Back to skill

Security audit

Hotel Finder

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward hotel-search helper that sends user-provided lodging searches to Camino AI using a user-supplied API key.

Install only if you are comfortable sending hotel search text, travel intent, optional latitude/longitude values, and any trial signup email to Camino AI. Keep CAMINO_API_KEY private, avoid committing it to shared files, and use a placeholder or disposable email for trial signup if privacy matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The README instructs users to send an email address to a third-party trial API endpoint but does not clearly disclose that personal data is being transmitted, how it will be used, or link to a privacy notice. This can lead to unintended exposure of personal information and weakens informed consent, especially because the example normalizes direct submission of real user data from the command line.

VirusTotal

No VirusTotal findings

View on VirusTotal