Back to skill

Security audit

Hotel Finder

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to provide the advertised hotel search function, but its install guidance is broader and more mutable than necessary while it also handles API keys and travel/location queries.

Review before installing. Prefer a pinned release or commit, install only the hotel-finder skill unless you intentionally want the whole companion suite, use a limited/rotatable Camino API key, and avoid sending sensitive itinerary or precise location details unless you are comfortable sharing them with Camino's API.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party Installation Commands Permit Supply-Chain Code Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/hotel-finder.sh:43
Finding

Unvalidated Optional Inputs Permit API Query-Parameter Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The documentation instructs users to place a long-lived API key in ~/.claude/settings.json, an agent configuration directory that may be broadly accessible to local tools, extensions, backups, or other skills. Storing secrets in a shared config file increases the blast radius if the host or agent environment is later compromised.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Add your key to Claude Code:

Add to your ~/.claude/settings.json:

json
{

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell-based execution (./scripts/hotel-finder.sh, curl) but does not declare any explicit tool scope such as permissions or allowed-tools. That increases the chance an agent can invoke shell capabilities more broadly than intended, weakening least-privilege controls for a network-enabled skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx skills add https://github.com/barneyjm/camino-skills without pinning a specific version or commit makes installation dependent on whatever code is served later. If the upstream package or repository is modified or compromised, users may install unreviewed code, creating a supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill-specific install example still references the GitHub repository through npx skills add without an immutable version. This exposes users to the same supply-chain risk from future repository changes or compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

npx clawhub@latest install hotel-finder uses a floating latest tag, which can change over time and pull newly published code without review. That creates a supply-chain exposure if a malicious or vulnerable release is published.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

Instant Trial (no signup required): Get a temporary API key with 25 calls:

bash
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"email": "you@example.com"}' \
  https://api.getcamino.ai/trial/start

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

bash
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"email": "you@example.com"}' \
  https://api.getcamino.ai/trial/start

Returns: {"api_key": "camino-xxx...", "calls_remaining": 25, ...}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

bash
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"email": "you@example.com"}' \
  https://api.getcamino.ai/trial/start

Returns: {"api_key": "camino-xxx...", "calls_remaining": 25, ...}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script transmits user-supplied search queries and optional location coordinates to an external Camino API, but it provides no user-facing notice at runtime that this data will leave the local environment. In an agent skill context, queries may contain sensitive travel plans, locations, or business itinerary details, so silent exfiltration to a third party creates a real privacy and data-governance risk even if the transmission is the skill's intended function.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This code makes a direct HTTPS request to an external API endpoint using user-controlled content in the request parameters. Although the network access is expected for a hotel search tool, it still constitutes a real external data transfer path that can expose potentially sensitive queries and location metadata to a third-party service.

Content

Scanner excerpt · scripts/hotel-finder.sh (reported line 72)May include surrounding context.

sh
curl -s -X GET \
    -H "X-API-Key: $CAMINO_API_KEY" \
    -H "X-Client: claude-code-skill" \
    "https://api.getcamino.ai/query?${QUERY_STRING}" | jq .