Book Tires

Security checks across malware telemetry and agentic risk

Overview

This is a simple tire-service booking skill whose external calls and contact-information use match its stated purpose, though users should confirm before sending personal details.

Install only if you are comfortable using Lokuli for tire-service search and booking. Before creating a booking, confirm the provider, service, time slot, and that your name, email, and phone number will be sent to the external booking service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger text is broad enough to activate on generic tire-related requests without clearly constraining when the skill should be used, which can cause unintended invocation of an external booking workflow. In this context, accidental activation is more dangerous because the skill connects to a third-party MCP endpoint and can lead users into searches or bookings they did not explicitly intend.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill documents collection and transmission of customer name, email, and phone number to an external MCP endpoint but provides no user-facing warning, consent language, or data-handling notice. This is dangerous because users may unknowingly share sensitive contact information with a third party during booking, creating privacy, compliance, and trust risks.

VirusTotal

48/48 vendors flagged this skill as clean.

View on VirusTotal