Back to skill

Security audit

Local Booking

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward local-service booking helper, with some privacy and activation-scope notes users should understand before use.

Before installing, understand that searches and bookings go through Lokuli, and creating a booking may share your contact details and service request information with Lokuli and payment providers such as Stripe. Review the provider, price, time, and contact details before approving any booking or opening a checkout link.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is broad enough to activate on essentially any local service request, which increases the chance the skill is invoked in situations where the user did not clearly intend to use an external booking provider. In this context, over-triggering is risky because the skill can progress toward collecting location and contact data and initiating third-party booking flows.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs collection of name, email, phone, and location data for transmission to an external booking service, but it does not prominently warn the user that their personal information will be shared with Lokuli and potentially Stripe. This reduces informed consent and creates privacy and trust risks, especially because the workflow naturally escalates from search to booking.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.