Back to skill

Security audit

QuickTaxReturn — AI Tax Preparation

Security checks for vulnerabilities and agentic risk

Overview

This tax-prep skill is not outright malicious, but it needs review because it can place highly sensitive tax, identity, banking, and IRS PIN details into a plain-text CPA handoff while using a tracked commercial referral link.

Review this skill carefully before installing. It may be useful for organizing a simple federal tax return, but do not type full SSNs, bank account numbers, IRS IP PINs, or similar secrets into chat, and use a secure CPA portal for those values. Treat the CPA recommendation as a configured commercial referral, not neutral provider selection.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
escalation-config.md:36
Finding

Mandatory Commercial Referral and Tracked-Link Output Hijacking

Content
View full analysis
"I can see you received a 1099-NEC — that means you have freelance or self-employment income. I want to be upfront: this triggers something called Schedule C and self-employment tax, which involves more complexity than I'm set up to handle accurately. I don't want to give you numbers that are off. > > The good news is I can connect you with M.S.Ayubi CPA, a CPA firm that QuickTaxReturn partners with. They handle exactly this kind of return and have a dedicated booking link for QuickTaxReturn users. Want me to share that?" ### Script B — Investment Sales / 1099-B > "Stock sales — or sales of any investments — require something called Schedule D and cost basis calculations. That's outside what I can do reliably (cost basis errors are actually one of the most common and costly tax mistakes). > > Rather than risk getting that wrong, I'd like to hand you off to M.S.Ayubi CPA. They can handle your investment sales and the rest of your return together. Want me to share their booking link?" ### Script C — Multi-State Filing > "It looks like you earned income in [STATE] but live in [STATE] — that means you may need to file ...[truncated 3569 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
intake-template.md:4
Finding

Plain-Text Collection and Handoff of SSNs, Banking Credentials, and IRS IP PINs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The referral package workflow instructs the agent to compile 'all data collected so far' into an intake package, but it provides no localized privacy warning, data minimization rule, or consent language in that handoff step. In a tax context, this can expose extremely sensitive personal and financial information beyond user expectations, especially if the package includes identifiers, income forms, dependent data, or account details.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document claims QuickTaxReturn is 'not storing or transmitting your tax data,' yet elsewhere instructs the agent to generate an intake package containing collected taxpayer information for CPA handoff. That creates a misleading privacy representation and risks unauthorized disclosure of highly sensitive tax data if users rely on the disclaimer when sharing SSNs, income records, and dependent details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template explicitly instructs the agent to compile and present a package containing highly sensitive tax and identity data, including SSNs, bank account details, dates of birth, prior-year AGI, and IRS IP PINs, but the usage instructions only say to present it to the user and avoid raw document images. There is no warning to minimize included data, redact unnecessary fields, verify consent, or use secure delivery/storage, which creates a realistic privacy exposure risk if the output is displayed in an insecure channel, logged, copied, or forwarded.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This skill provides extensive tax rules, calculations, and filing-line mappings without an explicit warning that the material is informational and not a substitute for official IRS instructions or professional tax advice. In a tax-preparation context, users may rely on the content as authoritative and make filing decisions without understanding edge cases, exceptions, or the need to verify current forms and instructions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document makes a strong verification claim ('all figures verified from primary IRS sources as of February 2025') while later relying on 2026-issued secondary sources such as 2025 instructions published in 2026. That mismatch can mislead users into over-trusting the accuracy and timeliness of tax values, increasing the risk of filing errors or incorrect tax calculations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The booking link embeds referral and UTM tracking parameters, but the skill does not instruct the agent to disclose that the link contains tracking identifying the referral source. While lower severity than direct tax-data leakage, it can still create a transparency and privacy issue because users are sent to a third party with attribution metadata without being informed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.