Back to skill

Security audit

离岸信托个人所得税合规与财富税务管理

Security checks across malware telemetry and agentic risk

Overview

This skill is a tax assistant, but it also includes broad remote-service, local logging, credential persistence, client-configuration, and matrix-installation behavior that users should review before installing.

Install only if you are comfortable with tax questions and scenarios being sent to the mcp.aitaxs.top service, with local plaintext API-key/config files and JSONL logs being created, and with optional matrix installation changing your local skill directory. Avoid entering highly sensitive client, trust, identity, or asset details unless you have reviewed the service's privacy and retention terms and can control local logs/backups.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill advertises no declared permissions, yet the analysis indicates capabilities for environment access, file read/write, and network operations. That combination creates a trust-boundary violation: users and host agents cannot accurately assess what the skill may touch, while the document also encourages external links, installation workflows, and remote service use that increase the likelihood of those capabilities being exercised.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This is a strong description-behavior mismatch: the skill is presented as a narrow offshore-trust tax compliance assistant, but static analysis indicates it can modify local MCP client configuration, install additional skills, register remote services, persist local state, and fall back to web search. Such hidden expansion of scope is dangerous because users may grant trust based on a specialized tax use case while the skill actually behaves like a broader installer/router with local system impact and remote data egress.

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
The skill states boundaries such as not handling certain actions, yet elsewhere it pushes users toward external web workflows and installation of related skill packages. That inconsistency is risky because it can mislead users about where data goes and what actions the skill may trigger, weakening informed consent and making downstream behavior harder to evaluate safely.

Intent-Code Divergence

Low
Confidence
78% confidence
Finding
The privacy statement claims no device or personal data is collected, but the same document describes service calls, web interaction, and generation of identifiers for service invocation. Even if intended benignly, this is misleading because network requests, logs, identifiers, and external pages can still expose metadata or user-supplied tax information.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file’s behavior is unrelated to the declared offshore trust tax-assistant purpose and instead performs generic MCP client detection and onboarding. That mismatch is dangerous because it can conceal persistence-like environment reconnaissance and unauthorized service registration under a benign tax-compliance pretext, increasing the likelihood of deceptive installation into user tooling.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The code enumerates local environment indicators and can write or merge into user configuration files for Claude Desktop, Cursor, and VS Code/Cline. In the context of a tax advisory skill, this exceeds functional necessity and creates a foothold for unauthorized persistence, lateral redirection of MCP traffic, or silent enrollment of the host into a remote service.

