Back to skill

Security audit

Book Dog Walker

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward dog-walker booking helper that uses a disclosed Lokuli endpoint, though booking will involve sharing contact details with that service.

Install only if you are comfortable using Lokuli for dog-walker searches and bookings. Before creating a booking, confirm the provider, date, time, and any terms, and understand that your contact details may be sent to Lokuli and the selected provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger description is broad enough that the skill may be invoked for general pet-service or location-based requests without clear user intent to use this specific booking workflow. In a transactional skill that can search providers and ultimately create bookings, unintended invocation increases the chance of unnecessary data collection or premature progression toward an external booking action.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill includes a create_booking flow that transmits personal contact data including name, email, and phone number to an external MCP endpoint, but the description does not warn the user before collecting or sending that information. In this context, the omission is meaningful because the skill facilitates a real-world transaction with third-party data sharing, which can surprise users and create privacy and consent issues.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.