Back to skill

Security audit

Book Tree Service

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal tree-service booking integration, but users should know booking details are sent to Lokuli's external service.

Install only if you are comfortable using Lokuli as a third-party booking service. Before creating a booking, confirm the provider, appointment details, and exactly which contact information will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger language is broad enough to activate on general tree-service requests, not just explicit booking intent. That can cause the agent to prematurely route a user into an external booking workflow and share request details without clear consent or confirmation.

Missing User Warnings

High
Confidence
95% confidence
Finding
The skill instructs use of an external MCP endpoint but provides no warning that user data and service requests may be sent to a third party. This creates a meaningful privacy and consent risk because users may not realize their information is leaving the local agent context.

Missing User Warnings

High
Confidence
97% confidence
Finding
The booking example includes full customer name, email, and phone number, but the skill does not require any privacy notice, minimization, or confirmation before transmitting that PII. In practice, this could normalize collecting and sending sensitive contact data to a third-party service without informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.