Back to skill

Security audit

Book Fence

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward fence-service booking skill that uses an external Lokuli MCP endpoint and collects contact details only for the expected booking flow.

Install only if you are comfortable using Lokuli for fence-service search and booking. Before creating a booking, confirm the provider, service, time slot, and that your name, email, and phone number will be sent to the external booking service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger text is broad enough that the skill may activate on generic requests like finding fences or related service queries without clear user intent to use this specific third-party booking workflow. Unintended activation increases the chance of unnecessary data flow to an external MCP endpoint and could cause users to enter booking details in the wrong context.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The booking example collects and transmits personal data including customer name, email, and phone number to a third-party MCP service, but the skill does not warn the user that this information will be sent externally. This creates privacy and consent risk because users may disclose contact data without understanding where it is going or for what purpose.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.