Back to skill

Security audit

Book Tires

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward tire-service booking helper that uses an external Lokuli endpoint and expected contact details for appointments.

Install only if you are comfortable using Lokuli for tire-service search and booking. Before creating a booking, confirm the provider, service, time slot, and that your name, email, and phone number will be sent to the external booking service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger description is broad enough to activate on vague phrases like any tires-related request, which can cause the skill to run in situations the user did not clearly intend. In a booking skill that may initiate searches and progress toward reservations, overbroad activation increases the chance of unnecessary third-party data transmission or undesired transactional actions.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill instructs collection and transmission of customer name, email, and phone number to an external MCP endpoint without any user-facing warning, consent language, or data-handling notice. Because this is personally identifiable information sent to a third party during booking, the absence of an explicit warning and consent step creates privacy, compliance, and trust risks.

VirusTotal

48/48 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.