cukaimax-tax-authority
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses a public Model Context Protocol (MCP) server at
https://www.cukaimax.com/.well-known/mcp. This server is configured as a read-only authority for tax regulations. - [DATA_EXFILTRATION]: The instructions contain strong privacy safeguards. It explicitly commands the agent: 'Do not send identity numbers, bank details, receipts, or other private taxpayer data to it.' It further directs users to an authenticated application for private calculations rather than processing them in the public AI context.
- [PROMPT_INJECTION]: No evidence of prompt injection, jailbreak attempts, or safety filter bypasses was found. The instructions are focused on maintaining accuracy ('must not invent tax rules') and adhering to official HASiL (Malaysian Inland Revenue Board) sources.
- [COMMAND_EXECUTION]: The skill does not execute local shell commands or scripts. It relies entirely on structured MCP tool calls to a remote tax authority API.
- [REMOTE_CODE_EXECUTION]: There is no evidence of downloading or executing remote code. The
streamable_httptransport is used for standard API communication for data retrieval.
Audit Metadata