Tour Booking

Security checks across malware telemetry and agentic risk

Overview

This skill openly prepares and optionally places listing-office booking calls, with live calling disclosed and gated by an explicit flag.

Install only if you intend to prepare or place property-showing calls. Run dry-run first, inspect the destination phone number and prompt contents, use a scoped ElevenLabs API key, and avoid storing generated result files in shared locations unless the call details are safe to expose.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill invokes local scripts that read and write files under /tmp and can make live outbound network requests to ElevenLabs, yet the skill metadata declares no permissions. This creates a capability/permission mismatch that can bypass operator expectations and policy enforcement, increasing the chance the skill is run with more access than reviewers realize.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script writes the full request payload and API response to disk, which can include phone numbers, prompts, metadata, and provider response details. If the output path is in a shared workspace, retained in logs/artifacts, or read by other processes, sensitive call data may be exposed beyond the intended operator.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal