Back to skill

Security audit

Book Carpet Cleaning

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward carpet-cleaning booking helper that shares expected booking contact details with a disclosed third-party service.

Before installing, be comfortable with the agent contacting Lokuli and sharing booking details such as your name, email, phone number, location or ZIP code, selected provider, service, and time slot. Confirm the provider and appointment details before allowing any booking to be created.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger text is broad enough to activate on general carpet-cleaning requests without clearly constraining when booking actions should occur. In a skill that can search availability and create bookings with an external provider, over-broad triggering increases the chance the agent invokes this skill in unintended contexts and progresses toward transmitting user data or initiating bookings without sufficiently specific user intent.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill documents a create_booking action that sends customer name, email, and phone number to an external MCP endpoint, but it does not warn users that their personal contact information will be shared with a third-party service. This reduces informed consent and can lead to privacy and compliance issues if the agent collects and transmits PII without making the disclosure clear.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.