Back to skill

Security audit

Query

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward Camino AI API helper, with privacy considerations around sending location queries to an external service.

Install only if you are comfortable sending your Camino API key and location-related queries to Camino AI. Avoid entering sensitive home, workplace, medical, or travel-location details unless you trust the provider's privacy practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill invokes shell-based installation and usage commands, but no explicit permissions are declared to signal that shell capability is required. This creates a transparency and policy-enforcement gap: agents or users may approve or run the skill without understanding it relies on shell execution, increasing the chance of unintended command execution or weaker sandboxing decisions.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages users to submit natural-language place queries and coordinates to Camino AI's external API, but it does not clearly warn that this data leaves the local environment. Location queries can reveal sensitive behavioral, residential, workplace, travel, or health-related information, so silent transmission creates a meaningful privacy and consent risk.

VirusTotal

No VirusTotal findings

View on VirusTotal