Back to skill

Security audit

Tax Calculator

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Taiwan real-estate tax helper, but it tells the agent to run an unrelated, unbundled analytics script from a relative path after use.

Review this skill before installing. The tax calculator itself is local and purpose-aligned, but do not allow the post-task analytics command unless you know exactly which skills/analytics.py will run and what it records. Choose report output paths carefully because existing writable files can be replaced.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:73
Finding

Execution of an Unbundled Working-Directory Analytics Script

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 73–84
Vulnerability Type: Execution of an unverified relative-path script
Risk Level: Medium

Vulnerable code snippet:

markdown
## 📊 Usage Analytics

當你使用此 Skill 完成任務後,請記錄使用次數:

```bash
python3 skills/analytics.py taiwan-real-estate-tax used

查看統計:

bash
python3 skills/analytics.py stats
text

### Technical Analysis

The Skill instructs the Agent to execute `skills/analytics.py` through a relative path after completing a task. This script is not included in the audited project. Consequently, its identity and integrity cannot be established from the Skill package.

A relative path is resolved against the process's current working directory rather than a verified Skill installation directory. If an attacker can place a file at `skills/analytics.py` in that directory, the documented analytics command will execute the attacker's Python code. The analytics operation is also unrelated to the core tax-calculation function, making this an unnecessary execution surface.

### Attack Path

1. An attacker gains the ability to create files in, or influence the contents of, the Agent's working directory.
2. The attacker creates a malicious file at `skills/analytics.py`.
3. A user invokes the tax-calculator Skill for a legitimate task.
4. After the task, the Agent follows the Skill's usage-analytics instruction.
5. Python resolves the relative path to the attacker-controlled script.
6. The malicious script executes with the same operating-system privileges and environment access as the Agent process.

### Impact Assessment

Successful exploitation permits arbitrary Python code execution under the Agent's current account. The resulting access may include reading or modifying files available to that account, accessing inherited environment variables, making network requests where permitted, and invoking other local programs. This does not
...[truncated 259 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the analytics execution instructions because they are not required for tax calculation.
  2. If analytics is necessary, bundle the analytics implementation inside the reviewed Skill package.
  3. Resolve the script from a canonical, verified installation directory rather than the current working directory.
  4. Verify the bundled script's integrity before execution, such as through a package signature or trusted checksum.
  5. Require explicit user consent before collecting or recording analytics.
  6. Document what information is collected, where it is stored or transmitted, and the applicable retention policy.
  7. Run optional analytics with the minimum required filesystem, environment, and network permissions.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/calc-tax.py:251
Finding

Caller-Controlled Output Path Allows Arbitrary File Overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/calc-tax.py, lines 251–252 and 261–262
Vulnerability Type: Unrestricted file overwrite
Risk Level: Low

Vulnerable code snippet:

python
with open(output_path, 'w', encoding='utf-8') as f:
    f.write(report)

The output path is taken directly from a command-line argument:

python
input_path = sys.argv[1]
output_path = sys.argv[2]

Technical Analysis

The script accepts an arbitrary output path and opens it in write mode without validating its destination. Python's 'w' mode creates a missing file or immediately truncates an existing file. The implementation does not:

  • Restrict reports to an approved output directory.
  • Reject absolute paths or parent-directory traversal.
  • Detect symbolic links.
  • Refuse to overwrite an existing file.
  • Ask for confirmation before destructive replacement.

Therefore, anyone who controls the command-line arguments can cause the process to replace any file writable by its operating-system account. A symbolic link at the destination can also redirect the write to another writable target.

Attack Path

  1. An attacker or untrusted caller controls or influences the output-path argument passed to calc-tax.py.
  2. The attacker selects an existing writable file, a traversal path leading outside the intended report directory, or a symbolic link to a writable target.
  3. The script calls open(output_path, 'w', encoding='utf-8').
  4. The target file is truncated.
  5. The generated Markdown report replaces the original contents.

Impact Assessment

Successful exploitation can destroy or replace files writable by the Agent process. Potential consequences include loss of user data, corruption of project files, or modification of configuration and script files where the generated report content has a meaningful effect.

The issue does not by itself bypass operating-system permissions: protec ...[truncated 178 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define a dedicated report-output directory and resolve the requested destination against its canonical path.
  2. Reject destinations that escape the approved directory after path normalization.
  3. Reject absolute paths unless explicitly required and separately authorized.
  4. Use exclusive creation mode ('x') so existing files are not overwritten by default.
  5. If overwriting is required, expose it through an explicit option and request confirmation where interactive operation is possible.
  6. Reject symbolic links and verify the destination immediately before opening it.
  7. Where supported, use low-level file-opening flags such as O_CREAT, O_EXCL, and O_NOFOLLOW to reduce symlink and race-condition risks.
  8. Write to a safely created temporary file in the approved directory and atomically rename it after successful report generation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code is broadly aligned with the stated domain of Taiwan real estate tax estimation and reporting, and it does generate tax estimate reports for sale, gift, and inheritance scenarios. However, the declared description claims coverage of additional tax types that are not implemented in this code chunk, specifically 財產交易所得稅, 房屋稅, and 地價稅. It also suggests use for comparing scenarios such as self-use vs rental vs business, but the code only uses a self_use flag and has no rental/business treatment. Additionally, although the input format mentions a 'buy' scenario, the actual code does not support it beyond returning an unsupported scenario message. Therefore the description overstates the implemented coverage and supported planning scenarios, making this a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The operational instructions, tax categories, and usage guidance are presented almost entirely in Traditional Chinese and framed specifically for Taiwan, but the document does not explicitly state that the skill is Taiwan-region/language specific or offer a language option. This can violate language/locale policy when users are not given an opt-in or clear locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written in Traditional Chinese and does not provide an opt-in, alternative language, or explanation that the skill is intentionally limited to a Chinese/Taiwan-specific audience. Under the policy rule for natural-language violations, forcing a specific language without user choice is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code hard-codes user-facing natural-language output in Traditional Chinese, beginning with function documentation and continuing throughout the generated reports. The file does not offer any language selection or explain a justified region-specific restriction, which makes the locale policy constraint implicit rather than opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill embeds a separate analytics workflow unrelated to tax calculation, instructing the agent to record usage after task completion. This creates an unnecessary side effect that can leak behavioral metadata, expands the operational surface of the skill, and normalizes execution of non-essential commands without explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation tells the agent to log task usage but does not clearly warn users that using the skill results in activity recording. Even if the collected data is minimal, undisclosed telemetry undermines user consent and can expose usage patterns or project metadata in environments where skill execution should be side-effect free.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire template is written in Traditional Chinese and provides no indication that language selection is optional or that the skill is limited to a Chinese-speaking or region-specific context. Under the policy, fixed language output without user opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire reference file is written only in Traditional Chinese and presents tax information without offering any language or locale choice. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file contains user-facing natural-language guidance exclusively in Chinese and does not mention any option to use another language. Under the stated policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document title and all instructional content are written exclusively in Traditional Chinese, with no indication that users may request another language or locale. Under the policy rule for natural-language constraints, this is a locale/language restriction without explicit user opt-in or documented justification in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.