Back to skill

Security audit

US Tariff Lookup

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a tariff-lookup purpose, but its offline/privacy promises conflict with instructions and outputs that steer customs queries and documents to the publisher's website.

Review this before installing if you need strict offline handling. The local script appears limited, but the skill instructions can cause an agent to contact invoicetariff.com for live lookups and to point users toward uploading customs documents; do not use it with sensitive entry summaries unless that data flow is acceptable, and verify tariff/refund outputs against official sources or a customs professional.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
Deterministic US tariff engine bundled as a single script (`scripts/tariff.mjs`,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
Deterministic US tariff engine bundled as a single script (`scripts/tariff.mjs`,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/tariff.mjs (reported line 1)May include surrounding context.

js
var ve={version:"0.3.1",asOf:"2026-09-19",mfn:[{hts8:"61091000",description:"T-shirts, singlets and other vests, knitted, of cotton",descriptionZh:"\u68C9\u5236\u9488\u7EC7T\u6064/\u80CC\u5FC3",general:"16.5%",keywordsZh:["T\u6064","\u68C9\u5236","\u9488\u7EC7","\u4E0A\u8863"],sample:!0},{hts8:"42021200",description:"Handbags, with outer surface of plastic sheeting or of textile materials",descriptionZh:"\u5851\u6599/\u7EBA\u7EC7\u9762\u6599\u624B\u63D0\u5305",general:"17.6%",keywordsZh:["\u624B\u63D0\u5305","\u7BB1\u5305","\u5973\u5305"],sample:!0},{hts8:"85171300",description:"Smartphones",descriptionZh:"\u667A\u80FD\u624B\u673A",general:"Free",keywordsZh:["\u624B\u673A","\u667A\u80FD\u624B\u673A"],sample:!0},{hts8:"73181500",description:"Threaded screws and bolts, of iron or steel",descriptionZh:"\u94A2\u94C1\u5236\u87BA\u4E1D/\u87BA\u6813",general:"9% + 0.5\xA2/kg",keywordsZh:["\u87BA\u4E1D","\u87BA\u6813","\u7D27\u56FA\u4EF6"],sample:!0},{hts8:"87032300",description:"Motor cars with spark-ignition engine of 1500cc-3000cc",descriptionZh:"\u706B\u82B1\u70B9\u706B\u5F0F\u4E58\u7528\u8F66\uFF081.5-3.0L\uFF09",general:"2.5%",keywordsZh:["\u4E58\u7528\u8F66","\u6C7D\u8F66"],sample:!0},{hts8:"30049000",description:"Medicaments, put up in measured doses, other",descriptionZh:"\u6210\u5242\u836F\u54C1\uFF08\u5176\u4ED6\uFF09",general:"Free",keywordsZh:["\u836F\u54C1","\u6210\u836F"],sample:!0},{hts8:"44071100",description:"Coniferous wood sawn lengthwise, of pine",descriptionZh:"\u677E\u6728\u952F\u6750",general:"Free",keywordsZh:["\u952F\u6750","\u6728\u6750","\u677E\u6728"],sample:!0},{hts8:"94032000",description:"Other metal furniture",descriptionZh:"\u5176\u4ED6\u91D1\u5C5E\u5BB6\u5177",general:"Free",keywordsZh:["\u91D1\u5C5E\u5BB6\u5177","\u5BB6\u5177"],sample:!0},{hts8:"64039960",description:"Footwear, uppers of leather, other",descriptionZh:"\u76AE\u9769\u9762\u978B\u9774\uFF08\u5176\u4ED6\uFF09",general:"8.5%",keywordsZh:["\u978B","\u76AE\u978B","\u978B\u9774"]
...[truncated 28 chars]

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README makes strong privacy and execution assurances ('zero network calls' and 'fully offline') while elsewhere advertising a 'live update feed' and 'live-DB fallback'. In a security-sensitive agent ecosystem, contradictory claims about network behavior can cause operators to permit a skill under false assumptions, which may expose sensitive trade data or violate offline-only deployment policies.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation says ACE 7501 parsing is '100% locally' and 'nothing uploaded' while also mentioning live update and live fallback behavior elsewhere, creating ambiguity about whether user-provided customs documents or derived query data might ever be sent externally. This is dangerous because users may paste sensitive import, valuation, or supplier information assuming strict local processing when the actual behavior is unclear.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill markets itself as fully local and says no network is required, but later instructs the agent to call external APIs when local search data is insufficient or outdated. This creates a trust-boundary mismatch: users may provide sensitive product, tariff, or customs-related details believing processing is offline, while the agent is actually directed to transmit queries to a third party.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation strongly assures users that ACE Form 7501 parsing is local and never uploaded, but elsewhere requires live fetching for answers dependent on newer rules. In practice, an agent could combine parsed customs-document facts with remote lookups during the same task, undermining the privacy expectation and risking disclosure of sensitive import data or derived commercial information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a US import tariff toolkit focused on goods imported into the United States, including US duties, US refund paths, and offline ACE 7501 parsing. In addition to that, the code contains a separate international destination ruleset with VAT/GST, de minimis thresholds, and tariff-source metadata for countries such as GB, DE, FR, IT, NL, ES, PL, CA, AU, NZ, JP, SG, KR, AE, and CN, and routes requests to a non-US simplified regime when destCountry is not US.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code tells users ACE 7501 text is parsed locally and 'NOT uploaded anywhere,' but later directs them to upload original documents to an external site for a line-by-line audit package. This conflicting privacy messaging can induce users to disclose sensitive customs records, importer details, and financial data under a false sense of offline-only handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file describes deterministic tariff, refund-eligibility, and deadline outputs that could influence compliance and money-sensitive decisions, but it does not include any explicit caution about verification before use or limits of the tool. Under the markdown variant of SQP-2, user-facing descriptions should warn about behaviours that could affect user data, privacy, or system integrity; here the primary concern is consequential decision-making without a cautionary disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises offline operation but actively steers users to an external commercial website and API fallback, creating an undeclared data-flow boundary. In a security-sensitive agent context, this can cause users or higher-level orchestration to disclose product, shipment, tariff, or entry-summary data to a third party contrary to user expectations or policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script supports both Chinese and English in many messages via a locale flag, but the shared metadata emitted by N() always includes the disclaimer text in English only: "Estimates only — not customs advice. Confirm with your licensed customs broker before filing." This is a natural-language locale policy inconsistency because the tool otherwise presents bilingual behavior and does not offer a localized disclaimer for non-English users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.