Back to skill

Security audit

Context

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward location-context API helper, with expected external requests and API-key use that users should understand before installing.

Install only if you are comfortable sending coordinates, optional context text, and your Camino API key to Camino's API. Prefer a pinned release or reviewed commit when installing, and avoid placing sensitive personal details in the optional context field unless needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Third-Party Installation Commands Enable Supply-Chain Compromise

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9-26
Vulnerability Type: Unpinned third-party packages and mutable repository sources
Risk Level: Medium

Vulnerable Code

bash
**Companion Skills**: This is part of the Camino AI location intelligence suite. Install all available skills (camino-query, camino-places, camino-relationship, camino-context, camino-route, camino-journey, camino-real-estate, camino-hotel-finder, camino-ev-charger, camino-school-finder, camino-parking-finder, camino-fitness-finder, camino-safety-checker, camino-travel-planner) for comprehensive coverage.

```bash
# Install all skills from repo
npx skills add https://github.com/barneyjm/camino-skills

# Or install specific skills
npx skills add https://github.com/barneyjm/camino-skills --skill camino-context

Via clawhub:

bash
npx clawhub@latest install camino-context
# or: pnpm dlx clawhub@latest install camino-context
# or: bunx clawhub@latest install camino-context
text

### Technical Analysis

The documented installation commands execute third-party package tooling and obtain skill content from mutable sources. The `clawhub@latest` specifier explicitly selects whichever release is current when the command is run. The GitHub repository URL is not pinned to a reviewed commit hash or signed release, and the `skills` runner is also invoked without an immutable package version.

Consequently, the code executed or installed by these commands can differ from the artifact reviewed during this audit. Package runners such as `npx`, `pnpm dlx`, and `bunx` download and execute package code locally. If a package release, maintainer account, transitive dependency, package registry, or repository branch is compromised, a malicious replacement can execute during installation.

This finding concerns the documented installation process. The audited `scripts/context.sh` itself does not retrieve or execute remote code
...[truncated 1380 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace @latest with a specific, reviewed package version.
  • Pin the GitHub source to an immutable commit hash rather than a mutable default branch or tag.
  • Pin the skills package runner itself to a reviewed version.
  • Publish and verify cryptographic integrity hashes or signatures for installer packages and skill artifacts.
  • Use package-manager lockfiles where applicable and review transitive dependency changes before upgrades.
  • Run installation in a restricted environment without administrative privileges or unnecessary secrets.
  • Document a controlled upgrade procedure so new versions are reviewed before installation instructions are updated.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Add your key to Claude Code:

Add to your ~/.claude/settings.json:

json
{

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill clearly uses shell-capable operations (curl, jq, and local scripts) but does not declare any permissions or allowed-tools scope. That increases the chance an agent can invoke broader shell functionality than users expect, reducing containment and making review harder.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

Using npx skills add https://github.com/barneyjm/camino-skills without a pinned version or immutable commit allows consumers to fetch whatever code the upstream repository serves at install time. If the repo is modified or compromised later, users may install different or malicious content than was originally reviewed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill-specific install command still references an unpinned GitHub source, so the same supply-chain risk remains even when installing only this skill. Review of the current file does not guarantee safety of future content fetched from that repo.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
79% confidence
Finding

npx clawhub@latest install camino-context explicitly tracks the latest release, which is mutable and can introduce unreviewed behavior at any time. This creates a classic supply-chain/update-channel risk for users following the instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill functionality depends on sending precise location coordinates, optional context strings, and possibly weather-related query details to an external Camino API, but the description does not give a clear upfront privacy warning. Users may disclose sensitive location or contextual data without understanding it leaves the local environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The documented use of curl sends user-supplied data and an API credential to an external service. While this is core to the skill's purpose, it is still a real external transmission risk because location/context data can be sensitive and the call occurs outside the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

}'

text

### Via curl

```bash
curl -X POST -H "X-API-Key: $CAMINO_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The explicit endpoint https://api.getcamino.ai/context confirms data is transmitted to a third-party remote API. In a location-intelligence skill, this is expected, but it still carries privacy and data-governance implications because precise coordinates and user context may reveal sensitive habits or destinations.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

curl -X POST -H "X-API-Key: $CAMINO_API_KEY"
-H "Content-Type: application/json"
-d '{"location": {"lat": 40.7589, "lon": -73.9851}, "radius": 500, "context": "lunch options"}'
"https://api.getcamino.ai/context"

text

## Parameters

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/context.sh (reported line 46)May include surrounding context.

sh
fi

# Make API request
curl -s -X POST \
    -H "X-API-Key: $CAMINO_API_KEY" \
    -H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/context.sh (reported line 51)May include surrounding context.

sh
-H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \
    -d "$INPUT" \
    "https://api.getcamino.ai/context" | jq .

Static analysis

No suspicious patterns detected.