skills/qverisai/qverisbot/camsnap/Gen Agent Trust Hub

camsnap

Warn

Audited by Gen Agent Trust Hub on Mar 6, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the camsnap tool via a Homebrew formula from a personal repository (steipete/tap/camsnap), which is not included in the trusted vendors list.
  • [COMMAND_EXECUTION]: The camsnap watch command includes an --action flag designed to execute arbitrary shell commands when motion is detected. This capability could be exploited for command injection or persistence if malicious actions are configured.
  • [CREDENTIALS_UNSAFE]: Setup instructions demonstrate passing camera credentials as plaintext command-line arguments (--user and --pass), which risks exposure in shell history and process lists.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 6, 2026, 01:22 AM