Book Battery

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says: help search and book battery services through Lokuli, with ordinary booking-related privacy considerations.

Install this if you intend to use Lokuli for battery-service search and booking. Before creating a booking, confirm the details and only provide contact information you are comfortable sharing with Lokuli and any provider needed to fulfill the appointment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger language is broad enough to activate on generic battery-related requests without clearly constraining scope or requiring explicit user intent to use Lokuli. That can cause unintended invocation of the skill and unnecessary transmission of user queries or booking-related data to an external service, especially in ambiguous contexts like informational or shopping requests.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill facilitates sending personally identifiable information, including name, email, and phone number, to an external booking service, but the description does not warn the user about that data transfer. This creates a meaningful privacy and consent risk because users may provide contact details without understanding they will be transmitted off-platform to Lokuli or downstream providers.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal