Book Pedicure

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says: help search and book pedicure appointments through Lokuli, with personal contact details used for the booking flow.

Install only if you are comfortable using Lokuli for pedicure appointment search and booking. Before any booking is finalized, confirm the provider, time, cancellation terms, and that your name, email, and phone number will be sent to Lokuli.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger text is broad enough that the skill may activate on generic pedicure-related requests without making clear that it will use an external booking MCP. That can cause unintended routing of user requests into a transactional flow and increase the chance that personal data or booking actions are initiated without sufficiently explicit user intent.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill defines a booking flow that collects and transmits customer name, email, and phone number to an external MCP endpoint, but the description does not warn users about this data transfer. This creates a privacy and consent risk because users may not realize their personal contact information is being sent to a third-party service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal