Trust Assessment
book-braids received a trust score of 94/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Skill designed to transmit PII to external service.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 14, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Skill designed to transmit PII to external service The 'create_booking' tool is designed to collect and transmit Personally Identifiable Information (PII) such as 'customerName', 'customerEmail', and 'customerPhone' to an external endpoint ('https://lokuli.com/mcp/sse'). While this is the intended functionality of a booking skill, it represents a data privacy risk as this sensitive user data will be shared with a third-party service. Users should be aware of this data sharing, and the security of the external service is critical to prevent unauthorized data exfiltration. Inform users about the PII collection and sharing with third-party services. Ensure the third-party service ('lokuli.com') adheres to strong data privacy and security standards. Implement data minimization principles where possible, only collecting necessary PII. | LLM | SKILL.md:39 |
Scan History
Embed Code
[](https://skillshield.io/report/d2003a5b324e41d4)
Powered by SkillShield