Back to skill

Security audit

Book HVAC

Security checks across malware telemetry and agentic risk

Overview

This is a simple HVAC booking connector that discloses its Lokuli endpoint and booking fields, with privacy and confirmation caveats but no hidden or malicious behavior.

Install only if you are comfortable using Lokuli for HVAC provider search and booking. Before any real booking, confirm the provider, service, appointment time, and exact contact details, and avoid invoking it for general HVAC advice unless you intend to search for or schedule service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger language is broad enough to activate on generic HVAC-related requests, which can cause the agent to invoke this skill when the user may only be asking for advice, information, or non-booking help. This increases the chance of unintended external tool use and can steer conversations toward third-party actions without sufficiently clear user intent to book or search for providers.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs transmission of personal contact data (name, email, phone) to an external MCP service for booking, but it does not include a user-facing notice, consent step, or data-handling warning. This creates a privacy and compliance risk because sensitive personal information may be shared with a third party without explicit informed consent or clear minimization controls.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.