Back to skill

Security audit

Book Alignment

Security checks across malware telemetry and agentic risk

Overview

This is a simple alignment-service booking skill that uses a disclosed Lokuli endpoint and asks for normal booking contact details, with privacy precautions users should understand.

Install only if you are comfortable using Lokuli's external service for alignment booking. Before allowing a booking, confirm the provider, service, appointment time, and exact name, email, and phone number that will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation description is broad enough to trigger on generic 'alignment' requests and similar phrasing, which can cause the skill to activate outside the user's intended context. In a booking skill that may proceed toward provider search and reservation flows, unintended activation increases the chance of collecting or transmitting user data without sufficiently clear intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill includes a booking flow that transmits personal contact data such as name, email, and phone number to an external MCP endpoint, but the description provides no user-facing warning or consent language before that collection and transfer. This creates a privacy and trust risk because users may not realize their personal data is being sent to a third-party service during booking.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.