecessary access to sensitive business data or accidental progression toward state-changing workflows in the wrong context.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation instructs users to submit and store a bank account number but provides no warning that this is sensitive financial data or guidance on secure handling. In a bookkeeping and tax skill, this increases the chance of accidental exposure through logs, screenshots, shell history, or misuse by operators who may not realize the sensitivity of the value.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation instructs operators to submit highly sensitive employee personal data, including national ID numbers, phone numbers, and dates related to identity and employment, but provides no privacy warning, consent guidance, masking advice, or data-handling safeguards. In an agent-driven workflow, this increases the chance that users or downstream systems will transmit excessive PII into logs, prompts, shell history, analytics, or other storage locations without understanding the sensitivity.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This documentation exposes a command that can confirm personal tax amounts or trigger payment actions, including an 'immediate payment' mode, without any warning about financial consequences, irreversibility, or the need for explicit user confirmation. In the context of an accounting/tax skill, this is especially risky because an agent may operationalize the command directly and cause real monetary transactions or compliance actions from ambiguous user input.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill documentation explicitly describes a command that returns full bank account numbers and labels them as part of normal output, but provides no masking, least-privilege guidance, or warning that this is highly sensitive financial data. In an accounting skill, access to bank account data may be functionally relevant, but exposing complete account numbers by default increases the risk of unnecessary disclosure through logs, prompts, screenshots, downstream tools, or unauthorized operators.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The documentation includes a realistic credential-like `auth_key` token and a live-looking quick-login URL in an example response. Even if illustrative, publishing bearer-style tokens without explicit redaction guidance normalizes unsafe handling of secrets and risks accidental reuse, scraping, or operators misunderstanding that such values must be protected.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation exposes a destructive command that deletes a bank account record using only identifiers, but it provides no warning, confirmation step, or guidance to verify user authorization before execution. In an accounting and tax skill, this increases the risk of accidental or socially engineered deletion of financial account data, which can disrupt bookkeeping workflows and impair downstream reporting.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation includes an example response for employee-list retrieval that exposes highly sensitive personal data fields, including full ID number, phone number, birth date, and salary, without any warning about authorization, minimization, masking, or secure handling. In a bookkeeping/payroll skill, this increases the risk that downstream agents or users will treat bulk employee PII as routine output and retrieve, store, or disclose it more broadly than necessary.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation includes and encourages display of payroll data fields such as employee names, ID numbers, income, insurance contributions, and tax amounts, which are highly sensitive personal and financial data. In a skill that retrieves payroll for companies, showing full identifiers without masking, minimization, or privacy handling guidance increases the risk of unauthorized disclosure, overexposure in chat transcripts, and downstream logging of regulated personal information.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation explicitly recommends rendering full certificate/ID numbers (zjhm) in payroll preview output. Because this skill handles payroll and tax data, exposing full government ID numbers alongside salary and insurance details materially increases privacy and identity-theft risk, especially if shown in chat transcripts, logs, screenshots, or shared reports.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation exposes a command for retrieving detailed personal tax information, including names, salary figures, tax amounts, bonuses, and deduction details, but provides no warning, access-control guidance, or handling requirements for this highly sensitive personal and financial data. In an accounting/tax skill, this functionality may be legitimate, but the absence of privacy safeguards in the documentation increases the risk of misuse, over-collection, or accidental disclosure by agents and operators.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document describes a write operation that can modify invoice accounting records and potentially trigger financial workflow changes, but it does not warn the agent or user that the command performs a state-changing action. In an agent setting, this omission increases the risk of accidental or unauthorized bookkeeping changes, especially because the command can default to the currently active company uid when uid is omitted.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document exposes a destructive payroll deletion command with no warning about irreversibility, no recommendation for explicit user confirmation, and no guidance to verify the target month/company before execution. In an accounting and tax workflow, accidental or socially engineered use could delete payroll records that are important for compliance, reporting, and auditability.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The document exposes a state-changing command that marks a month as audited/submitted without any warning, confirmation requirement, or explicit notice that it alters accounting workflow state. In a finance/tax skill, this can cause users or an agent to prematurely finalize audit status for the wrong company or month, leading to compliance, reporting, or operational errors.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation presents a state-changing command that marks a month as having no incoming invoices, which can alter company accounting and tax-related records, but it does not clearly warn that this operation updates persistent business data. In an accounting skill, omission of mutation warnings increases the risk of accidental misuse by an agent or user, potentially causing incorrect bookkeeping, compliance issues, or downstream tax/reporting errors.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document instructs the agent to perform a state-changing accounting action that marks a month as having no sales invoices, but it provides no warning about business, compliance, or audit consequences and no indication of whether the action is reversible. In a bookkeeping and tax-filing context, silently performing this operation could cause incorrect tax records, missed reporting, or unauthorized changes to a company’s financial state.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This document describes a command that confirms social-security tax amounts/rates, which is a state-changing financial/compliance action, but it does not warn the operator that executing it may finalize or acknowledge amounts with legal and monetary consequences. In the context of a bookkeeping/tax skill, omission of a confirmation warning increases the risk of accidental approval, unauthorized execution, or irreversible compliance mistakes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation includes example output containing highly sensitive personal data fields, including a full name and an apparent government ID number, without masking, minimization, or any privacy handling warning. In a payroll/social-security skill, this is especially risky because the documented command retrieves employee records at scale, normalizing exposure of PII and increasing the chance of copying, logging, or reuse in insecure contexts.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents uploading bank statements and receipt PDFs to a remote service but provides no security or privacy warning about handling highly sensitive financial records. In an accounting skill, this omission is materially risky because users may upload regulated or confidential banking data without understanding retention, access control, redaction, or transmission implications.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation instructs users to upload a local invoice file to a remote service but does not clearly warn that the specified path causes the file contents to be transmitted off-host. Because invoice files commonly contain sensitive financial and personal data, omission of an explicit disclosure can lead to unintended exfiltration of confidential documents, especially when an agent or user treats the command as a routine local file operation.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The workflow includes a destructive bank-account deletion command but provides no requirement to verify user intent, confirm the exact target account, or warn about consequences. In a financial-accounting skill, an agent following these instructions could remove the wrong linked bank account, causing operational disruption, loss of access to future receipt matching, or integrity issues in bookkeeping workflows.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs the agent to upload bank receipt/detail files, which likely contain sensitive financial and personal data, without any privacy notice, minimization guidance, or transmission-safety checks. Because this skill is specifically for bookkeeping and tax handling, the context increases risk: users may provide highly sensitive bank records, and the workflow normalizes sending them without consent or validation of secure handling.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.