Back to skill

Security audit

Book Gutter Cleaning

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it can send contact details to an outside booking service and create a real booking without clearly requiring final user consent.

Review this before installing if you are comfortable using Lokuli as a third-party booking service. Before any booking is submitted, confirm the provider, service, appointment time, any price or terms shown, and the exact name, email, and phone number that will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger language is broad enough to activate on generic gutter-cleaning requests without clearly constraining when the skill should engage. That can cause the agent to invoke an external booking workflow in situations where the user only wanted information, increasing the chance of unintended data collection or third-party service interaction.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill includes a booking flow that transmits personal contact data such as name, email, and phone number to an external MCP endpoint, but it does not instruct the agent to warn the user or obtain clear consent first. This creates privacy and compliance risk because users may not realize their personal information will be shared with a third party for booking.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.