Book Facial

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it claims, but it can send contact details to an external booking service and create real appointments without clear confirmation safeguards.

Install only if you are comfortable using Lokuli as an external booking service. Before creating any booking, confirm the provider, service, time, price if available, cancellation terms, and exactly what contact details will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger text is broad enough to activate on generic facial-service requests without clearly constraining scope to explicit booking intent. That can cause the agent to invoke an external booking workflow in situations where the user only wanted information, increasing the chance of unintended third-party data sharing or transactional actions.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill documents booking through an external MCP endpoint and includes fields for customer name, email, and phone number, but provides no warning that this personal data will be transmitted off-platform. In a booking context, this omission is especially risky because users may disclose sensitive contact information without informed consent, creating privacy, compliance, and trust issues.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal