Trust Assessment
book-painter received a trust score of 97/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 0 medium, and 1 low severity. Key findings include PII transfer to external service.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| LOW | PII transfer to external service The 'create_booking' tool collects Personally Identifiable Information (PII) including customer name, email, and phone number. This data is then transmitted to an external service at 'https://lokuli.com/mcp/sse'. While this may be the intended functionality of the skill, users should be explicitly aware that sensitive data is being shared with a third-party endpoint. This constitutes a data privacy consideration. Inform users explicitly about the collection and transfer of PII to third-party services. Ensure the third-party service adheres to relevant data privacy regulations and that data handling practices are transparent. Consider providing options for users to control data sharing or anonymizing data where possible. | LLM | SKILL.md:57 |
Scan History
Embed Code
[](https://skillshield.io/report/9ba94ef2baa32de0)
Powered by SkillShield