camsnap

Warn

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's installation metadata requires a third-party Homebrew tap ('steipete/tap/camsnap'). This involves downloading and installing an executable binary from a repository not managed by the skill platform or an officially whitelisted vendor.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands using the 'camsnap' binary. This includes discovery, snapshots, and video clipping, which grant the agent operational control over local hardware/network resources.
  • [DATA_EXFILTRATION]: The skill references a sensitive local path ('~/.config/camsnap/config.yaml') used for storing RTSP and ONVIF credentials. The setup instructions also demonstrate passing plaintext passwords via command-line arguments, which can leave secrets in shell history.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 9, 2026, 10:44 PM
Security Audit — agent-trust-hub — camsnap