Back to skill

Security audit

kami-package-detection

Security checks for vulnerabilities and agentic risk

Overview

This camera-monitoring skill mostly matches its stated purpose, but it under-discloses sensitive image uploads, local retention, background monitoring, and credential logging.

Review this skill before installing. Use it only if you are comfortable with continuous camera monitoring, local snapshot files, external notification services receiving alert data and possibly images, and installer downloads. Avoid placing RTSP passwords in URLs if possible, restrict file permissions on the skill directory, disable or remove notification credentials unless needed, and clear snapshots/logs regularly.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (21)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill clearly exercises privileged capabilities including shell execution, network access, and local file read/write, but does not declare them in any explicit permission model. This weakens user consent and security review because operators may assume a narrower trust boundary than the skill actually requires. In a camera-monitoring context, undeclared network and file access are especially sensitive because the skill handles RTSP streams, snapshots, and external notification endpoints.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior substantially exceeds the core description by adding external notifications, image uploads, daemon/process management, multi-camera orchestration, model downloading, and on-disk snapshot storage. Security-relevant functionality that is omitted or underemphasized in the description can mislead users and reviewers about data exposure, persistence, and remote communications. For a home-camera skill, hidden or poorly disclosed egress paths and image handling materially increase privacy and security risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README makes a privacy assurance that there is 'no background daemon, no cache, and no residual data,' but earlier sections explicitly document daemon mode and a 24-hour tracking window for suppressing repeat alerts. This mismatch can mislead users about persistence and long-running monitoring behavior, causing them to deploy camera surveillance software under false assumptions about retention and process lifetime.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that frames are only held in memory and that the skill emits a single JSON object to stdout, but elsewhere it describes continuous background multi-camera monitoring with repeated control/status interactions. Even if raw frames are not saved, these statements understate the operational scope and can misrepresent surveillance duration and output behavior to users and integrators.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The privacy notice says frames are not persisted to disk by default, yet the documented alarm path saves annotated JPEG snapshots locally. Misstating retention behavior is dangerous because users may deploy the skill assuming no image evidence is stored, when in fact potentially sensitive camera frames are written to disk and could be retained, copied, or accessed later. In a residential surveillance context, even local-only snapshots can contain highly sensitive personal data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The stop logic trusts a PID read from a writable file under the skill directory and then sends SIGTERM/SIGKILL to that PID without verifying the target process is actually this skill. If an attacker or another local process can tamper with the PID file, the skill can be turned into an arbitrary local process killer running with the skill's privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The troubleshooting section reveals that setup may download a model archive from an external host, but this is not prominently disclosed in installation/setup documentation. Undisclosed network retrieval of executable model assets expands the trust boundary and can expose users to supply-chain risk, especially if the archive source, integrity checks, and provenance are not clearly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation contains internally contradictory privacy statements about whether a background daemon exists. While this is primarily a documentation integrity issue, in a camera-monitoring skill it can still materially affect user consent, operational expectations, and safe deployment decisions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Broad trigger phrases like generic smart-home and package-related queries can cause the skill to activate in unintended contexts. Unintended activation matters here because the skill can access camera streams, run background monitoring, and send notifications, so overbroad invocation increases the chance of accidental surveillance or configuration changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger set includes ambiguous everyday phrases such as checking for deliveries or asking whether there is a package, without strong scope constraints. In this skill's context, such ambiguity can lead to accidental invocation of camera-monitoring functionality and expose surveillance data or start persistent background processes when the user did not clearly intend that level of access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The helper uploads local camera snapshots to sm.ms, a public anonymous image host, as a fallback for notifications. In the context of a smart-home package detection skill, these images can expose private residential scenes, delivery activity, timestamps, and potentially people or address-identifying details to a third-party public service without explicit disclosure or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically installs Python packages and downloads a model archive from the internet without an upfront consent or safety warning. That behavior changes the local environment and executes trust decisions on remote content, which increases supply-chain and unexpected system-modification risk, especially for users who run setup scripts casually.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code logs the full RTSP URL, which commonly embeds camera usernames, passwords, hostnames, and internal network details. Anyone with access to logs could recover camera credentials or map the home network, making this especially sensitive in a smart-home surveillance context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill saves annotated camera snapshots to disk persistently without any retention control or explicit user consent mechanism in this code. In a home-camera context, these images can contain people, packages, and surroundings, creating privacy and data-retention risk if the host is shared or later compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

Alarm payloads including camera name, detections, and snapshot path are sent to a notification dispatcher without any visibility here into destination, transport security, or user consent. In a smart-home monitoring skill, outbound transmission of surveillance-derived events increases privacy risk because it may disclose presence, deliveries, or images to external services.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

This duplicate finding corresponds to the same actual behavior: the script invokes sudo to update apt metadata and install build dependencies. Even though it asks first, running privileged package operations from installer logic expands the blast radius from user-level setup to system-wide modification.

Content

Scanner excerpt · setup.sh (reported line 73)May include surrounding context.

sh
echo ""
        read -p "Install build dependencies with sudo? [y/N] " confirm
        if [[ "$confirm" =~ ^[Yy]$ ]]; then
            sudo apt update && sudo apt install -y \
                make build-essential libssl-dev zlib1g-dev \
                libbz2-dev libreadline-dev libsqlite3-dev \
                libncursesw5-dev xz-utils tk-dev libxml2-dev \

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

This duplicate finding corresponds to the same actual behavior: the script invokes sudo to update apt metadata and install build dependencies. Even though it asks first, running privileged package operations from installer logic expands the blast radius from user-level setup to system-wide modification.

Content

Scanner excerpt · setup.sh (reported line 73)May include surrounding context.

sh
echo ""
        read -p "Install build dependencies with sudo? [y/N] " confirm
        if [[ "$confirm" =~ ^[Yy]$ ]]; then
            sudo apt update && sudo apt install -y \
                make build-essential libssl-dev zlib1g-dev \
                libbz2-dev libreadline-dev libsqlite3-dev \
                libncursesw5-dev xz-utils tk-dev libxml2-dev \

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency list leaves onnxruntime unpinned, which makes builds non-reproducible and can cause the skill to silently consume newer releases with security regressions or breaking behavior. While not an exploit by itself, unpinned packages increase supply-chain risk and make it harder to verify what code is actually deployed.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
onnxruntime
opencv-python-headless
numpy
requests

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

opencv-python-headless is unpinned, so installations may resolve to different versions over time, including versions with known vulnerabilities or incompatible behavior. In a camera-processing skill that handles untrusted image/video input, this weakens supply-chain control and increases exposure to parser bugs in native code.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
onnxruntime
opencv-python-headless
numpy
requests

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

numpy is unpinned, which permits uncontrolled version drift and can pull in vulnerable or incompatible builds. Although common in early-stage projects, this is still a dependency hygiene weakness that increases operational and security risk.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
onnxruntime
opencv-python-headless
numpy
requests

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

requests is unpinned, so the installed version may vary by environment and time, potentially introducing known flaws such as credential leakage or TLS-related bugs. Because this skill likely fetches models, streams, or remote resources, network-library version control matters for security.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
onnxruntime
opencv-python-headless
numpy
requests

Static analysis

No suspicious patterns detected.