Book Test Prep

Security checks across malware telemetry and agentic risk

Overview

This is a simple booking skill that clearly uses an external Lokuli service, though users should confirm before sharing contact details.

Install only if you trust Lokuli for test-prep booking. Before creating a booking, confirm the provider, service, time slot, and that you want your name, email, and phone number sent to the external service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is broad enough to activate on generic test-prep requests, which can cause the skill to run when a user may only be asking for information rather than intending to book through a third-party service. In that case, the agent could prematurely initiate search or booking workflows and route user data to an external MCP endpoint without sufficiently clear user intent.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill includes a booking flow that collects and transmits personal information such as name, email, and phone number to an external service, but it does not instruct the agent to warn the user or obtain explicit consent before doing so. This creates a privacy and data-handling risk because users may not realize their contact data is being shared with Lokuli's MCP server.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal