Back to skill

Security audit

财税中介机构AI合规咨询服务转型专题

Security checks across malware telemetry and agentic risk

Overview

This skill offers plausible tax-advisory help, but it also adds under-disclosed remote services, local logging, feedback transmission, admin endpoints, and bulk skill installation behavior.

Review before installing. Use this only if you are comfortable with tax questions and feedback being sent to the listed remote service and logged locally under ~/.workbuddy. Avoid pasting client-identifying or confidential taxpayer data unless you have approved that data flow. Do not use the matrix install command unless you intend to add or update multiple related skills from marketplace ZIP downloads.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Lp3

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding
The skill declares no permissions, yet the accompanying analysis indicates file read/write and network-capable behavior. That creates a transparency and consent gap: operators may invoke the skill believing it is content-only, while it can access local data or communicate externally. In a tax-advisory context, this is more sensitive because user prompts may include confidential taxpayer, contract, or firm operational data.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The described skill is framed as a compliance/advisory content package, but the static finding says it also performs remote API access, device identifier submission, web search, local config/log/cache writes, Git operations, cross-skill installation, and routing. This is a significant description-behavior mismatch that can conceal data exfiltration, environment modification, or unexpected tool use from users handling sensitive tax and client information. The skill context makes this more dangerous because tax advisory workflows routinely involve regulated, confidential business and personal data.

Description-Behavior Mismatch

High
Confidence
84% confidence
Finding
The client exposes broad tax-policy knowledge-base, update, feedback, and administrative operations that go well beyond the manifest’s stated advisory scope for tax intermediary AI compliance consulting. In a skill ecosystem, this kind of scope expansion increases attack surface and can enable unintended remote actions or data flows that users and reviewers would not reasonably expect from the declared purpose.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The one-click installation of related skills is a separate capability from advisory answering and is not disclosed by the manifest. Hidden installation/orchestration behavior is dangerous because it can silently expand code execution and permissions by bringing in additional skills the user did not explicitly review.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The code dynamically resolves file paths and loads external Python modules from the skill or project root using importlib, then uses them to route and install other skills. Dynamic loading and orchestration of adjacent files creates a code execution boundary outside the declared skill behavior and can be abused if those files are replaced or tampered with.

Context-Inappropriate Capability

High
Confidence
92% confidence
Finding
The client exposes Git administration endpoints such as init, backup, rollback, diff, and log, which are unrelated to a tax advisory role and can materially affect server-side state. These administrative actions expand the blast radius of the skill and could be abused to alter history, inspect changes, or trigger operational side effects on the remote service.

Intent-Code Divergence

Medium
Confidence
81% confidence
Finding
The docstring downplays risk by describing the router as standard-library only, while the implementation dynamically loads and executes external project files. This mismatch can mislead reviewers and users about the true trust boundary, causing underestimation of code execution risk from local file tampering or packaging abuse.

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The script can download ZIP archives from URLs in the manifest and install additional skills into the user's skills directory, which is materially broader than the declared tax-advisory/compliance purpose. This creates a supply-chain and unauthorized capability expansion risk: if the manifest or remote packages are tampered with, the skill can silently add new code/content outside the user's expected scope.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The code inspects local ClawHub config paths and CLI presence to infer the distribution channel, which is unnecessary host probing for a tax-advisory skill. Although limited, it gathers local environment information and alters network behavior based on host state, expanding the skill's reach into platform detection and reducing user transparency.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The skill invites activation from broad natural-language requests without clear boundaries or exclusion criteria. Overly broad invocation increases the chance the skill is selected in contexts where users did not intend to use a capability that may trigger network, file, or cross-skill behaviors, especially given the mismatch noted elsewhere. In a tax/compliance setting, mistaken activation can expose sensitive client matter details to unnecessary processing paths.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The shortcut usage language encourages very broad activation phrasing, which can cause the skill to engage on loosely related requests. When combined with hidden or under-disclosed capabilities, this creates a risk of unintended data handling, external queries, or environment changes from ordinary user prompts. The domain raises sensitivity because contracts, advisory drafts, and taxpayer data may be pasted into such shortcuts.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill logs user questions and scenarios to local JSONL files, including potentially sensitive tax, compliance, and business details, without clear disclosure or minimization. This creates a confidentiality risk because local logs may be readable by other processes, backups, support tools, or future users of the same environment.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Feedback submission persists user-provided questions and expected answers locally and sends them to remote endpoints without prominent disclosure or consent. Because tax and compliance prompts may contain confidential client facts, this behavior can leak sensitive business information beyond what users expect from an advisory skill.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The script is designed to write into the user's skills directory and potentially fetch packages over the network, yet the skill metadata describes an advisory/compliance service rather than an installer with side effects. This mismatch undermines informed consent and can lead users to trigger file writes and package installation without understanding the operational impact.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword "协议" is extremely broad and appears in many unrelated user requests, so using it as an automatic routing trigger can cause this skill to activate outside its intended contract/tax context. In a skill matrix that drives automatic installation or routing, this creates prompt-selection confusion and increases the chance of misrouting users into an overprivileged or irrelevant skill path.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword "模板" is so general that it can match a wide range of harmless requests unrelated to this skill, causing unintended skill activation. In an automated routing system, broad triggers weaken skill isolation and may expose users to the wrong workflows, templates, or downstream networked services.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword "审核" is ambiguous because it applies to many business, legal, financial, and content-review scenarios outside the intended tax/contract domain. This ambiguity can cause false activation and routing confusion, especially in a matrix described as the single source of truth for automatic installation and intelligent dispatch.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The keyword "评审" is insufficiently scoped and can match numerous unrelated enterprise requests, leading to accidental selection of this skill. Because this manifest is used for automatic routing, such broad triggers can degrade trust boundaries between skills and misdirect user inputs to the wrong package or service.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The term "合规" is broadly applicable across many organizational contexts and is too general for safe automatic skill routing. Since multiple skills in this matrix are compliance-related, this trigger materially increases cross-skill collisions and can send users into the wrong advisory workflow or remote knowledge service.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword "风险" is highly generic and likely to collide with a large number of unrelated prompts, especially in advisory environments where risk is discussed broadly. In this matrix, such a trigger can cause excessive skill activation and misrouting, undermining least-astonishment and potentially exposing users to unintended remote or template-driven behavior.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The contract-review skill's manifest includes several broad keywords without exclusion logic, making the routing surface overly permissive. In a large multi-skill ecosystem with automatic download and dispatch, this creates a real selection-integrity problem: ordinary user prompts may invoke the wrong skill, which can in turn expose unrelated templates, advice flows, or network-backed services.

Ssd 3

Medium
Confidence
96% confidence
Finding
The client stores natural-language questions, scenarios, and expected answers in local log and queue files, creating durable retention of potentially sensitive tax and compliance data. In this skill context, users are likely to submit confidential client or case details, so retained plaintext content materially increases exposure through local compromise, shared workstations, backups, or support collection.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
config/mcp_client.py:765