Book Moving

Security checks across malware telemetry and agentic risk

Overview

This is a simple moving-service booking skill that uses Lokuli’s external MCP endpoint, with privacy and confirmation caveats but no evidence of hidden or malicious behavior.

Install this only if you want an agent to use Lokuli to search for and book movers. Before any booking is submitted, confirm the provider, time, price, cancellation terms, and that you are comfortable sending your name, email, phone number, and booking details to Lokuli and its connected providers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is broad enough to activate on generic "moving" requests, which can cause the skill to engage when the user did not clearly intend to book a moving service. In an agent setting, unintended invocation can lead to premature querying of an external provider and unnecessary collection or transmission of user location or booking-related data.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill includes a booking flow that collects and sends personal data such as name, email, and phone number to an external MCP endpoint, but it does not warn the user or require explicit consent before transmission. This creates a meaningful privacy and compliance risk because sensitive contact details may be shared with a third party without clear user awareness or approval.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal