Book Bartender

Security checks across malware telemetry and agentic risk

Overview

This is a simple bartender-booking skill that uses a disclosed Lokuli endpoint and does not include local code, persistence, or hidden behavior.

Install only if you are comfortable using Lokuli as the booking service. Before any booking is created, make sure the agent shows the selected provider, service, date/time, and contact details, and only share personal information you are willing to send to that third-party endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest description includes broad trigger language such as "any bartender service request," which can cause the skill to activate on vague or ambiguous user requests. That increases the chance of the agent invoking an external booking workflow without sufficiently clear user intent, potentially leading to unintended data sharing or transactional actions.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs booking through an external MCP endpoint and the create_booking example includes customer name, email, and phone number, but the description does not warn that this personal data will be transmitted to a third-party service. Users may unknowingly disclose sensitive contact information to an external provider, creating privacy, consent, and compliance risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal