Book Venue

Security checks across malware telemetry and agentic risk

Overview

This venue-booking skill is mostly coherent, but it can create real bookings and send personal contact details to Lokuli without clear confirmation safeguards.

Review before installing. Use it only when you intend to book through Lokuli, and tell your agent to confirm the venue, time, contact details, price, cancellation terms, and personal data sharing before calling create_booking.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger guidance is broad enough to activate on generic venue-related requests, which can cause the skill to run when the user did not clearly intend to use this third-party booking flow. In a skill that can search availability and initiate bookings, over-triggering increases the chance of unnecessary external data transmission and unintended transactional actions.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill includes a create_booking flow that sends customerName, customerEmail, and customerPhone to an external MCP endpoint without any stated warning, consent language, or data-handling notice. This creates privacy and compliance risk because users may not realize their personal contact data will be transmitted to a third-party service as part of the booking operation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal