Journey

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requirements and instructions are consistent with a journey-planning integration that calls an external Camino API; nothing in the files suggests unrelated or hidden behavior, but it will transmit location data to api.getcamino.ai and requires you to store an API key.

This skill appears to do what it says: it posts your provided waypoints to https://api.getcamino.ai/journey using CAMINO_API_KEY. Before installing/using: 1) Verify the Camino service and GitHub repo (https://github.com/barneyjm/camino-skills) are trustworthy; the skill metadata has no homepage. 2) Understand that any location data and emails you submit are sent to api.getcamino.ai (privacy-sensitive). 3) If you store the API key in ~/.claude/settings.json, it will persist on disk—consider using a secrets manager or ephemeral trial key. 4) The script requires jq and curl; review the script (it's short and readable) before running. If any of these points are unacceptable, do not install or provide your real API key.

Static analysis

Static analysis findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.