Back to skill

Security audit

Real Estate

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says: it sends addresses or coordinates to Camino AI to return real-estate location context.

Install only if you are comfortable sending property addresses, precise coordinates, search radius, query context, and any trial-signup email to Camino AI. Use a limited API key where possible, keep it out of committed files, and review the optional companion-skill repository before installing the whole suite.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises shell-based usage and installation commands, but the metadata declares only an environment variable requirement and no explicit permissions or capability boundaries. This can cause users or host systems to underestimate that the skill relies on shell execution, increasing the chance of unsafe invocation or policy bypass in environments that gate shell access.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill processes addresses and coordinates through Camino's external API, yet the description does not prominently warn users that potentially sensitive location data will be transmitted off-platform. Home addresses and exact coordinates can reveal private residences, travel patterns, or other personal information, so lack of notice meaningfully increases privacy and data-handling risk.

VirusTotal

No VirusTotal findings

View on VirusTotal