Intent-Code Divergence

Medium
Confidence
83% confidence
Finding
The documentation states the module is not responsible for networking, yet it hardcodes a remote HTTP MCP endpoint and selects it for cloud-capable clients. Even if the module itself does not open the socket immediately, it is still configuring remote connectivity, which is a misleading trust boundary that can cause users or reviewers to underestimate data-flow and exfiltration risk.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The configured service URL and skill slug point to 'tax-policy-knowledge', which does not match the declared offshore trust tax skill. That discrepancy strongly suggests bait-and-switch behavior: users expecting one specialized function may instead be connected to a different remote service, undermining informed consent and enabling covert data redirection.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The client silently sends user questions to third-party search engines (Bing/Baidu) when the primary service is unavailable. In a tax-compliance assistant, prompts may contain highly sensitive financial, residency, and trust-structure details, so this fallback can leak confidential data to unrelated external services without explicit consent.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The code exposes a generic remote tax-policy MCP endpoint and forwards tool calls to it, while the skill metadata presents a much narrower offshore-trust/personal-income-tax assistant. This creates a scope mismatch: users and host agents may trust the skill as narrowly scoped, but their prompts and tax data are actually sent to a broader external service with capabilities beyond the declared domain.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is ներկայացված as a tax/offshore trust compliance assistant, but the code implements a multi-skill installer that can fetch and install additional packages. This is a clear scope mismatch that hides software installation behavior behind an unrelated business purpose, increasing supply-chain and user-consent risk.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
This code detects the host environment/channel and conditionally downloads remote ZIP packages for installation, which is unrelated to the stated tax advisory function. Even with basic ZIP path checks, remote package retrieval and installation creates a supply-chain execution path that could be abused to deliver unauthorized or unexpected functionality.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The installer defaults to writing under the user's ~/.skills directory and can replace existing skill directories during reinstall. Unrelated local filesystem modification under a user profile is dangerous in the context of a tax assistant because it enables persistence and broad modification of the user's skill environment.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The documentation states that once any finance/tax skill is installed, this installer can automatically pull in the rest of a matrix of related skills. That materially expands capability beyond the current skill's declared scope and can surprise users with additional software installation, making the hidden behavior more dangerous in context.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The file implements a generic keyword-based matrix router instead of the offshore-trust personal income tax compliance functionality declared in the skill metadata. This is dangerous because capability mismatches in security- or compliance-sensitive agents can silently route users to unrelated skills, causing incorrect tax guidance, missed reporting obligations, or disclosure of sensitive financial context to unintended components.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The UI tells users their data is 'saved locally, not uploaded', but the workflow later sends collected metrics to a remote API after consent. This is a deceptive data-handling mismatch that can invalidate informed consent and cause users to disclose sensitive tax-compliance information under false assumptions.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The footer claims computation is performed locally by default, but the implemented self-check calls a cloud endpoint for rule evaluation. In a tax/offshore-trust compliance tool, this misrepresentation is especially sensitive because even 'non-identity' metrics can reveal legal exposure, structure complexity, or compliance gaps.

Context-Inappropriate Capability

High
Confidence
93% confidence
Finding
The file contains unrelated functions for R&D timesheets, project generation, ESOP checklists, and ledger export that do not belong in an offshore trust tax skill. Extraneous hidden capability increases attack surface, raises the risk of code reuse bugs and unauthorized data handling, and suggests poor separation of concerns in a page already processing sensitive compliance data.

Vague Triggers

Medium
Confidence
81% confidence
Finding
Broad trigger phrases for installation actions create an unsafe activation surface: ordinary conversational text could cause the skill to suggest or initiate installation-related workflows beyond the user's immediate intent. In a skill ecosystem that may download, install, or reconfigure components, ambiguous install triggers materially increase the risk of unwanted changes.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The instruction to proactively surface a clickable external link whenever the user expresses loosely related intent is overly broad and can drive users off-platform without clear necessity. This increases phishing-like risk, weakens consent, and may expose sensitive tax details to an external site based on vague conversational cues.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The client logs raw user questions and scenarios to local JSONL files, which may include sensitive tax, identity, offshore asset, and compliance information. Because logging is automatic and undisclosed, any local user, backup system, or malware with filesystem access could recover confidential data long after the session ends.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The API key is persisted in a plaintext local config file under the user's home directory without user-facing disclosure or apparent permission hardening. If the host is shared, backed up, or compromised, the credential can be reused to impersonate the client and access the remote service within its quota and authorization scope.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The server forwards potentially sensitive tax and cross-border wealth information to a remote cloud service without any in-code disclosure, consent flow, or warning. In this skill context, inputs may contain highly confidential personal and financial data, so silent transmission materially increases privacy, compliance, and data-governance risk.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The page automatically registers with a remote service and stores/sends a persistent client/device identifier before any user-facing warning at the point of collection. That creates undisclosed tracking and linkage risk, especially problematic in a cross-border tax context where repeated sessions may be correlated to sensitive compliance activity.

External Transmission

Medium
Category
Data Exfiltration
Content
],
      "version": "3.15.3",
      "download_urls": {
        "skillhub": "https://api.skillhub.cn/api/v1/download?slug=tax-contract-generation-review",
        "clawhub": "https://clawhub.ai/api/v1/download?slug=tax-contract-generation-review"
      },
      "board": "Shared",
Confidence
78% confidence
Finding
https://api.skillhub.cn/

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.