Back to skill

Security audit

Fitness Finder

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward fitness-facility search helper that uses a disclosed Camino API key and does not show hidden or harmful behavior.

Before installing, be comfortable sharing fitness search terms and optional location coordinates with Camino AI. Keep CAMINO_API_KEY private, avoid committing Claude settings to source control, and rotate or remove the key when you stop using the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
83% confidence
Finding
The setup instructions tell users to place a long-lived API key in a plaintext local settings file without any warning about local credential exposure, file permissions, or safer secret-handling options. If the workstation is shared, backed up insecurely, or the config file is accidentally committed or exposed, the API key could be stolen and abused for unauthorized API usage.

VirusTotal

No VirusTotal findings

View on VirusTotal