InvoiceGuard Pro

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's code and runtime instructions mostly match an invoice-checking purpose, but there are several mismatches and undeclared dependencies (Feishu/tax API credentials, external CLI/tools, and an explicit server IP) that are not declared in the skill metadata, so you should clarify before installing.

This skill appears to implement invoice OCR, duplicate detection and report generation, but it depends on external CLIs and service credentials that are not declared in the skill metadata. Before installing or enabling it: (1) Ask the publisher which binaries must be present (e.g., miaoda-studio-cli) and which environment variables or tokens are required for Feishu and the national tax API. (2) Confirm where Pro 'tax verification' requests run and how captchas are handled — crawling a government site may have legal/usage constraints. (3) Verify the hardcoded deployment server IP (124.220.60.10) and ask whether any telemetry or outbound connections are made to that host. (4) If you will use Pro features, create dedicated, scoped credentials for Feishu/tax APIs and test in an isolated environment with non-production data. (5) If the skill will be allowed to run autonomously, restrict its network access or review logs for unexpected external calls. If the publisher cannot clearly justify the undeclared dependencies and the IP reference, treat the package with caution.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.