Back to skill

Security audit

Book Auto Body

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple auto-body booking helper that uses a disclosed Lokuli booking endpoint, with expected but sensitive contact-data sharing.

Install only if you are comfortable using Lokuli for booking. Before any final booking, have the agent show the provider, service, appointment time, and contact details, then explicitly approve sending that information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger description is broad enough to activate on generic auto-body related requests without clearly constraining user intent to booking through this external service. That can cause the agent to invoke the skill unexpectedly, leading to unintended data flow, unnecessary external calls, or accidental booking-oriented actions when the user only wanted information.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill documents collection and transmission of customerName, customerEmail, and customerPhone to an external MCP endpoint, but it does not warn the user that personal contact data will leave the local agent context. This creates a privacy and consent risk because users may not realize their PII is being sent to a third-party booking service.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.