Ev Charger
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's code, instructions, and required credential (CAMINO_API_KEY) are consistent with an EV charger lookup using Camino AI; nothing in the files indicates unexplained access or data exfiltration.
This skill appears coherent and limited to querying Camino's API. Before installing or running: (1) verify you trust the GitHub repo URL referenced in SKILL.md if you run the npx install command, (2) ensure jq and curl are installed (the script will exit otherwise), (3) only provide a Camino API key obtained from the official Camino site (the script posts to api.getcamino.ai and the trial endpoint shown), (4) avoid running scripts from unknown sources as root and inspect files (scripts/ev-charger.sh) locally first, and (5) consider using a scoped or limited API key if Camino supports that so the key cannot be abused elsewhere.
Static analysis
Static analysis findings are pending for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
