Book Salon

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward salon-booking skill, with privacy considerations because bookings use an external Lokuli endpoint and may send contact details.

Install only if you are comfortable using Lokuli for salon booking. Before creating an appointment, confirm the salon, service, time, and the exact name, email, and phone number your agent will send.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description is broad enough to activate on generic salon-related requests, which can cause the skill to engage without clear user intent to search or book through this external service. In context, that increases the chance of unnecessary routing to a third-party MCP endpoint and premature collection or transmission of booking-related data.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill documents collection of customer name, email, and phone number for create_booking but does not warn that this information is sent to an external MCP endpoint at lokuli.com. This is dangerous because users may provide sensitive personal contact data without informed consent, creating privacy, compliance, and data-handling risks if the endpoint is unexpected, untrusted, or misused.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal