The skill is related to tax compliance, but it needs Review because it under-discloses remote data handling, persistent credentials/logs, and optional MCP client configuration changes.
Review this before installing in an enterprise or advisory environment. Treat questions, risk scenarios, and web self-check metrics as potentially sent to the vendor's remote service, and avoid entering confidential payroll, R&D, audit, or tax-return details unless that is approved. Check whether TAX_ENABLE_AUTOSETUP is set before running the config scripts, and be aware that credentials/logs may remain in ~/.tax-policy-client or browser localStorage.