Back to skill

Security audit

Journey

Security checks across malware telemetry and agentic risk

Overview

The skill does what it says: it sends user-provided journey waypoints to Camino's API, with privacy and optional companion-install considerations users should review.

Install the journey-only skill unless you have reviewed the broader Camino companion repository. Avoid sending exact home, work, client, or future travel coordinates unless necessary, and consider using a temporary or scoped API key rather than a long-lived key in settings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to send precise waypoint coordinates and itinerary details to a third-party remote API, but it does not warn that this shares potentially sensitive location history, travel plans, and behavioral patterns outside the local environment. In a journey-planning skill, this context increases risk because the data can reveal home/work locations, routines, and planned absences, which may create privacy and physical security concerns if mishandled.

VirusTotal

No VirusTotal findings

View on VirusTotal