camsnap
Warn
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's installation metadata requires a third-party Homebrew tap ('steipete/tap/camsnap'). This involves downloading and installing an executable binary from a repository not managed by the skill platform or an officially whitelisted vendor.
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands using the 'camsnap' binary. This includes discovery, snapshots, and video clipping, which grant the agent operational control over local hardware/network resources.
- [DATA_EXFILTRATION]: The skill references a sensitive local path ('~/.config/camsnap/config.yaml') used for storing RTSP and ONVIF credentials. The setup instructions also demonstrate passing plaintext passwords via command-line arguments, which can leave secrets in shell history.
Audit Metadata