Back to skill

Security audit

Book Pressure Washing

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward pressure-washing booking skill, but users should confirm before sharing contact details or creating an appointment.

Before using this skill, make sure the agent shows the provider, service, date and time, cost or terms if available, and the exact contact details it will send to Lokuli. Only approve create_booking when you intend to book and are comfortable sharing that information with Lokuli and the selected provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger language is broad enough to activate on generic pressure-washing requests without clearly constraining when booking actions should occur. In a skill that can search availability and create bookings through an external MCP endpoint, overbroad activation increases the chance of unintended invocation, unnecessary data flow, or premature progression toward a transaction the user did not explicitly request.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill handles booking and explicitly includes personal data fields such as customer name, email, and phone number, but it does not warn the user that this information will be collected and sent to Lokuli's external MCP server. This creates a privacy and consent risk because users may not realize their contact details are being transmitted to a third party as part of the booking flow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.