Back to skill

Security audit

Hotel Finder

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent hotel-search skill, but users should know it sends search and optional location data to Camino and its install examples are not pinned.

Install only the specific skill from a trusted, pinned version when possible. Avoid putting sensitive travel plans or exact coordinates into queries unless you are comfortable sending them to Camino, and protect the CAMINO_API_KEY like any other API credential.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Remote Dependencies in Installation Commands

Content
View full analysis
Remediation
View remediation
install camino-hotel-finder ``` 2. Pin GitHub installations to a specific reviewed commit hash or signed release tag rather than the repository's mutable default branch. 3. Use package integrity hashes, lockfiles, or registry provenance verification where supported. 4. Install only `camino-hotel-finder` by default instead of all skills in the repository. 5. Document the expected package version and repository commit so users can verify what will be installed. 6. Prefer signed releases and verify signatures or checksums before executing downloaded installation tooling. 7. Periodically review and deliberately update pinned versions rather than resolving new upstream code automatically. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/hotel-finder.sh:47
Finding

URL Query-Parameter Injection Through Unvalidated Optional Fields

Content
View full analysis
Remediation
View remediation
/dev/null <<<"$INPUT"; then echo "Error: lat, lon, radius, and limit must be numeric" >&2 exit 1 fi ``` 2. Enforce semantic ranges, including: - Latitude: `-90` through `90`. - Longitude: `-180` through `180`. - Radius: a positive integer within an API-approved maximum. - Limit: an integer from `1` through `100`, as documented. 3. Reject fractional values for integer fields and reject non-finite numeric representations if the parser permits them. 4. URI-encode every value rather than only the `query` field. 5. Prefer `curl --get --data-urlencode` so `curl` safely constructs the query string: ```bash curl -sS --fail-with-body --get \ -H "X-API-Key: $CAMINO_API_KEY" \ -H "X-Client: claude-code-skill" \ --data-urlencode "query=$QUERY" \ --data-urlencode "lat=$lat" \ --data-urlencode "lon=$lon" \ --data-urlencode "radius=$radius" \ --data-urlencode "limit=$limit" \ --data-urlencode "rank=true" \ --data-urlencode "answer=true" \ "https://api.getcamino.ai/query" ``` 6. Add regression tests using values containing `&`, `=`, whitespace, arrays, objects, booleans, negative values, and values outside the documented ranges. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Add your key to Claude Code:

Add to your ~/.claude/settings.json:

json
{

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly instructs users to run shell commands and shell scripts, but it does not declare any explicit tool scope such as allowed-tools or permissions. This increases the chance that an agent may invoke shell capabilities more broadly than intended, reducing containment and making misuse or accidental command execution more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Using npx skills add https://github.com/barneyjm/camino-skills without a pinned version or commit allows the installed content to change over time. If the upstream package or repository is compromised, users may fetch and run altered skill definitions or code without noticing.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill-specific npx skills add command still references a mutable GitHub source without pinning to a version or commit. This creates a supply-chain risk because future repository changes could alter what gets installed and executed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

npx clawhub@latest install camino-hotel-finder pulls the latest package version at execution time, which is a mutable supply-chain dependency. A compromised or malicious newly published version could be executed by users immediately.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill transmits user-provided search queries and optional location data to https://api.getcamino.ai/query, which is an external network destination. In this context that behavior is core to the skill, but it still creates privacy and data-handling risk because travel intent and exact coordinates may be sent off-box.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

bash
curl -H "X-API-Key: $CAMINO_API_KEY" \
  "https://api.getcamino.ai/query?query=hotels+near+the+Eiffel+Tower&limit=5&rank=true&answer=true"

Parameters

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script transmits the user's free-text query and optional latitude/longitude to a third-party service, which can expose sensitive location or travel-intent data without any runtime disclosure or consent mechanism. In a skill context, users may not realize their inputs are leaving the local agent environment and being sent to an external vendor.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This skill performs an external network request to Camino's API containing user-supplied search text and optional location parameters. While expected for a hotel-finder integration, it still creates a privacy and data-handling risk because potentially sensitive travel and location information is transmitted to a third party.

Content

Scanner excerpt · scripts/hotel-finder.sh (reported line 72)May include surrounding context.

sh
curl -s -X GET \
    -H "X-API-Key: $CAMINO_API_KEY" \
    -H "X-Client: claude-code-skill" \
    "https://api.getcamino.ai/query?${QUERY_STRING}" | jq .

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends natural-language hotel queries and potentially precise coordinates to an external Camino API, but the description does not prominently warn users about that data flow. This can expose location preferences, travel plans, or sensitive itinerary information without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.