Book Personal Trainer

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says: help book a personal trainer through Lokuli, with the main caution being that booking sends contact details to an external service.

Install only if you are comfortable using Lokuli for personal-trainer searches and bookings. Before creating a booking, confirm the trainer, service, date, time, and the exact name, email, and phone number that will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger language is broad enough to activate on generic service-booking requests, which can cause the assistant to route users into this skill when they may not have intended to use Lokuli or book a personal trainer. This increases the chance of inappropriate tool use and unintended external data disclosure or booking flow initiation.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill instructs use of an external MCP endpoint and later shows transmission of customer name, email, and phone number, but it does not disclose that this personal data will be sent to a third-party service. Users may unknowingly expose sensitive contact information to an external system without informed consent or privacy notice.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The create_booking example depicts a real reservation action using personal details but includes no requirement for explicit confirmation before execution. In practice, this could lead to accidental or unauthorized bookings, potentially causing charges, scheduling conflicts, or disclosure of user contact data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal