tax-risk-scanner财税风险扫描与合规处理,如需正式版或需求定制请联系微信-jacky_zhouxj
Security checks across malware telemetry and agentic risk
Overview
The skill's described capabilities (backend invoice/status verification, rule-engine updates, third-party handoffs) are not fully supported by the instruction-only package and the SKILL.md contains vague data‑handling and consent steps—this mismatch warrants caution before install/use.
This skill is an instruction-only conversational design that promises backend checks (invoice verification, rule‑engine lookups, monthly updates) and accepts uploads of financial documents, but provides no technical details about where analysis runs or how data is protected. Before using or sharing sensitive financial data: 1) Ask the author to specify how invoice verification works (what APIs or services, with endpoints and auth requirements). 2) Request a written privacy/data-retention policy: are files uploaded off-device, how long are they kept, and who can access them? 3) Require an explicit consent flow before any data is shared with third‑party advisors and prefer redacted/minimal data uploads. 4) Avoid sending full payroll/tax files until you confirm secure transmission (HTTPS, server owner identity) and legal compliance. 5) If you need true invoice authenticity checks, insist on documented integrations with official tax-authority APIs or an audited backend; otherwise treat results as heuristic guidance only. If the developer cannot clarify these points, consider the skill suspicious and avoid submitting real sensitive documents.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
