Back to skill

Security audit

invoice-qr-scanner

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned for invoice QR processing, but it can send sensitive company, tax, banking, and contact details to QR-derived websites without strong validation or clear user confirmation.

Review this skill carefully before installing. Only use it with trusted invoice QR codes, confirm the destination domain before any browser action, and require a final review before entering or submitting tax, bank, phone, or email data. Avoid storing bank account details in general memory unless you intentionally accept that cross-session retention.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:23
Finding

Untrusted QR URLs Can Receive Sensitive Invoice and Banking Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:23-53
Vulnerability Type: Unvalidated external URL navigation followed by sensitive-data submission
Risk Level: High

Vulnerable Instructions

text
### Step 2: Navigate to Invoice System

1. Open the decoded URL in browser automation
2. Verify the page loads successfully
3. Take snapshot to understand form structure

### Step 3: Retrieve Company Information

Before filling the form, retrieve the user's company information:

1. Check memory files for stored invoice header information:
   - Search `memory/YYYY-MM-DD.md` for recent invoice info
   - Check `MEMORY.md` for long-term stored details
2. Required fields typically include:
   - Company name (公司名称)
   - Tax ID/Unified Social Credit Code (税号)
   - Address (地址)
   - Phone number (电话)
   - Bank name (开户行)
   - Bank account number (银行账号)

### Step 4: Fill Invoice Form

1. Analyze the form structure using browser snapshot
2. Fill in company information fields
3. Fill in recipient information:
   - Phone number (手机号)
   - Email address (邮箱)
4. Verify all required fields are completed

Technical Analysis

The decoded QR value is treated as a navigable URL without a mandatory validation procedure. The workflow does not enforce:

  • An https:// scheme.
  • A trusted invoice-provider domain allowlist.
  • Rejection of embedded credentials, IP-address hosts, private network destinations, or nonstandard ports.
  • Validation of redirect destinations.
  • A binding between the expected invoice provider and the final page origin.
  • Explicit user approval before sensitive fields are entered.

After navigation, the Agent is instructed to infer the form structure and populate it with company identity, tax, bank-account, phone, and email information obtained from memory. A malicious page can imitate an invoice form and expose field labels that cause the Agent to enter this infor ...[truncated 1568 chars]

Remediation
View remediation

Remediation Suggestions

  1. Parse the decoded value as a URL and accept only canonical https:// URLs.
  2. Maintain an explicit allowlist of approved invoice-provider hostnames; do not rely on visual page appearance.
  3. Reject URLs containing credentials, IP-literal hosts, loopback destinations, link-local destinations, private-network destinations, nonstandard ports, and unsupported schemes.
  4. Validate every redirect and stop navigation if any redirect leaves the allowlist.
  5. Display the final normalized origin and requested fields to the user.
  6. Require explicit user confirmation immediately before entering or submitting tax, banking, phone, or email data.
  7. Use provider-specific field mappings instead of filling fields inferred solely from page labels.
  8. Minimize submitted data and omit bank information unless the selected trusted provider demonstrably requires it.
  9. Isolate browser automation from local services and private networks where feasible.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:31
Finding

Overbroad Retrieval and Persistent Storage of Sensitive Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:31-40, 68-70, 108-123
Vulnerability Type: Excessive collection and retention of sensitive information
Risk Level: Medium

Vulnerable Instructions

text
1. Check memory files for stored invoice header information:
   - Search `memory/YYYY-MM-DD.md` for recent invoice info
   - Check `MEMORY.md` for long-term stored details
2. Required fields typically include:
   - Company name (公司名称)
   - Tax ID/Unified Social Credit Code (税号)
   - Address (地址)
   - Phone number (电话)
   - Bank name (开户行)
   - Bank account number (银行账号)
text
### Missing Information

If required company or contact information is missing:
1. Ask user to provide the missing details
2. Update memory files with new information
3. Continue with the invoice application
text
## Memory Integration

This skill relies on stored user information in memory files:

**Company Invoice Header Information** (stored in MEMORY.md):
- Company name
- Tax ID
- Address
- Phone number
- Bank information

**Contact Information** (stored in MEMORY.md):
- Mobile phone numbers
- Email addresses

Technical Analysis

The workflow instructs the Agent to search general-purpose daily memory files and long-term memory rather than retrieving a narrowly scoped, structured invoice profile. These stores may contain unrelated information, creating a risk that excessive data will be collected while the Agent analyzes an external form.

