Book Painter
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The skill bundle defines a 'book-painter' service that interacts with an external Lokuli MCP endpoint (https://lokuli.com/mcp/sse) using JSON-RPC 2.0. It provides tools for searching, checking availability, and creating bookings. While the `create_booking` tool handles customer PII (name, email, phone), this is directly aligned with the stated purpose of booking a service and is expected to be provided by the user. There is no evidence of malicious intent, data exfiltration beyond the skill's stated function, unauthorized command execution, or prompt injection attempts against the agent in `SKILL.md`.
