T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party Installation Sources Permit Supply-Chain Substitution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward travel-planning API wrapper, with expected external sharing of entered waypoints and an API key but no hidden persistence or deceptive behavior found.
Install only from a source and version you trust, preferably a pinned release or reviewed commit. Use this skill only for itineraries you are comfortable sending to Camino's API, and store CAMINO_API_KEY as a normal environment variable or in your agent settings only if you accept that local configuration choice.
SKILL.md:12Unpinned Third-Party Installation Sources Permit Supply-Chain Substitution
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Add your key to Claude Code:
Add to your ~/.claude/settings.json:
{
The skill documents shell-based capabilities (curl, jq, local scripts) but does not declare an explicit tool scope such as permissions or allowed-tools. This creates a mismatch between what the skill can cause an agent to do and what is transparently constrained, increasing the risk of unintended command execution or overbroad tool use.
Using npx skills add https://github.com/barneyjm/camino-skills installs remote code/content without pinning to a specific commit, tag, or version. If the upstream package or repository changes, users may fetch malicious or unexpected content through a supply-chain compromise.
The skill-specific install command still references a mutable GitHub source via npx skills add ... --skill camino-travel-planner without pinning. This leaves consumers exposed to repository changes or tampering that could alter the installed skill after publication.
npx clawhub@latest install camino-travel-planner explicitly requests the latest version, which is mutable and can introduce unreviewed code at install time. This is a classic supply-chain risk because the fetched package behavior may change between executions.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}'
### Via curl
```bash
curl -X POST -H "X-API-Key: $CAMINO_API_KEY" \
The script sends user-supplied itinerary data, including waypoint coordinates and trip details, to a third-party API without any explicit disclosure, consent prompt, or redaction step. In a travel-planning context, location and itinerary data can be sensitive and reveal movement patterns, making undisclosed transmission a real privacy issue even though it appears necessary for the feature.
This curl invocation transmits the full JSON input to an external service, which includes user waypoint and travel-planning data. While external transmission is functionally expected for a route optimization skill, it is still a genuine privacy/security concern because the script performs no data minimization, consent check, or destination validation beyond a hardcoded endpoint.
fi
# Make API request
curl -s -X POST \
-H "X-API-Key: $CAMINO_API_KEY" \
-H "Content-Type: application/json" \
-H "X-Client: claude-code-skill" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
-H "Content-Type: application/json" \
-H "X-Client: claude-code-skill" \
-d "$INPUT" \
"https://api.getcamino.ai/journey" | jq .
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
-H "Content-Type: application/json" \
-H "X-Client: claude-code-skill" \
-d "$INPUT" \
"https://api.getcamino.ai/journey" | jq .
No suspicious patterns detected.