Back to skill

Security audit

Book Appliance Repair

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward appliance-repair booking skill that uses a disclosed Lokuli MCP endpoint, though users should confirm before sharing contact details.

Install only if you are comfortable using Lokuli to search and book appliance-repair services. Before creating a booking, confirm the provider, service, date, time, and the exact name, email, and phone number that will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger language is broad enough to activate on generic appliance-repair or nearby-service requests without clearly requiring explicit booking intent. That can cause the skill to engage when the user only wants information, increasing the risk of unintended tool use and premature collection or transmission of service-related data.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill includes a booking flow that sends customer name, email, and phone number to an external MCP endpoint, but it does not disclose that this third-party transfer will occur or require explicit user consent before transmission. In the skill context, this is especially sensitive because the workflow is designed to collect and forward personal contact data to a remote service, creating privacy, compliance, and trust risks if done unexpectedly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.