Back to skill

Security audit

Relationship

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed API client for spatial relationship calculations, with privacy and supply-chain caveats but no hidden or destructive behavior found.

Install this only if you are comfortable sending the email used for trial signup, the provided coordinates, and your Camino API key to Camino's service. Prefer a pinned release or reviewed commit instead of the unpinned GitHub and @latest install examples, and avoid using it with highly sensitive home, workplace, or client locations unless that data sharing is acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Installation Commands Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13-24
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

The installation documentation recommends executing package runners using the mutable latest tag and installing source directly from a Git repository without pinning a reviewed commit:

bash
# Install all skills from repo
npx skills add https://github.com/barneyjm/camino-skills

# Or install specific skills
npx skills add https://github.com/barneyjm/camino-skills --skill relationship

Via clawhub:

bash
npx clawhub@latest install relationship
# or: pnpm dlx clawhub@latest install relationship
# or: bunx clawhub@latest install relationship

Technical Analysis

The Git installation commands reference a mutable repository branch rather than an immutable commit hash or signed release. The package-runner commands similarly use clawhub@latest, which resolves to whichever package version is current at execution time. Consequently, the code installed or executed by these commands can differ from the version reviewed during this audit.

Package runners such as npx, pnpm dlx, and bunx download and execute package code. If the relevant registry account, package, repository, maintainer credentials, or release process is compromised, an attacker could substitute malicious installation logic. The recommendation to install all skills also expands the supply-chain attack surface beyond the code needed for the relationship function.

No evidence shows that the currently reviewed project contains such a malicious payload. The vulnerability is the absence of dependency pinning and integrity controls in the documented installation process.

Attack Path

  1. An attacker compromises the upstream package registry account, Git repository, maintainer credentials, or publishing pipeline.
  2. The attacker publishes a malicious version under the `latest ...[truncated 1008 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an explicitly reviewed package version, for example clawhub@x.y.z.
  2. Pin Git-based installation to an immutable commit SHA or a cryptographically signed release rather than the repository's default branch.
  3. Publish and verify cryptographic checksums or signatures for installation artifacts.
  4. Commit and enforce an appropriate lockfile where package-manager workflows support it.
  5. Recommend installing only the required relationship skill instead of all repository skills, unless the additional components have been independently reviewed and are necessary.
  6. Run installation with a non-privileged account in an isolated environment, and do not expose unrelated credentials or sensitive environment variables during installation.
  7. Establish dependency provenance, maintainer account protection, and release review controls, including multi-factor authentication and protected release workflows.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as performing spatial calculations, but the content shows it is actually a thin client for a third-party API that transmits user-supplied location data and relies on an API key. This mismatch is dangerous because users and agents may trust it as a local calculation utility while unknowingly disclosing sensitive data externally and granting credentialed network access.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Add your key to Claude Code:

Add to your ~/.claude/settings.json:

json
{

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs users to run shell commands and invoke local scripts, but it does not declare any tool scope or allowed-tools restrictions. In an agent environment, missing capability declarations reduces transparency and can permit broader shell use than users expect, increasing the chance of unsafe command execution or misuse by downstream automation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx skills add against a remote GitHub repository without pinning a version or commit causes installation to depend on mutable upstream content. If the repository or its dependencies are changed or compromised later, users may install altered code unexpectedly, creating a supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This installation path also references an unpinned remote source, so the installed skill contents can change over time without user awareness. That makes the skill vulnerable to repository compromise, malicious updates, or accidental breaking changes that affect security.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Running npx clawhub@latest explicitly requests the newest published version, which is mutable and could introduce malicious or unreviewed behavior at install time. This creates a software supply-chain exposure because users cannot reproduce or audit the exact code they executed later.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation encourages sending email addresses to obtain trial API keys and later sending precise location pairs to the provider, but it does not provide an explicit privacy warning or data-handling notice. Because location and email data are sensitive, the omission can lead users to disclose personal information without informed consent or understanding of retention/sharing practices.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill documentation includes a network request that sends a user's email address to an external service to obtain a trial key. External transmission of personal data is expected for this workflow, but it remains a real security/privacy concern because the transfer is to a third party and is not accompanied by minimization or warning language.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

Instant Trial (no signup required): Get a temporary API key with 25 calls:

bash
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"email": "you@example.com"}' \
  https://api.getcamino.ai/trial/start

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

bash
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"email": "you@example.com"}' \
  https://api.getcamino.ai/trial/start

Returns: {"api_key": "camino-xxx...", "calls_remaining": 25, ...}

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill sends start/end coordinates and an API key to a remote endpoint, which is an external transmission of potentially sensitive location data. In context this is core functionality rather than hidden exfiltration, but it still creates privacy and credential exposure risk if users assume the tool computes relationships locally.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

curl -X POST -H "X-API-Key: $CAMINO_API_KEY"
-H "Content-Type: application/json"
-d '{"start": {"lat": 40.7128, "lon": -74.0060}, "end": {"lat": 40.7589, "lon": -73.9851}}'
"https://api.getcamino.ai/relationship"

text

## Parameters

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The script transmits user-supplied location data and an API key to an external service via curl. This is expected for the skill's functionality, but it is still a real data egress/security concern because sensitive coordinates or other unexpected JSON content in the input are sent off-host to a third party, which may violate least-privilege or data-handling expectations if the caller is unaware.

Content

Scanner excerpt · scripts/relationship.sh (reported line 52)May include surrounding context.

sh
fi

# Make API request
curl -s -X POST \
    -H "X-API-Key: $CAMINO_API_KEY" \
    -H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The hardcoded external endpoint confirms that the skill sends data to a remote third-party API. In this context that behavior is intentional, but it remains a genuine vulnerability from a supply-chain/data-exfiltration perspective because execution of the skill necessarily discloses input data and uses a secret-bearing request header to an external domain.

Content

Scanner excerpt · scripts/relationship.sh (reported line 57)May include surrounding context.

sh
-H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \
    -d "$INPUT" \
    "https://api.getcamino.ai/relationship" | jq .