Back to skill

Security audit

Camsnap

Security checks for vulnerabilities and agentic risk

Overview

The skill is a small, coherent camera-capture helper, but users should be careful with its third-party install source and command-line password example.

Install only if you trust the camsnap Homebrew tap and are comfortable giving the tool access to camera streams. Avoid typing real camera passwords directly into command examples; prefer an interactive prompt, protected config, or least-privileged camera account if the tool supports it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Executable Installed from a Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Supply-chain risk from an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

yaml
metadata: {"clawdbot":{"emoji":"📸","requires":{"bins":["camsnap"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/camsnap","bins":["camsnap"],"label":"Install camsnap (brew)"}]}}

Technical Analysis

The skill directs the environment to install the camsnap executable from the third-party Homebrew tap steipete/tap. The dependency is not pinned to an immutable version or commit, and the metadata does not require verification of a cryptographic checksum or signature.

Consequently, the executable installed later may differ from the artifact that existed when this skill was reviewed. Compromise of the tap, its upstream release process, or the formula can cause the installation process to retrieve and execute altered code. The project does not itself contain a malicious payload, so this is a dependency-integrity weakness rather than evidence of embedded malicious code.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, its formula repository, or the referenced upstream release channel.
  2. The attacker modifies the formula or release artifact to distribute a malicious camsnap executable.
  3. A user or agent loads the skill and follows its installation metadata.
  4. Homebrew retrieves and installs the mutable, attacker-controlled artifact.
  5. The installed binary executes with the privileges of the invoking user when the documented camsnap commands are run.

Impact Assessment

Successful exploitation permits arbitrary code execution under the account that installs or invokes camsnap. This may expose files readable by that account, camera configuration and credentials, captured images or video, and accessible local-network resources. The dependency declaration does not req ...[truncated 128 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin camsnap to an immutable, reviewed version or source commit rather than relying on the current state of a mutable tap.
  • Verify the downloaded artifact with a published cryptographic checksum or signature before installation.
  • Prefer a trusted official package source with reproducible releases and documented provenance.
  • Record the expected package version and integrity value in the skill metadata where supported.
  • Review updates before changing the pinned version, and use an isolated or least-privileged environment for camera tooling.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Camera Password Passed Through a Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Sensitive credential exposure through process arguments and command history
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- Add camera: `camsnap add --name kitchen --host 192.168.0.10 --user user --pass pass`

Technical Analysis

The documented setup pattern instructs users to provide a camera password through the --pass command-line argument. Although pass is an example placeholder rather than a hardcoded production secret, users following the documentation are likely to replace it with a real credential.

Command-line secrets can be retained in shell history, terminal or agent transcripts, command auditing systems, diagnostic logs, and automation records. Depending on the operating system and process-inspection policy, arguments may also be observable by other local users or monitoring software while the command is running. This creates credential exposure outside the intended camera configuration channel.

Attack Path

  1. A user follows the documented command and replaces pass with an actual camera password.
  2. The complete command is stored in shell history, an agent transcript, terminal logging, process telemetry, or another command-capture mechanism.
  3. A local user, operator, compromised process, or party with access to retained logs obtains the command.
  4. The attacker extracts the camera host, username, and password from the recorded arguments.
  5. The attacker authenticates to the camera or a related RTSP/ONVIF service, subject to network reachability and the privileges assigned to that camera account.

Impact Assessment

Exploitation can disclose camera credentials and permit access with the compromised camera account's privileges. Depending on that account's authorization, an attacker may view live feeds, retrieve recordings, alter camera configuration, or disrupt camera availability. The ...[truncated 158 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the command-line password example with an interactive hidden prompt that does not echo or retain the secret.
  • If supported, use an operating-system keychain, secret manager, protected file descriptor, or restricted credential file instead of process arguments.
  • Explicitly warn users not to enter real credentials in commands that may be retained in shell history, agent transcripts, or logs.
  • Ensure any credential file is created with owner-only permissions and is excluded from source control and diagnostic output.
  • Recommend a dedicated, least-privileged camera account and credential rotation if a password has already appeared in command history or logs.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.