Back to skill

Security audit

tax-environmental

Security checks across malware telemetry and agentic risk

Overview

The skill is a useful environmental tax assistant on the surface, but it also installs or proxies broader tax-policy tooling, persists credentials and logs, and sends sensitive compliance questions to a general remote backend under unclear scope.

Install only if you are comfortable with this package using a broader tax-policy backend, registering and storing API keys/client IDs, writing local logs, and potentially modifying MCP client configuration when setup is enabled. Treat submitted company scenarios, environmental metrics, tax questions, and copied prompts as sensitive business information; review the files and disable auto-setup or remote workflows unless you explicitly want them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Lp3

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding
The manifest declares no permissions, yet the detected capabilities include environment access, local file read/write, and network access. That combination can enable covert exfiltration, local configuration tampering, or persistence without informed user consent, especially in an agent ecosystem where users expect least-privilege declarations.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
This is a serious description-behavior mismatch: the skill is presented as a narrow environmental-tax/carbon compliance assistant, but the detected behavior includes host fingerprinting, local MCP config modification, API-key registration/storage, broader tax functions, and public-search fallback. That creates a high risk of deceptive installation, overbroad access, and unsafe changes to the user's local agent environment under a misleading trust boundary.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
A skill advertised as topic-specific also nudges users to install a broader skill matrix and related cross-topic skills. In practice this can expand the trust boundary and lead users to authorize more capabilities or content than intended, increasing exposure to unrelated functionality and supply-chain risk.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The privacy statement says no device or personal data is collected, but the same document describes generating an anonymous identifier for service calls and sending users to external web backends. Even if pseudonymous, this is still data processing and can mislead users about tracking, backend logging, and possible linkage of activity across sessions.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The bootstrap hard-codes a different remote MCP service (tax-policy-knowledge) than the declared environmental tax/carbon compliance skill. This creates a clear capability/identity mismatch: a user or host expecting one skill may silently connect to another backend, enabling unauthorized data flow, misleading responses, and supply-chain style service substitution.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The module performs host fingerprinting and can modify client MCP configuration files, which exceeds the stated scope of a tax/compliance assistant. Even if presented as convenience setup, software that inspects host environment and writes persistence-like configuration broadens trust boundaries and can stealthily alter how the agent platform connects to external services.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The client exposes broad tax-policy, tax-risk, and tax-calculation capabilities that materially exceed the skill's declared environmental-tax and carbon-compliance scope. This creates a scope-expansion/confused-deputy risk: users and hosting agents may trust the skill with a narrower permission model while the code can process unrelated tax matters and send them to a remote service.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The fallback search logic enumerates many unrelated tax domains and automatically broadens queries beyond the environmental/carbon remit. In fallback mode, this defeats the claimed specialization and can cause user data to be sent to third-party search engines for unrelated topics, expanding both functional scope and data exposure.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The policy Q&A API accepts arbitrary questions and categories without validating that they belong to environmental-tax or carbon-compliance workflows. This allows the skill to act as a general tax advisor despite being presented as a specialized compliance assistant, undermining least-privilege expectations and increasing remote data disclosure.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The risk_check interface is a generic enterprise tax-risk screening channel, not an environmental-tax or emissions-data compliance checker. Because users may submit sensitive business scenarios, this scope mismatch can expose broader operational and tax information to the remote backend under the guise of a narrow environmental skill.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The tax_calculate entry point accepts arbitrary tax_type values, enabling generic tax computations far beyond environmental protection tax and carbon-related accounting. In a skill advertised as domain-limited, this is dangerous because it bypasses user and platform assumptions about what data and decisions the skill should handle.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The module documentation describes a general 'tax policy' client rather than an environmental-tax/carbon-specialized component. Misleading documentation is security-relevant here because it masks the true breadth of the integration and can cause reviewers, operators, or users to apply the wrong trust boundary.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This server advertises an environmental-tax/carbon-compliance skill but actually proxies all tool calls to a generic tax-policy cloud endpoint with mismatched tool names and domain scope. That creates a capability-integrity problem: users and agents may send environmental compliance data under false assumptions, receive inapplicable guidance, or expose sensitive emissions/tax information to an unintended backend.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The module documentation explicitly describes a tax-policy MCP service rather than the advertised environmental-tax skill, which is a strong indicator of repurposed or mislabeled code. Misleading identity and documentation can cause operators to trust the wrong service, route regulated data incorrectly, and miss domain-specific limitations in the returned compliance advice.

