Book DJ

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward DJ booking skill that discloses its external service and expected booking data, but users should confirm before sending contact details or creating a booking.

Install this only if you intend to use Lokuli for DJ booking. Before creating a booking, confirm the DJ, date, time, price or cancellation terms, and the exact name, email, and phone number that will be sent to the external service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description includes a broad trigger phrase such as 'any dj service request,' which can cause the skill to activate for loosely related user queries. Overbroad invocation increases the chance the agent routes users into a booking workflow unexpectedly, exposing them to external service calls and possible collection of booking-related personal data without sufficiently specific user intent.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill documents transmission of customerName, customerEmail, and customerPhone to an external MCP endpoint during booking, but provides no user warning, consent step, or data-handling notice. This is dangerous because users may not realize their personal contact information is being sent to a third-party service, creating privacy, compliance, and trust risks if data is collected or shared without explicit informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal