Back to skill

Security audit

Studio Booking Manager

Security checks across malware telemetry and agentic risk

Overview

The skill fits a studio-booking use case, but it includes payment/refund and customer-history handling without enough built-in confirmation, authorization, or privacy controls.

Before installing, confirm the bot enforces owner/admin authorization, requires explicit confirmation before cancellation or refund, logs booking changes, and shows users what contact/payment/history data is collected, shared with TelegaPay, retained, and visible to staff.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly handles contact details, booking history, phone numbers, and payment-related data, but provides no guidance on consent, minimization, retention, or user disclosure. In a booking/payment workflow this creates a real privacy and compliance risk, because an agent could collect or expose sensitive personal data more broadly than necessary.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The cancellation routine performs destructive state changes and can trigger refunds, yet the skill contains no requirement for explicit user confirmation, authorization checks, or operator warning before execution. In a real booking system this could lead to accidental or unauthorized cancellations/refunds, causing financial loss and service disruption.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.