Back to skill

Security audit

Ev Charger

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward EV charger lookup tool that sends user-provided search and location data to Camino AI as documented.

Before installing, confirm you trust Camino AI with EV charging searches and any precise coordinates you provide. Prefer a limited or revocable CAMINO_API_KEY, and review the broader Camino suite separately before choosing the optional all-skills install path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding
The skill documents shell-based execution paths (`npx`, `curl`, and `./scripts/ev-charger.sh`) but does not declare corresponding permissions or capabilities. This can mislead users and host tooling about what the skill actually requires, increasing the chance of unintended command execution, network access, or unsafe installation flows in environments that rely on declared permissions for trust decisions.

VirusTotal

No VirusTotal findings

View on VirusTotal