Book Tailor

Security checks across malware telemetry and agentic risk

Overview

This skill transparently helps search for and book tailor services through Lokuli, but users should confirm before sharing contact details.

Install only if you trust Lokuli for tailor booking. Before using create_booking, confirm the provider, service, appointment time, price or cancellation terms if available, and the exact name, email, and phone number that will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is broad enough to activate on generic tailor-related requests without clearly constraining user intent or requiring confirmation before contacting an external service. In a booking skill, unintended invocation can lead to premature search or booking flows and unnecessary disclosure of location or contact details to a third-party MCP endpoint.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill includes a create_booking example that transmits customerName, customerEmail, and customerPhone to an external endpoint but provides no user-facing warning, consent requirement, or data-handling notice. Because this skill is specifically designed to book real-world services through a third party, the absence of disclosure materially increases the risk of unintended sharing of personally identifiable information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal