Book Appliance Repair

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward appliance-repair booking helper, but users should confirm before sending contact details to Lokuli.

Install only if you are comfortable using Lokuli for appliance-repair booking. Before creating a booking, confirm the provider, service, date, time, price or cancellation terms if available, and the exact name, email, and phone number that will be shared.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger text is broad enough to activate on generic appliance-repair requests rather than a tightly scoped invocation, which can cause the agent to route users into an external booking workflow without clear intent. In this skill, that risk is amplified because activation can lead to downstream collection and transmission of booking-related personal data to a third-party MCP service.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill facilitates booking by sending customer name, email, and phone number to an external Lokuli MCP endpoint, but it does not disclose that this third-party transfer will occur. That omission undermines informed consent and can expose users to privacy and compliance risks if they provide personal contact information without understanding where it is being sent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal