Back to skill

Security audit

tax-high-tech-deduction

Security checks across malware telemetry and agentic risk

Overview

The skill is related to tax compliance, but it needs Review because it under-discloses remote data handling, persistent credentials/logs, and optional MCP client configuration changes.

Review this before installing in an enterprise or advisory environment. Treat questions, risk scenarios, and web self-check metrics as potentially sent to the vendor's remote service, and avoid entering confidential payroll, R&D, audit, or tax-return details unless that is approved. Check whether TAX_ENABLE_AUTOSETUP is set before running the config scripts, and be aware that credentials/logs may remain in ~/.tax-policy-client or browser localStorage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Lp3

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding
The skill declares no permissions, yet the analysis indicates access patterns consistent with environment, file read/write, and network capabilities. That mismatch prevents informed consent and review, and in this context could expose sensitive tax data, modify local agent configuration, or enable undisclosed remote communication.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
This is a serious description-behavior mismatch: the skill presents itself as a narrow tax-compliance assistant, but the detected behavior includes host-agent detection, MCP/client config modification, remote API-key registration, persistent local state/logging, and web-search fallback. In a skill handling potentially sensitive financial and personnel records, undisclosed configuration changes and outbound data flows materially increase the risk of credential leakage, privacy violations, and supply-chain style compromise.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The documentation instructs the agent to install other skills and even an entire skill matrix, which expands trust and execution scope far beyond the stated single-purpose tax assistant. That creates a lateral-expansion risk where a benign user query can lead to additional packages, permissions, or behaviors being introduced without focused review.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill claims session-only, non-retained handling, but also directs users to external web pages and shared service backends for interactive processing. In this tax and R&D compliance context, users may submit payroll, project, equipment, and expense-allocation data, so inconsistent privacy claims can lead to unconsented exposure of sensitive business information to third-party infrastructure.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The privacy statement says only a local anonymous identifier is generated and no device or personal data is collected, but the rest of the skill describes external links, shared backends, and service calls that are inconsistent with that assurance. Misrepresenting data handling is dangerous because it can cause users to disclose highly sensitive corporate tax, employee, and R&D records under false privacy expectations.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The initialization path performs host-agent detection and can modify user MCP client configuration files for Claude, Cursor, and VS Code/Cline. That behavior exceeds the declared tax-compliance assistant scope and creates persistence/installation-like side effects on the host, which is dangerous because a skill can silently alter how the user’s tooling connects to services or launches local code.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill hard-codes an external MCP endpoint and uses identifiers for a different service than the manifested skill metadata, which indicates scope mismatch and possible service substitution. This is dangerous because users invoking a tax-deduction assistant could be transparently routed to another remote service, enabling data exfiltration, unauthorized behavior changes, or trust-boundary violations.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The code fingerprints the host by inspecting environment variables, user home directories, editor folders, and stdin characteristics to infer which agent is running. Even without collecting a full device fingerprint, this reconnaissance is unrelated to tax-assistance functionality and increases risk by enabling environment-specific behavior, stealthy persistence decisions, or targeted configuration tampering.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The module writes to user-level Claude, Cursor, and VS Code/Cline configuration files, modifying MCP server registrations outside the skill’s declared domain. This is dangerous because it gives the skill installation and persistence capability across developer tools, potentially redirecting future sessions to remote or local code without the user clearly understanding the change.

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The module documentation minimizes networking responsibility, but the code explicitly chooses a cloud HTTP transport and embeds a remote endpoint. This discrepancy is dangerous because it can mislead reviewers and users about the skill’s actual trust boundaries, reducing informed consent for remote data flows and making suspicious connectivity easier to hide.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The code performs arbitrary public web-search fallback using user questions, sending potentially sensitive tax/compliance scenarios to third-party search engines outside the primary MCP service boundary. In a tax compliance assistant, user prompts can contain confidential financial, personnel, or audit-risk details, so silent fallback materially increases data exposure and weakens source integrity by returning scraped public results.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The page claims it only uses public rules and does not involve enterprise private data, yet the implementation later sends user-entered tax/compliance metrics to a remote service. Even if identity fields are excluded, those metrics can still be sensitive business information, so the mismatch undermines informed consent and creates unnecessary data exposure.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The code silently auto-registers a remote client and stores an API key plus client identifier in localStorage, which is accessible to any script running in the page origin. This creates persistent credentials in a browser storage area commonly exposed by XSS, third-party scripts, shared devices, or browser extensions, and it is not justified by a simple tax-rule workflow.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The interface tells users that entered data is local-only and not uploaded, but the workflow later transmits collected metrics to a remote API after consent. This inconsistent messaging can cause users to disclose sensitive operational and tax data under false assumptions, making the data handling deceptive and riskier in a compliance context.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The installation triggers are vague and action-oriented, making it easy for ordinary language to cause unintended installation behavior. In this skill's context, that is more dangerous because the broader document already indicates undeclared capabilities and cross-skill expansion, so accidental invocation could change the user's environment or trust boundary.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Repeated broad installation triggers increase the chance of unintended activation and normalize automatic package expansion. Given the surrounding behavior mismatch and external-service references, accidental trigger matching could lead to unreviewed installation or remote interaction beyond what users expect from a tax advisory skill.

Vague Triggers

High
Confidence
91% confidence
Finding
The instruction to trigger on 'related intent' is overly broad and effectively encourages proactive link injection and workflow redirection without a precise user request. In this context, that can steer users to external sites and data-processing flows whenever the skill loosely infers relevance, increasing the chance of unconsented disclosure and unwanted off-platform interaction.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
User tax questions and risk scenarios are transmitted to a remote service without any explicit runtime disclosure, consent step, or visible minimization controls. Because this skill is positioned for high-tech enterprise qualification, R&D expense deduction, and audit-risk handling, prompts are likely to contain highly sensitive business, tax, and employee information, making silent external transmission a meaningful privacy and compliance risk.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The client automatically registers for an API key with a remote service and persists the credential and device identifier locally without a visible warning or consent flow. Even though the code avoids host fingerprinting and logs only a prefix, silent enrollment and credential storage still create privacy, governance, and surprise-networking concerns in enterprise environments.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The server forwards tool arguments over the network to a fixed third-party endpoint without any user-facing disclosure or consent mechanism in this file. In the context of a tax/compliance assistant, inputs may contain sensitive financial, payroll, R&D, or tax-risk information, so silent transmission to an external service creates a meaningful confidentiality and compliance risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The page contacts the remote service to auto-register and obtain/store an API key before giving a clear user-facing warning that this bootstrap action will occur. That means identifiers and credential material may be created and persisted without informed user approval, which is especially problematic in a tool handling business-sensitive tax data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.