Book Cleaning

Security checks across malware telemetry and agentic risk

Overview

This skill appears legitimate for booking cleaners, but it can send contact details to a third-party service and create a real booking without clear confirmation guidance.

Install only if you are comfortable using Lokuli as a third-party booking service. Before creating any booking, make sure your agent confirms the provider, service, date, time, price, cancellation terms, and exactly which contact details will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger description is broad enough to match generic cleaning-service requests, which can cause the skill to activate in contexts the user did not specifically intend for this provider or workflow. In a booking skill tied to an external MCP endpoint, overbroad activation increases the chance of routing users into third-party search/booking flows and collecting data without sufficiently explicit user intent.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill includes a booking flow that transmits personal contact details such as name, email, and phone number to an external booking service, but the description does not indicate any user-facing warning or explicit consent step. This creates a meaningful privacy and trust risk because users may not realize their personal data is being shared with a third party when the skill is invoked.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal