Back to skill

Security audit

Travel Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward travel-planning API wrapper, with expected external sharing of entered waypoints and an API key but no hidden persistence or deceptive behavior found.

Install only from a source and version you trust, preferably a pinned release or reviewed commit. Use this skill only for itineraries you are comfortable sending to Camino's API, and store CAMINO_API_KEY as a normal environment variable or in your agent settings only if you accept that local configuration choice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party Installation Sources Permit Supply-Chain Substitution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Add your key to Claude Code:

Add to your ~/.claude/settings.json:

json
{

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents shell-based capabilities (curl, jq, local scripts) but does not declare an explicit tool scope such as permissions or allowed-tools. This creates a mismatch between what the skill can cause an agent to do and what is transparently constrained, increasing the risk of unintended command execution or overbroad tool use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Using npx skills add https://github.com/barneyjm/camino-skills installs remote code/content without pinning to a specific commit, tag, or version. If the upstream package or repository changes, users may fetch malicious or unexpected content through a supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill-specific install command still references a mutable GitHub source via npx skills add ... --skill camino-travel-planner without pinning. This leaves consumers exposed to repository changes or tampering that could alter the installed skill after publication.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

npx clawhub@latest install camino-travel-planner explicitly requests the latest version, which is mutable and can introduce unreviewed code at install time. This is a classic supply-chain risk because the fetched package behavior may change between executions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

}'

text

### Via curl

```bash
curl -X POST -H "X-API-Key: $CAMINO_API_KEY" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends user-supplied itinerary data, including waypoint coordinates and trip details, to a third-party API without any explicit disclosure, consent prompt, or redaction step. In a travel-planning context, location and itinerary data can be sensitive and reveal movement patterns, making undisclosed transmission a real privacy issue even though it appears necessary for the feature.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This curl invocation transmits the full JSON input to an external service, which includes user waypoint and travel-planning data. While external transmission is functionally expected for a route optimization skill, it is still a genuine privacy/security concern because the script performs no data minimization, consent check, or destination validation beyond a hardcoded endpoint.

Content

Scanner excerpt · scripts/travel-planner.sh (reported line 46)May include surrounding context.

sh
fi

# Make API request
curl -s -X POST \
    -H "X-API-Key: $CAMINO_API_KEY" \
    -H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
-H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \
    -d "$INPUT" \
    "https://api.getcamino.ai/journey" | jq .

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/travel-planner.sh (reported line 51)May include surrounding context.

sh
-H "Content-Type: application/json" \
    -H "X-Client: claude-code-skill" \
    -d "$INPUT" \
    "https://api.getcamino.ai/journey" | jq .

Static analysis

No suspicious patterns detected.