Back to skill

Security audit

Book Tutor

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Lokuli tutor-booking skill, with the main caution that creating a booking sends contact details to an external service.

Install this only if you intend to use Lokuli for tutor search and booking. Before creating a booking, confirm the tutor, time, and that your name, email, and phone number will be sent to Lokuli or its booking provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description says the skill should trigger on broadly phrased requests like 'any tutor service request,' which can cause over-activation in contexts where the user did not explicitly intend to invoke an external booking workflow. Because this skill connects to a third-party MCP endpoint and can lead to search and booking actions, overly broad triggering increases the risk of unintended data sharing or accidental transactional behavior.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill includes a booking flow that transmits personal data such as customer name, email, and phone number to an external service, but it does not warn the user that this information will be shared. Without a clear notice and consent step, users may disclose sensitive personal data without understanding that it is being sent to a third-party booking provider.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.