Back to skill

Security audit

Book Oil Change

Security checks across malware telemetry and agentic risk

Overview

This skill is a small, purpose-aligned oil-change booking integration that uses a disclosed external Lokuli MCP endpoint and shows no hidden code, persistence, or unrelated access.

Install only if you are comfortable using Lokuli as the external booking service. Confirm the provider, service, date, time, and contact details before creating a booking, and avoid using it for general oil-change advice that does not require contacting a booking service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is broad enough to activate on generic oil-change-related requests, not just clear booking intents. This can cause the agent to invoke an external booking workflow prematurely, increasing the chance of unintended third-party interaction or collection of user data without sufficiently specific user consent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill sends personal contact information to an external MCP booking service, but the skill description does not explicitly warn users that their name, email, and phone number will be shared with a third party. This creates a privacy and consent risk because users may provide sensitive personal data without understanding where it will be transmitted.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.