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The offline workflow is materially out of scope for the declared skill, which is supposed to focus on environmental protection tax and carbon-emissions compliance. Instead, it provides broad tax-compliance and risk-guidance logic across VAT/CIT/PIT and corporate transaction scenarios, creating a dangerous capability mismatch that can mislead users into relying on incorrect domain guidance under the authority of the environmental-tax skill.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The code embeds unrelated risk assessment for topics such as invoice fraud, shell companies, private accounts, equity transfers, liquidation, family holding structures, and cross-border restructuring. In the context of an environmental-tax/carbon assistant, this expands functionality into sensitive tax-risk triage and corporate compliance areas without justification, increasing the chance of incorrect advice, unsafe user reliance, and policy evasion-oriented misuse.

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The documentation states that the tool provides only standardized process guidance, but the implementation performs substantive classification and assigns risk levels such as CRITICAL, MEDIUM, SCENARIO, and LOW. This mismatch can cause operators to trust the tool as a harmless workflow helper while it actually makes compliance judgments, reducing oversight and increasing the risk of users acting on incomplete or misleading assessments.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The page states that enterprise basic data is kept local and not uploaded, but the script automatically registers the browser with a remote service, generates a persistent client ID, and stores an API key in localStorage. Even if only metrics are later posted, this undisclosed remote enrollment and persistent credentialing materially contradicts the privacy representation and creates a tracking surface across sessions.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The consent dialog describes sending unrelated tax metrics such as R&D ratios and personnel proportions, while the actual transmitted fields are environmental/compliance indicators. This is a materially misleading consent notice: users cannot make informed decisions about data sharing if the notice describes different data than what the code sends.

Context-Inappropriate Capability

High
Confidence
91% confidence
Finding
The file contains unrelated R&D-hours analysis, ledger export, and project-document generation functions that do not match the stated environmental tax/carbon compliance purpose. Dormant or repurposed code expands attack surface, increases the chance of accidental exposure of unrelated business data, and undermines user trust about what the skill is actually designed to do.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The page tells users that only non-identifying indicator values are sent and that identity data is excluded, but it also encourages copying a deep-analysis prompt that includes the entered company name and compliance results into another AI agent. While this is not the same network path as the self-check API, it still facilitates disclosure of sensitive business identity and findings contrary to the privacy impression created by the page.

Vague Triggers

Medium
Confidence
81% confidence
Finding
Broad trigger phrases such as installing a full tax skill matrix can match generic requests outside this skill's environmental-tax scope. Overbroad activation increases the chance of unintentional invocation, social engineering of users into broader installs, and actions being taken outside the principle of least surprise.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The instruction to trigger on 'related intent' lacks precise boundaries, making activation ambiguous and potentially too aggressive. In an agent setting, fuzzy activation rules can cause unexpected link promotion, data routing to external services, or execution of broader workflows based on weak intent matching.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
User-provided questions and scenarios are transmitted to remote services, but this file does not provide a clear user-facing disclosure or consent mechanism at the point of collection. In a compliance-oriented skill, submitted content may include sensitive operational, tax, or emissions details, so undisclosed network transmission increases privacy and confidentiality risk.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The client automatically writes configuration, health-state, and log data to local disk without an obvious user-facing disclosure in this code path. Even if API keys are partially protected in logs, these files can still reveal usage patterns, device identifiers, service endpoints, and sensitive question/scenario metadata stored elsewhere in the module.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.