Back to skill

Security audit

Book Physical Therapy

Security checks across malware telemetry and agentic risk

Overview

This is a narrowly scoped physical-therapy booking skill that sends expected booking details to a disclosed Lokuli endpoint, with privacy and confirmation cautions but no evidence of hidden or malicious behavior.

Install only if you are comfortable using Lokuli for physical-therapy provider search and appointment booking. Before any booking is submitted, confirm the provider, service, time slot, and exact contact details being sent, and avoid sharing unnecessary medical details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger language is broad enough to activate on generic requests like finding or booking physical therapy without clearly constraining when the skill should be invoked. Over-broad routing can cause the assistant to select this skill in situations where the user did not intend external booking behavior, increasing the chance of unintended third-party data sharing or transaction initiation.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill describes collecting and transmitting customer name, email, and phone number to an external MCP endpoint but does not warn the user that their personal contact information will leave the assistant and be sent to Lokuli. In a healthcare-adjacent booking context, undisclosed transmission of personal data is especially sensitive and can undermine user consent, privacy expectations, and compliance obligations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.