Book Computer Repair

Security checks across malware telemetry and agentic risk

Overview

This skill has a legitimate booking purpose, but it can create a real third-party repair appointment and send contact details without documented confirmation or consent safeguards.

Review before installing. Use only if you are comfortable with Lokuli receiving search and booking details, and require the agent to confirm the provider, service, time, price or fees if available, cancellation terms, and exact contact information before creating any booking.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger wording is broad enough to activate on generic computer-repair or nearby-service requests without making clear that the skill will connect to an external booking provider. Overbroad invocation can cause the agent to select this skill in situations where the user only wanted information, increasing the chance of unintended external queries or downstream booking actions.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill describes collecting and sending customer name, email, and phone number to Lokuli's external MCP endpoint but provides no user-facing warning or consent guidance. In a booking context, this creates a meaningful privacy and compliance risk because sensitive contact data may be transmitted off-platform without the user clearly understanding where it is going.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal