Back to skill

Security audit

Book Facial

Security checks across malware telemetry and agentic risk

Overview

This skill appears aligned with booking facial appointments, but it can send contact details to an external service and create real bookings without clear confirmation safeguards.

Review before installing if you are comfortable using Lokuli as the external booking service. Before any booking is created, confirm the provider, service, appointment time, price or cancellation terms if available, and exactly which contact details will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger scope is overly broad because it claims to activate on "any facial service request," which can cause the skill to engage in situations where the user did not clearly ask to book through this provider. In a booking skill, overbroad triggering increases the risk of unintended tool use, unnecessary collection of user location/contact details, and accidental third-party booking workflows.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill transmits personal data including customer name, email, and phone number to an external MCP endpoint for booking, but the skill text provides no user-facing notice that this information will be shared with a third party. In a booking context, that omission can undermine informed consent and lead to privacy violations or unintended disclosure of sensitive contact information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.