Book Handyman

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: it helps search and book handyman services through Lokuli, with expected contact details used for booking.

Install this only if you intend to use Lokuli for handyman search or booking. Before creating a booking, confirm the provider, service, appointment time, and the exact contact details that will be sent to Lokuli.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger text is broad enough to activate on essentially any handyman-related request, without requiring explicit user intent to search or book through this external service. That increases the chance the agent routes ordinary informational queries into a transactional flow, potentially leading to unintended third-party data sharing or booking actions.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill facilitates sending personally identifiable information such as name, email, and phone number to an external MCP endpoint, but the description does not warn users about this transmission. In a booking context, this omission is dangerous because users may not realize their contact data is being disclosed to a third-party service, undermining informed consent and increasing privacy/compliance risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal