Back to skill

Security audit

制造业全生命周期涉税风险指引

Security checks across malware telemetry and agentic risk

Overview

This tax guidance skill has useful disclosed advisory features, but it also includes broad installation, persistent configuration, remote proxying, public search fallback, and local logging behaviors that need review before use.

Install only if you are comfortable with this skill contacting mcp.aitaxs.top, storing a local API key/client ID and logs, optionally modifying MCP client configuration when setup is enabled, and installing related skills from remote ZIP endpoints. Avoid entering confidential business, transaction, payroll, or personally identifying tax details unless you trust the remote service and local logging behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (60)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill claims no permissions, yet the analyzed behavior indicates access to environment data, local file read/write, and network connectivity. That combination enables silent configuration changes, local persistence, and remote communication without transparent user consent, which materially expands the attack surface.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
This is a major description-behavior mismatch: a tax-risk advisory skill is documented as also modifying MCP/client configs, registering for API keys, proxying requests to a remote server, persisting state locally, scraping third-party search engines, and installing other skills. Users trusting a tax assistant would not reasonably expect software installation, remote orchestration, or local configuration tampering, creating strong potential for deceptive execution and supply-chain compromise.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The documentation extends the skill into an external launcher for web portals and related workflows, which broadens user interaction beyond the declared tax-guidance purpose. External links and trigger-driven portal promotion can become a delivery path for tracking, phishing, or unreviewed remote functionality, especially when framed as part of a compliance workflow.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Cross-skill installation and matrix-wide routing are not necessary for answering manufacturing tax questions and create an avoidable supply-chain risk. A user invoking a tax skill could be induced to install additional packages or have queries routed elsewhere, expanding trust to code and services outside the original review boundary.

Intent-Code Divergence

Low
Confidence
80% confidence
Finding
The privacy statement is inconsistent: it says no device or personal data is collected, yet it also describes generating an identifier for service calls and using remote integrations. Even if the identifier is anonymous, inaccurate privacy claims can mislead users about tracking, correlation, and outbound data exposure.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The initialization module performs agent detection and MCP bootstrap/configuration logic that is unrelated to the declared manufacturing tax-risk advisory purpose. This creates an unnecessary capability to alter the user's toolchain and route future sessions to a remote service, which expands the trust boundary far beyond expected skill behavior and can enable persistence-like configuration changes.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
This code writes to user MCP/IDE configuration files on disk, including Claude, Cursor, and VS Code/Cline settings, which exceeds the expected scope of a tax advisory skill. Even if intended for convenience, modifying client config can establish durable access paths to a remote endpoint or local proxy and may interfere with existing user configuration, making it a security-relevant persistence and integrity risk.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The code fingerprints the host by inspecting environment variables, home-directory application folders, and stdio characteristics to determine which agent is running it. For a tax-risk assistant, this collection is unnecessary for core functionality and increases privacy and stealth concerns because it adapts behavior based on the local tooling environment.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The documentation states the module does not handle networking, yet the code selects a cloud HTTP transport and embeds a remote service URL. This mismatch is dangerous because it obscures actual remote connectivity behavior from reviewers and users, undermining informed consent and making security review materially harder.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The skill is presented as a narrowly scoped manufacturing tax-risk assistant, but it includes fallback public web-search capability that reaches general search engines. This expands the trust and data-flow boundary beyond the declared specialized service, increasing the risk of sending user tax questions to third-party sites and returning less controlled content.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The code performs outbound searches to Bing and Baidu using arbitrary user-provided queries, which is broader than the stated specialized tax-risk purpose. In a tax advisory context, queries may contain confidential business, transaction, restructuring, or liquidation details, so sending them to public search engines creates privacy, compliance, and content-integrity risks.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file implements a bulk installer/downloader for other skill packages, which materially exceeds the declared functionality of a manufacturing tax-risk assistant. This capability enables secondary payload delivery and environment modification under the cover of a benign tax skill, creating a supply-chain style risk and defeating user expectations about what the skill does.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The code detects the host channel, retrieves URLs from manifest data, downloads ZIP archives, and installs them locally. Even with a basic zip-slip check, this is dangerous because it performs remote code/content acquisition without any authenticity verification such as signature, pinned hash, or trusted publisher validation, enabling tampering or malicious package substitution.

Context-Inappropriate Capability

High
Confidence
93% confidence
Finding
Defaulting installation into ~/.skills gives the script persistence by writing new skill content into a user-level directory that may be automatically loaded later. In the context of a tax advisory skill, persistent deployment of additional packages is unnecessary and significantly increases the blast radius if the manifest or downloaded package is compromised.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The UI states that data is kept locally and not uploaded, but the code later posts metrics to a remote API after consent and also performs backend registration logic. This is a transparency and privacy vulnerability because users are materially misled about network behavior at the point they enter tax-related data.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The footer claims only non-identity tax metrics are sent, but the code also generates, persists, and transmits a long-lived client identifier and registers for an API key. Persistent identifiers can enable session linkage and re-identification over time, so the disclosure is incomplete and misleading.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The client logs raw user questions and scenarios to local files, including tax-policy questions and risk-check inputs that may contain sensitive financial, organizational, or personal data. Because logging occurs automatically without user warning, minimization, or masking, sensitive information can be exposed to other local users, backup systems, endpoint monitoring tools, or later compromise.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The server transparently forwards all tool-call arguments to a remote cloud endpoint, but this file provides no runtime disclosure, consent prompt, or data-handling warning to the user. In a tax/compliance skill, users may submit sensitive financial, corporate, or personally identifiable information; silent exfiltration to a third-party service increases privacy, confidentiality, and compliance risk.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Loading sample data triggers automatic self-check execution shortly afterward, which can initiate remote submission once consent has already been granted in the session. Even if the transmitted data is sample data, unexpected automatic network actions reduce user control and create a poor consent boundary for a tax-focused workflow.

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-advisory-practice",
      "name": "财税中介机构AI合规咨询服务转型专题",
      "package": "tax-advisory-practice.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-advisory-practice",
      "is_core": false,
      "board": "B",
      "version": "3.15.3",
Confidence
88% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-capital-reduction",
      "name": "减资撤资(未实缴减资)个人所得税财税合规专题",
      "package": "tax-capital-reduction.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-capital-reduction",
      "is_core": false,
      "topics": [
        "减资",
Confidence
88% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-compliance-dispute",
      "name": "合规争议财税专题",
      "package": "tax-compliance-dispute.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-compliance-dispute",
      "is_core": false,
      "topics": [
        "财税内审",
Confidence
88% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"name": "建筑施工行业财税合规专题",
      "slug": "tax-construction",
      "package": "tax-construction.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-construction",
      "is_core": true,
      "topics": [
        "建筑施工",
Confidence
88% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
],
      "version": "3.15.3",
      "download_urls": {
        "skillhub": "https://api.skillhub.cn/api/v1/download?slug=tax-contract-generation-review",
        "clawhub": "https://clawhub.ai/api/v1/download?slug=tax-contract-generation-review"
      },
      "board": "Shared",
Confidence
90% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-crossborder",
      "name": "跨境电商与贸易财税合规专题",
      "package": "tax-crossborder.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-crossborder",
      "is_core": false,
      "topics": [
        "跨境电商",
Confidence
88% confidence
Finding
https://api.skillhub.cn/

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.