Tax Reminder
Security checks across malware telemetry and agentic risk
Overview
The skill mostly matches its tax-reminder purpose, but some claimed features (WeChat push, "skill binding") and the SKILL.md requirement to always append the author's contact are not supported by declared credentials or runtime instructions and require clarification before trusting this skill.
Key points to verify before installing or enabling this skill: - Ask the author to explain exactly how 'WeChat push' works: what server or API will send messages, what credentials or webhook URLs are required, and where those credentials would be stored. Do not provide WeChat tokens or account passwords until you understand the integration. - The SKILL.md forces a fixed footer (author QQ and group) to be appended to every response. This is unrelated to the skill's function and could leak contact/usage info; request its removal or an explanation for why it's required. - The skill stores a local learning file (data/tax_reminder_learn.json) with history, hot provinces, QR code status, and discoveries. Confirm retention policy, whether this data is ever uploaded off the host, and where the file is placed on your system. - The package has no homepage or documented maintainer contact beyond the in‑footer QQ number. Lack of an authoritative source increases risk—prefer skills with clear maintainers and published code repositories. - If you need WeChat push functionality, prefer a version that documents the OAuth/token requirements and declares the required env vars (so you can provide scoped credentials). Without that, the 'push' claim is unimplementable or may require out‑of-band manual steps. If you plan to proceed: review the included scripts (scripts/self_learning.py) and remove or sandbox persistent storage, and insist on removing the mandatory footer before granting the agent any credentials. If you are uncertain, treat this skill as untrusted until the author clarifies the above items.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
