T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned Third-Party Installation Commands Permit Supply-Chain Code Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to provide the advertised hotel search function, but its install guidance is broader and more mutable than necessary while it also handles API keys and travel/location queries.
Review before installing. Prefer a pinned release or commit, install only the hotel-finder skill unless you intentionally want the whole companion suite, use a limited/rotatable Camino API key, and avoid sending sensitive itinerary or precise location details unless you are comfortable sharing them with Camino's API.
SKILL.md:10Unpinned Third-Party Installation Commands Permit Supply-Chain Code Execution
scripts/hotel-finder.sh:43Unvalidated Optional Inputs Permit API Query-Parameter Injection
The documentation instructs users to place a long-lived API key in ~/.claude/settings.json, an agent configuration directory that may be broadly accessible to local tools, extensions, backups, or other skills. Storing secrets in a shared config file increases the blast radius if the host or agent environment is later compromised.
Add your key to Claude Code:
Add to your ~/.claude/settings.json:
{
The skill documents shell-based execution (./scripts/hotel-finder.sh, curl) but does not declare any explicit tool scope such as permissions or allowed-tools. That increases the chance an agent can invoke shell capabilities more broadly than intended, weakening least-privilege controls for a network-enabled skill.
Using npx skills add https://github.com/barneyjm/camino-skills without pinning a specific version or commit makes installation dependent on whatever code is served later. If the upstream package or repository is modified or compromised, users may install unreviewed code, creating a supply-chain risk.
The skill-specific install example still references the GitHub repository through npx skills add without an immutable version. This exposes users to the same supply-chain risk from future repository changes or compromise.
npx clawhub@latest install hotel-finder uses a floating latest tag, which can change over time and pull newly published code without review. That creates a supply-chain exposure if a malicious or vulnerable release is published.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Instant Trial (no signup required): Get a temporary API key with 25 calls:
curl -s -X POST -H "Content-Type: application/json" \
-d '{"email": "you@example.com"}' \
https://api.getcamino.ai/trial/start
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -s -X POST -H "Content-Type: application/json" \
-d '{"email": "you@example.com"}' \
https://api.getcamino.ai/trial/start
Returns: {"api_key": "camino-xxx...", "calls_remaining": 25, ...}
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -s -X POST -H "Content-Type: application/json" \
-d '{"email": "you@example.com"}' \
https://api.getcamino.ai/trial/start
Returns: {"api_key": "camino-xxx...", "calls_remaining": 25, ...}
The script transmits user-supplied search queries and optional location coordinates to an external Camino API, but it provides no user-facing notice at runtime that this data will leave the local environment. In an agent skill context, queries may contain sensitive travel plans, locations, or business itinerary details, so silent exfiltration to a third party creates a real privacy and data-governance risk even if the transmission is the skill's intended function.
This code makes a direct HTTPS request to an external API endpoint using user-controlled content in the request parameters. Although the network access is expected for a hotel search tool, it still constitutes a real external data transfer path that can expose potentially sensitive queries and location metadata to a third-party service.
curl -s -X GET \
-H "X-API-Key: $CAMINO_API_KEY" \
-H "X-Client: claude-code-skill" \
"https://api.getcamino.ai/query?${QUERY_STRING}" | jq .