Book Data Recovery

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple data-recovery booking connector that discloses its external Lokuli MCP endpoint and uses contact details in a way that matches booking a service.

Install this only if you are comfortable using Lokuli as the external booking service. Before any booking is created, confirm the provider, service, time slot, name, email, and phone number, and avoid sharing contact details unless you intend them to be sent for the booking.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger description is broad enough to activate on generic service-booking or local-service requests, which can cause the agent to invoke this skill in contexts the user did not intend. In this skill, mistaken activation is more dangerous because it can lead to external MCP interactions and eventual transmission of booking-related personal data to a third-party service.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill instructs booking through an external MCP endpoint and the booking example includes customer name, email, and phone number, but the description does not warn that this personal data will be sent to a third-party service. This creates a meaningful privacy and consent risk because users may not realize their contact details are being disclosed externally during booking.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal