Back to skill

Security audit

专精特新小巨人涉税合规指引

Security checks across malware telemetry and agentic risk

Overview

The skill is a real tax-compliance assistant, but it also has under-disclosed remote data transmission, local credential/log persistence, MCP client configuration, and bulk skill-installation behavior that users should review before installing.

Install only if you are comfortable with tax questions and risk scenarios being processed by the mcp.aitaxs.top service, with API credentials and logs stored locally, and with optional matrix installation modifying ~/.skills. Avoid pasting confidential financial, listing-preparation, or client-identifying data unless you have reviewed the service trust and retention terms. Do not enable TAX_ENABLE_AUTOSETUP or run config/init_agent.py directly unless you intend to modify your MCP client settings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (59)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill advertises no declared permissions, yet the detected capabilities include environment access, file read/write, and network access. That combination can enable silent local configuration changes, data exposure, and outbound communication without informed user consent, which is especially risky for a skill presented as a narrow tax-compliance assistant.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This is a strong description-behavior mismatch: the skill claims to provide specialized tax guidance, but the detected behavior includes host fingerprinting, modifying local MCP configuration files, proxying traffic to remote cloud services, local logging/caching, web-search fallback, and installing additional skills. Such hidden general-purpose installer and routing behavior can be abused for persistence, covert exfiltration, unauthorized tool expansion, and user deception.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This code performs host-agent detection and attempts to auto-write MCP client configuration files, which is unrelated to the declared tax compliance assistant purpose. A skill that modifies local client integration settings can silently alter trust boundaries, persist access, or redirect future tool traffic, making it materially dangerous even if presented as convenience automation.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The module fingerprints the host environment by inspecting environment variables, home-directory paths, editor folders, and stdin behavior to infer which agent is running it. In a tax advisory skill, this is unnecessary contextual reconnaissance that expands the privacy and attack surface and can be used to tailor persistence or configuration tampering to the detected host.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
These functions modify local configuration files for multiple AI clients, including backup, merge, and write operations into user-controlled settings paths. For a tax compliance assistant, such behavior is out of scope and enables unauthorized persistence, traffic redirection to remote MCP endpoints, and silent alteration of how the user's AI tooling behaves in future sessions.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The module hardcodes a remote service URL and identifiers that do not match the declared skill metadata, undermining transparency and creating risk of covert redirection to an unrelated backend. Combined with the auto-setup logic, this could cause users to unknowingly connect their MCP client to a different service than the one they intended to install.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The client defines a generic local web-search fallback using public search engines that is broader than the narrowly described tax-compliance skill purpose. This can cause user queries to be sent to third-party websites unexpectedly, expanding data exposure and behavior beyond the declared trust boundary.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The fallback logic directly fetches results from Bing and Baidu, which means user-entered tax questions may be transmitted to external search providers without clear disclosure. For a tax-compliance assistant, those queries can contain sensitive business, financial, or pre-IPO compliance details, making this a meaningful privacy and scope-expansion risk.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The code automatically registers with a remote auth service, obtains API credentials, and stores them locally without an explicit user action tied to credential creation. This introduces hidden outbound enrollment and local secret persistence that are not obviously necessary from the manifest, increasing privacy, compliance, and credential-handling risk.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file presents itself as a specialized tax-compliance skill, but the implementation is a generic proxy to a remote cloud MCP endpoint with broad tax tools. This creates a trust-boundary mismatch: users and host agents may believe they are invoking a narrowly scoped local workflow, while in reality sensitive prompts and tax data are forwarded off-box to a third-party service with different capabilities and handling assumptions.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The server imports and invokes agent detection and optional auto-setup logic unrelated to serving tax-policy queries. Even though writing is gated by an environment variable, the code performs capability discovery by default and may modify the local agent environment when enabled, which exceeds least-privilege for a simple stdio proxy and expands the attack surface to local configuration persistence.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file implements a bulk installer/downloader that can fetch and install additional skill packages into the user's ~/.skills directory, while the declared skill purpose is tax compliance assistance. This capability mismatch is security-relevant because it expands the skill's authority to modify the local skill environment and pull remote code/content, creating a supply-chain and unexpected-installation risk that a user would not reasonably infer from the skill description.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The page tells users identity fields are not uploaded and that processing is local, but it also generates a deep-analysis prompt that embeds the company name for copying into an external AI chat. That creates a data-disclosure path inconsistent with the privacy messaging, increasing the risk that users unknowingly exfiltrate sensitive business identity and compliance details to another service.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The page silently auto-registers a client and stores an API key and client identifier in localStorage, which is accessible to any script running in the origin. Persisting bearer credentials in localStorage broadens the attack surface and is more capability than users would reasonably expect from a simple self-check workflow, especially on a page handling tax-related data.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The client writes configuration and later logs/cache data into the user's home directory automatically, with no prior notice or consent flow. Silent persistence can expose sensitive operational metadata and surprises users in environments with strict workstation, privacy, or evidentiary controls.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The exported functions transmit user-provided tax questions and risk scenarios to remote services, and in fallback mode may also send them to public search engines, without any explicit disclosure at the interface boundary. Because this skill handles potentially sensitive tax, subsidy, related-party, and listing-preparation information, undisclosed data egress creates a significant confidentiality and compliance risk.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
All tool invocations are transmitted to a remote HTTPS service, but this file provides no user-facing notice that user inputs may leave the local environment. In a tax-compliance context, prompts may contain confidential financial, legal, or corporate-planning data, so undisclosed exfiltration to a third-party service materially increases privacy and compliance risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The code invokes setup logic that may write to disk without any warning in this file, relying on implicit environment-variable behavior rather than explicit consent. Hidden or poorly disclosed configuration changes are dangerous because they can alter agent behavior, persistence, or trust settings in ways users do not expect from a tax-analysis skill.

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-advisory-practice",
      "name": "财税中介机构AI合规咨询服务转型专题",
      "package": "tax-advisory-practice.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-advisory-practice",
      "is_core": false,
      "board": "B",
      "version": "3.15.3",
Confidence
86% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-capital-reduction",
      "name": "减资撤资(未实缴减资)个人所得税财税合规专题",
      "package": "tax-capital-reduction.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-capital-reduction",
      "is_core": false,
      "topics": [
        "减资",
Confidence
86% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-compliance-dispute",
      "name": "合规争议财税专题",
      "package": "tax-compliance-dispute.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-compliance-dispute",
      "is_core": false,
      "topics": [
        "财税内审",
Confidence
86% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"name": "建筑施工行业财税合规专题",
      "slug": "tax-construction",
      "package": "tax-construction.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-construction",
      "is_core": true,
      "topics": [
        "建筑施工",
Confidence
86% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
],
      "version": "3.15.3",
      "download_urls": {
        "skillhub": "https://api.skillhub.cn/api/v1/download?slug=tax-contract-generation-review",
        "clawhub": "https://clawhub.ai/api/v1/download?slug=tax-contract-generation-review"
      },
      "board": "Shared",
Confidence
88% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-crossborder",
      "name": "跨境电商与贸易财税合规专题",
      "package": "tax-crossborder.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-crossborder",
      "is_core": false,
      "topics": [
        "跨境电商",
Confidence
86% confidence
Finding
https://api.skillhub.cn/

External Transmission

Medium
Category
Data Exfiltration
Content
"slug": "tax-ecommerce",
      "name": "国内电商与直播财税合规专题",
      "package": "tax-ecommerce.zip",
      "download_url": "https://api.skillhub.cn/api/v1/download?slug=tax-ecommerce",
      "is_core": false,
      "topics": [
        "国内电商",
Confidence
86% confidence
Finding
https://api.skillhub.cn/

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.