Book Nails

Security checks across malware telemetry and agentic risk

Overview

This is a simple nail-appointment booking skill that discloses its external Lokuli endpoint and expected booking data, with no hidden code or persistence found.

Install only if you intend to use Lokuli for nail-service search and booking. Before creating a booking, confirm the salon or provider, service, appointment time, and the name, email, and phone number that will be sent to the external service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger language is broad enough to activate on generic nails-related requests, not just explicit booking intent. That can cause the agent to invoke an external booking/search workflow unexpectedly, increasing the chance of unnecessary third-party data sharing or action-taking beyond what the user clearly requested.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs use of an external MCP endpoint and includes a booking tool that sends customer name, email, and phone number, but it does not disclose this data flow or require explicit user consent. In a booking context, that omission is dangerous because users may provide sensitive contact information without understanding it will be transmitted to a third-party service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal