Back to skill

Security audit

财税法务审查与法税同审指引

Security checks across malware telemetry and agentic risk

Overview

The skill is a plausible tax/legal review assistant, but it adds under-disclosed cloud registration, credential storage, generic web fallback, local logging, client configuration changes, and bulk skill installation capability.

Install only if you are comfortable with cloud processing by mcp.aitaxs.top, local API-key and log persistence, possible fallback searches through public search engines, and optional installation/configuration of related skills. Avoid entering privileged, confidential, or client-identifying tax/legal facts unless you have reviewed those data flows and can manage the stored local files and browser credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (25)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill claims no declared permissions, yet the detected capabilities include environment access, file read/write, and network connectivity. That combination enables local configuration changes, secret exposure, and outbound data transmission without transparent consent or least-privilege controls, which is dangerous for a compliance-focused skill handling potentially sensitive legal and tax data.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This is a strong description-behavior mismatch: the skill is presented as a narrowly scoped tax/legal review assistant, but the detected behavior includes client fingerprinting, local MCP config modification, API key registration/storage, remote service proxying, web-search fallback, and installation/routing of other skill packages. Hidden installation, persistence, and networked expansion materially increase attack surface and can lead to unauthorized data exfiltration, local tampering, and supply-chain risk.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The module can automatically modify local MCP/editor configuration files based on host detection, which is behavior outside the declared purpose of a tax/legal review assistant. Even though writes are gated by flags or invocation mode, this creates unauthorized persistence/integration risk by altering user tooling and steering the host toward a remote or local MCP endpoint without explicit, informed consent per client.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The code inspects environment variables and scans user home/config directories to fingerprint which agent/editor is present. For a tax/legal due diligence assistant, this host reconnaissance is unnecessary to core business functionality and increases privacy and attack-surface concerns by collecting execution-context details that can be used to tailor persistence or integration behavior.

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The documentation claims the module does not handle networking and introduces no new endpoints, yet the code hardcodes and distributes a remote HTTP MCP service URL. This mismatch is dangerous because it can mislead reviewers and users about outbound connectivity and trust boundaries, reducing the likelihood that remote access is properly vetted.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The embedded service constants reference a different skill identity ('tax-policy-knowledge/财税政策知识库') than the package being reviewed ('tax-legal-tax-review'). This cross-skill mismatch can silently bind the host to the wrong remote service, causing data routing errors, unexpected capabilities, and supply-chain style trust violations because users think they installed one skill but configure another.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The client includes a local fallback to general public search engines despite the skill being presented as a specialized tax/legal review assistant. This expands the skill’s effective capability and trust boundary, and can cause sensitive tax/legal prompts to be sent to third-party search providers without clear disclosure or domain-specific controls.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The code silently auto-registers with a remote service, retrieves credentials, and persists them locally, while the skill description does not disclose this behavior. Hidden network enrollment and credential storage change the operational and privacy model of the skill, and can expose users or hosts to tracking, unauthorized outbound communication, and secret persistence they did not expect.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The code implements broad public internet search and HTML scraping/parsing logic that is not justified by the stated tax/legal review scope. In this context, user questions may contain confidential diligence facts or deal terms, so sending them to search engines creates unnecessary third-party data exposure and undermines the claimed constrained tool surface.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file claims to support a 财税法务审查 skill, but the implementation actually exposes a different remote tax-policy knowledge service. This capability mismatch is dangerous because it can mislead users and reviewers about what data is processed and where it is sent, undermining trust boundaries and enabling unauthorized data flow under a misleading skill identity.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The code proxies all tool calls to a public cloud MCP endpoint without demonstrating that remote transfer is necessary for the stated local tax/legal review function. In this context, users may submit sensitive due-diligence, tax, or legal facts, so undisclosed external transmission creates confidentiality and supply-chain risk.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
During startup, the server imports local setup logic and invokes environment detection with potential auto-configuration behavior gated only by an environment variable. Agent/environment modification is unrelated to tax/legal review and expands the skill's authority, creating risk of unexpected persistence, configuration tampering, or broader host interaction than users expect.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The script’s documented purpose is to automatically install a matrix of other skills by reading a manifest, selecting local or remote ZIP packages, and unpacking them into the user’s skills directory. That is a privileged software installation capability unrelated to the declared tax/legal review function, and it creates a supply-chain risk path where invoking this skill can expand code/content on the host beyond the user’s original intent.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The channel-detection logic probes user filesystem locations and PATH to infer whether ClawHub is installed, which is unnecessary for tax/legal analysis and reveals environmental information that can be used to tailor subsequent remote fetches. In context, this capability supports covert package-install behavior and increases the script’s ability to adapt to the host environment without explicit disclosure.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The code resolves remote URLs from the manifest and downloads ZIP archives for installation into ~/.skills, enabling remote content delivery and persistence on the user system. Although it includes a basic zip-slip check, it does not verify cryptographic signatures, trusted publishers, or immutable digests, so a compromised manifest, server, or package can lead to arbitrary skill installation and downstream code/content execution.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The UI states that entered enterprise data is kept local and not uploaded, but the workflow later transmits collected indicator data to a remote API after consent. Even if identity fields are excluded, this is still a data-flow mismatch that can mislead users about where their inputs go and undermine informed consent for sensitive compliance information.

