Back to skill

Security audit

Journey

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Camino API wrapper for journey planning, with ordinary but real privacy and supply-chain considerations.

Install only from a publisher and version you trust, avoid running installer commands with elevated privileges, and treat waypoint coordinates and purpose notes as data shared with Camino's hosted API. Store and rotate CAMINO_API_KEY like any other service credential.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Installation Commands Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises journey planning but the provided content shows external network access to a third-party API and dependence on an API key, while the actual planning logic is not present locally. This mismatch reduces transparency, making it easier for users or agents to authorize data transmission and privileged behavior they may not expect from the description alone.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The instructions tell users to place a long-lived API key into ~/.claude/settings.json, an agent configuration location that may be broadly accessible to the agent runtime and other skills. Storing secrets in shared config increases the blast radius if another skill, prompt injection, or local compromise gains config-file access.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Add your key to Claude Code:

Add to your ~/.claude/settings.json:

json
{

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly relies on shell execution via curl/jq but does not declare any tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and can cause the agent runtime to grant broader execution capability than the skill documentation makes explicit.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Using npx skills add https://github.com/barneyjm/camino-skills without a pinned version or commit causes installation to trust whatever code is served at install time. That creates a supply-chain risk where a future repository change or compromise could deliver malicious skill content to users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill-specific install command still references a mutable remote repository without pinning a version or commit. Even if only one skill is selected, users remain exposed to repository compromise or silent behavioral changes over time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

npx clawhub@latest install camino-journey pulls the latest package version at execution time, which is mutable and can change unexpectedly. If the package or its dependencies are compromised, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

}'

text

### Via curl

```bash
curl -X POST -H "X-API-Key: $CAMINO_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

], "constraints": {"transport": "foot"} }'
"https://api.getcamino.ai/journey"

text

## Parameters

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends the full user-supplied journey JSON, including waypoint coordinates and free-text purposes, to a third-party API without any runtime disclosure or confirmation. In a travel-planning context this can expose sensitive location and itinerary data unexpectedly, creating privacy and compliance risk even if the transmission is necessary for the feature.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This curl invocation transmits unredacted user input to an external service using an API key, which means potentially sensitive travel data leaves the local environment. The issue is not the existence of the API call itself, but the lack of safeguards such as disclosure, consent, data minimization, and validation of what sensitive fields may be included.

Content

Scanner excerpt · scripts/journey.sh (reported line 46)May include surrounding context.

sh
fi

# Make API request
curl -s -X POST \
    -H "X-API-Key: $CAMINO_API_KEY" \
    -H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded remote endpoint confirms that all journey planning requests are sent to a third-party hosted service rather than processed locally. In this skill's context, that increases privacy risk because waypoint coordinates and itinerary metadata can reveal sensitive movement patterns, home/work locations, or travel plans.

Content

Scanner excerpt · scripts/journey.sh (reported line 51)May include surrounding context.

sh
-H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \
    -d "$INPUT" \
    "https://api.getcamino.ai/journey" | jq .

Static analysis

No suspicious patterns detected.