Back to skill

Security audit

Book Towing

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward towing-booking integration, but users should confirm they want to share contact details with Lokuli before creating a booking.

Install only if you are comfortable using Lokuli for towing bookings. Before creating a booking, confirm the provider, time slot, price or cancellation terms if available, and that you want your name, email, and phone number shared for the service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase "or any towing service request" is overly broad and can cause the skill to activate in situations where the user did not clearly ask to use this specific booking workflow. Overbroad activation increases the chance of unintended tool use, premature collection of user data, or routing users into a third-party booking flow without sufficiently explicit consent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The create_booking example transmits personal contact details including name, email, and phone number to an external MCP endpoint, but the skill does not warn the user that this information will be collected and shared. This creates a privacy and consent risk because users may not understand that sensitive personal data is being sent to a third-party service for booking.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.