Back to skill

Security audit

Ev Charger

Security checks for vulnerabilities and agentic risk

Overview

The EV charger lookup behavior is disclosed and coherent, but the install instructions use mutable remote sources and encourage installing many companion skills outside this reviewed artifact.

Install only the specific skill version you intend to use, prefer pinned versions or commit hashes over @latest or branch-based GitHub installs, and avoid the all-companion-skills command unless you have reviewed those skills too. Expect your Camino API key and EV charger search details, including locations, to be sent to Camino's API.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Third-Party Installation Sources Permit Supply-Chain Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11–25
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

The installation documentation instructs users to execute package runners and install content from mutable remote sources:

bash
# Install all skills from repo
npx skills add https://github.com/barneyjm/camino-skills

# Or install specific skills
npx skills add https://github.com/barneyjm/camino-skills --skill camino-ev-charger

npx clawhub@latest install camino-ev-charger
# or: pnpm dlx clawhub@latest install camino-ev-charger
# or: bunx clawhub@latest install camino-ev-charger

Technical Analysis

The GitHub installation commands do not pin the repository to a reviewed commit hash or signed release. Consequently, the content installed by the same command can change after this Skill has been audited.

The package-runner commands explicitly use the mutable latest distribution tag. Tools such as npx, pnpm dlx, and bunx download and execute third-party packages in the local environment. If a package publisher account, registry release, repository, or transitive dependency is compromised, these commands may execute attacker-controlled installation logic with the privileges of the user performing the installation.

The command that installs all companion skills additionally expands the executable code and dependency surface beyond the specific Skill reviewed in this audit.

No evidence was found that the currently reviewed files are themselves malicious. The vulnerability is the absence of immutable dependency selection and integrity verification in the documented installation process.

Attack Path

  1. An attacker compromises the relevant package publisher, registry package, GitHub repository, release process, or transitive dependency.
  2. The attacker publishes malicious content under the mutable latest tag or changes the repository branch r ...[truncated 1092 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version, such as clawhub@x.y.z.
  2. Pin GitHub installations to a full immutable commit hash rather than a mutable branch or repository default.
  3. Publish cryptographic checksums or signed release artifacts and verify them before installation.
  4. Use lockfiles and integrity metadata for package and transitive dependency resolution where supported.
  5. Recommend installing only the required Skill instead of all companion skills by default.
  6. Document the expected publisher identity, package source, version, and commit so users can verify provenance.
  7. Perform installation in a least-privileged or sandboxed environment and explicitly warn users not to run package-runner commands as an administrator.
  8. Establish dependency monitoring and a release-review process so compromised or unexpected upstream changes can be detected before documentation is updated.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Add your key to Claude Code:

Add to your ~/.claude/settings.json:

json
{

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly shells out to curl and jq via scripts but does not declare any permissions or allowed-tools scope. That increases risk because an agent may execute shell commands without an explicit least-privilege contract, making command execution harder to audit and constrain.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Using npx skills add https://github.com/barneyjm/camino-skills installs code from a remote source without a pinned version or commit, creating a supply-chain risk. A later change to the package or repository could silently alter what gets installed and executed by users or agents.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill-specific npx skills add command also references an unpinned remote repository, so the installed skill content may change over time without review. This makes reproducibility and trust difficult and exposes consumers to supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

npx clawhub@latest install camino-ev-charger pulls the latest published package version at runtime, which can introduce unreviewed code changes. In an agent context, this is a meaningful supply-chain risk because the installer may gain execution before the user can inspect its behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
curl -s -X GET \
    -H "X-API-Key: $CAMINO_API_KEY" \
    -H "X-Client: claude-code-skill" \
    "https://api.getcamino.ai/query?${QUERY_STRING}" | jq .

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ev-charger.sh (reported line 65)May include surrounding context.

sh
curl -s -X GET \
    -H "X-API-Key: $CAMINO_API_KEY" \
    -H "X-Client: claude-code-skill" \
    "https://api.getcamino.ai/query?${QUERY_STRING}" | jq .

Static analysis

No suspicious patterns detected.