Description-Behavior Mismatch

High
Confidence
89% confidence
Finding
The file contains unrelated R&D-hours, project-document, ledger-export, and ESOP helper functions that are outside the declared legal-tax review purpose. Extra dormant capabilities increase attack surface, complicate review, and create a path for future activation of features that may process or export data users did not expect this skill to handle.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The page silently auto-registers a client with a remote service and stores a reusable bearer API key plus client identifier in localStorage. Long-lived secrets in localStorage are accessible to any JavaScript running in the origin, so an XSS or third-party script issue would expose credentials and permit unauthorized API use or user tracking.

Intent-Code Divergence

Low
Confidence
77% confidence
Finding
The code comments assert that q_* identity fields are never sent with collected metrics, but the deep-analysis prompt generator later embeds the company name into text intended for copying into an external agent conversation. This creates a privacy expectation gap: users may infer the company identity remains isolated when the UI actively prepares it for disclosure outside the page.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The markdown describes external service-backed processing and shared knowledge/reporting infrastructure, but the disclosure is not sufficiently explicit about data transmission, retention, third-party processing, and what user content may leave the local environment. In a tax/legal due-diligence context, even seemingly routine queries may contain highly sensitive transaction, compliance, or privileged information, making ambiguous disclosure particularly risky.

Missing User Warnings

Medium
Confidence
99% confidence
Finding
The logger writes raw questions, scenarios, and error details to local JSONL files. For a tax/legal diligence assistant, these fields can contain highly sensitive commercial, financial, personal, or dispute-related information, so plaintext local logging creates a significant confidentiality risk if the workstation, backups, or shared home directory are accessed by others.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The client automatically performs remote registration and obtains credentials without any user-facing warning or consent flow. In a legal/tax context, silent outbound enrollment is especially problematic because users may reasonably expect confidentiality and controlled data handling, and the registration process creates persistent identifiers and a remote dependency without transparent notice.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The network call sends JSON-RPC requests and user-supplied arguments to a remote cloud endpoint, but this file provides no user-facing disclosure at the point of collection or transmission. For a tax/legal diligence assistant, that omission is material because inputs may contain confidential transaction, compliance, or client data whose external transfer requires informed consent.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The sample-data flow automatically advances and triggers self-check logic, which in turn can initiate remote registration and submission once consent is granted, without a dedicated up-front warning that this path leads to network activity. In a compliance tool handling sensitive business metrics, indirect or surprise transmission paths weaken meaningful consent and increase the chance of accidental disclosure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The code persistently stores API credentials in localStorage but does not provide prominent runtime disclosure to users about credential creation, persistence, or reuse. This is risky because users cannot make an informed decision about device-resident secrets, and compromised browser context or shared workstations could leak tokens tied to the service.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.