Back to skill

Security audit

Book Haircut

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: it helps find and book haircut appointments through Lokuli, with no hidden code or unrelated access found.

Install only if you are comfortable using Lokuli as the external booking provider. Before a booking is created, confirm the provider, time, service, and that your name, email, phone number, and location details may be sent to Lokuli.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger scope is broad enough to activate on general haircut-related requests, not just clear booking intent. That can route users into an external booking workflow prematurely, causing unintended disclosure of location or contact details and increasing the chance of unauthorized third-party interactions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports transmitting personal data such as customer name, email, phone number, and likely location information to an external MCP service, but does not warn the user or require explicit consent for that sharing. This creates a privacy and compliance risk because sensitive personal data may be sent off-platform without clear disclosure or informed user approval.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.