Qr Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward QR code generator, with the main caution that QR contents and saved image files can expose sensitive data if users choose to encode or share it.

Install is acceptable for normal use. Generate files in a working or temporary directory, do not encode passwords, tokens, private login links, or confidential internal URLs unless that sharing is approved, and review any separate Feishu sender skill before using the sharing example.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The documentation explicitly shows generating a QR code and sending it via Feishu, but it does not warn that QR payloads may encode sensitive data such as login URLs, access tokens, WiFi credentials, or internal links. This can normalize unsafe sharing practices and lead users to transmit secrets through chat platforms or leave sensitive QR images on disk where they may be exposed.

VirusTotal

No VirusTotal findings

View on VirusTotal