Fitness Finder

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's code, instructions, and credential requirements line up with its stated purpose (searching for fitness venues via Camino AI); nothing indicates hidden exfiltration or unrelated privileges, though there are minor documentation inconsistencies to note.

This skill appears to do what it claims: it calls Camino's API and needs CAMINO_API_KEY. Before installing, do the following: (1) Confirm you trust https://api.getcamino.ai and the referenced GitHub repo if you follow the npx install instructions. (2) Be aware the script requires curl and jq even though the registry metadata omits those binaries; install them or update the metadata. (3) Keep your CAMINO_API_KEY secret — do not paste it into public places. (4) If you want to be extra cautious, inspect the GitHub repo contents (and any install scripts) before running npx/clawhub to avoid supply-chain risks.

Static analysis

Static analysis findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.