Bookkeeping Agency Skill System

ReviewAudited by ClawScan on May 10, 2026.

Overview

This instruction-only bookkeeping workflow skill is coherent and has no code or install step, but it can guide processing of sensitive tax, financial, customer, HR, bank, and tax-system information.

Install only if you intend to use it for bookkeeping-agency operations. Keep tasks narrowly scoped, avoid providing raw credentials or unredacted customer records, require human review for tax filings, invoice handling, banking, and customer-data workflows, and review the full untruncated reference set before relying on all capabilities.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If used broadly, the agent may handle many internal datasets and generate operational conclusions automatically.

Why it was flagged

The skill can direct automated collection and processing across many business systems. This is central to the stated analytics purpose, but users should set clear source and approval boundaries.

Skill content
多源原始数据:业务系统数据...财务系统数据...税务系统数据...人力资源数据...外部数据... AI自动执行数据采集、格式标准化、缺失值处理、异常值标记,无需人工干预
Recommendation

Limit each task to user-approved datasets and review automated outputs before making business, tax, or customer decisions.

What this means

Providing bank or tax-system authorization materials could expose sensitive account access if handled carelessly.

Why it was flagged

The tool/integration planning workflows may involve tax-system certificates, UKeys, bank account information, and authorization documents. This is expected for bookkeeping integrations but is high-impact account authority.

Skill content
数字证书/税务UKey配置要求...企业网银账户信息及授权文件;多银行统一对接需求
Recommendation

Do not paste secrets into prompts; use least-privilege service accounts or redacted configuration details, and require human approval for any live tax, banking, or filing action.

What this means

Poorly redacted source records could leak customer-specific facts into future FAQ, training, or support outputs.

Why it was flagged

The skill describes turning customer consultations, tickets, and feedback into reusable knowledge-base content. It calls for de-identification, which is good, but this still creates reusable context from sensitive customer material.

Skill content
客户历史咨询记录(脱敏)...客服工单数据...客户投诉与反馈记录...输出:客户FAQ知识库
Recommendation

Use only de-identified records, review generated knowledge-base entries for cross-customer leakage, and define retention and access-control rules.