Book Dog Walker

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only dog-walker booking skill whose external service use and contact fields match its stated purpose, though users should confirm before sharing personal details or booking.

Install only if you are comfortable using Lokuli for dog-walker searches and bookings. Before creating a booking, review the provider, date, time, price or cancellation terms if available, and confirm before sending contact details to the service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger description is broad enough that the skill may activate on generic dog-walking queries without clearly establishing that the user wants a third-party booking workflow. This can cause the agent to invoke an external MCP service unnecessarily, increasing the chance of unintended data sharing or transactional actions based on ambiguous user intent.

Missing User Warnings

High
Confidence
94% confidence
Finding
The skill demonstrates collecting and transmitting customer name, email, and phone number to an external endpoint without any visible notice, consent language, or data-minimization guidance. In a booking context this is especially sensitive because users may not realize their personal contact details are being sent to a third-party service, creating privacy, compliance, and trust risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal