Back to skill

Security audit

Book Language Tutor

Security checks across malware telemetry and agentic risk

Overview

This skill is for legitimate tutor booking, but it can share contact details and create a real booking without clear consent or final confirmation safeguards.

Install only if you are comfortable using Lokuli for tutor booking. Before allowing a booking, ask the agent to show the provider, service, date, time, contact details to be shared, price if available, and cancellation terms, then confirm explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger guidance is broad enough to activate on nearly any request related to finding or booking a language tutor, which can cause the skill to run when the user did not intend to use this external booking workflow. Because the skill connects to a third-party MCP endpoint and may later collect booking details, unintended invocation increases the chance of unnecessary data sharing or unwanted transactional actions.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill includes a booking flow that transmits personal data such as customer name, email, and phone number to an external endpoint, but it provides no user-facing warning or consent step before collection and transfer. In a booking context, this makes the issue more dangerous because the agent is encouraged to gather real PII for a live transaction, creating privacy, compliance, and trust risks if the user is not clearly informed.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.