Back to skill

Security audit

Book Beauty

Security checks across malware telemetry and agentic risk

Overview

This is a coherent beauty-booking skill that uses Lokuli for searches and bookings, with no hidden code, but booking will involve sharing contact details with that external service.

Install only if you are comfortable using Lokuli as the external service for beauty searches and appointment booking. Before approving a booking, verify the provider, service, time, price, and contact details that will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger language is overly broad because it includes "any beauty service request," which can cause the skill to activate for loosely related user messages rather than clear booking intent. In a transactional skill that searches providers and can proceed toward booking, unintended invocation increases the risk of confusing routing, unnecessary collection of user location/contact details, and accidental progression into external tool use.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.