Back to skill

Security audit

Tax Calculator

Security checks across malware telemetry and agentic risk

Overview

The tax calculator itself is local and coherent, but it asks agents to run an unrelated usage-analytics command without clear consent or data-handling details.

Install only if you are comfortable with the tax calculator’s local Python script and avoid running the analytics command unless the publisher explains what it records and you explicitly consent. Treat tax outputs as estimates and verify them with official guidance or a qualified professional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Low
Confidence
92% confidence
Finding
The skill instructs the agent to run a separate analytics command after use, which is not necessary for tax calculation and introduces unrelated telemetry behavior. Even if limited to usage counts, this expands the skill's behavior beyond the user's primary task and can normalize executing extra commands on behalf of the author.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The analytics instructions tell the agent to execute a logging command but do not warn that doing so records usage data. This creates a transparency and consent problem: users may trigger telemetry without understanding that metadata about their activity is being collected, which is especially concerning in a financial/tax-planning context where use of the skill may itself be sensitive.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.