The skill also directs the Agent to update memory whenever the user supplies missing information. No explicit consent requirement, retention period, deletion process, field-level access control, or prohibition against storing bank details is defined.

This is not evidence that attacker-controlled behavioral instructions are written into memory, so it is not classified as Agent Memory Poisoning. The issue is insecure handling and unne ...[truncated 1362 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace searches of general memory files with a dedicated, structured invoice-profile store.
  2. Retrieve only the specific field required by a verified form, rather than loading the complete profile.
  3. Do not inspect unrelated daily memory entries during invoice processing.
  4. Obtain explicit user consent before storing any newly supplied value.
  5. Do not persist bank-account information by default; request it per transaction when strictly necessary.
  6. Define retention periods, deletion controls, and a mechanism for users to inspect and correct stored data.
  7. Apply field-level access controls so invoice workflows cannot read unrelated memory content.
  8. Redact sensitive values from browser snapshots, diagnostic output, and activity logs.
  9. Present the exact fields and destination origin to the user before any external submission.

T08 · Insecure Dependencies

Note
Location
scripts/package.json:5
Finding

Mutable NPM Dependencies and Missing Lockfile Prevent Reproducible Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/package.json:5-8
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Low

Vulnerable Configuration

json
"dependencies": {
  "qrcode-reader": "^1.0.4",
  "canvas": "^2.11.2"
}

Related installation guidance in SKILL.md:99-102 permits dependency resolution during installation:

bash
cd scripts
npm install qrcode-reader canvas

No package lockfile is present in the audited project structure.

Technical Analysis

The caret version ranges allow npm to resolve newer compatible package releases. Without a committed package-lock.json, direct and transitive dependency versions can vary between installations. The documented command that installs packages by name also bypasses a frozen, reviewed dependency graph.

Consequently, the source tree alone does not identify the exact code that will be installed and executed. NPM packages may execute lifecycle scripts during installation, and native packages such as canvas add a significant binary and build-tool supply-chain surface.

The audit did not find evidence that the currently declared package names are typosquatted or intentionally malicious. The confirmed issue is the absence of reproducible dependency integrity controls.

Attack Path

  1. A user follows the documented installation instructions.
  2. npm resolves the mutable direct and transitive dependency graph from the configured registry.
  3. A future changed, compromised, or otherwise unsafe package version is selected because no reviewed lockfile fixes the graph.
  4. Package code or an installation lifecycle script executes with the privileges of the user running npm.
  5. The compromised dependency can affect installation or execute when scan-qr.js imports it.

Impact Assessment

If a resolved dependency is compromised, its installation scripts can execute with the npm user's privileges. Run ...[truncated 358 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin reviewed direct dependencies to exact versions instead of caret ranges.
  2. Generate, review, and commit package-lock.json.
  3. Use npm ci for deployment and automated installation so the lockfile is enforced.
  4. Remove documentation that recommends ad hoc npm install qrcode-reader canvas; direct users to the locked manifest.
  5. Review transitive dependencies and npm lifecycle scripts before release.
  6. Consider installation with lifecycle scripts disabled when compatible with the required native dependency build process.
  7. Run dependency vulnerability and provenance checks in continuous integration.
  8. Perform dependency upgrades through controlled pull requests that expose lockfile changes for review.
  9. Execute image processing with minimal filesystem and network privileges to reduce the impact of a compromised dependency.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The implemented behavior only covers generic QR-code extraction from an image path supplied on the command line. While this partially matches the 'scan QR codes from images' portion of the description, the main claimed workflow goes further: invoice receipt handling and automatic completion of electronic invoice applications. No code exists for parsing invoice fields, validating receipt/invoice content, interacting with an invoicing service, populating forms, browser automation, or network/API submission. Therefore the description materially overstates the skill's functionality and purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes a workflow that opens a QR-derived invoicing URL and automatically fills and submits a form. Because QR codes can encode attacker-controlled destinations, this can cause sensitive information to be sent to an untrusted external site or trigger unintended submissions without adequate user review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that the skill automatically reads company, tax, banking, phone, and email data from MEMORY.md and uses it to populate invoice forms. This creates a real privacy and data-handling risk because highly sensitive business and contact information may be accessed and transmitted to external invoicing sites without explicit per-use consent, minimization, or warning to the user.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 170)May include surrounding context.

  1. 跳过canvas安装(已全局安装或有其他方式)
  2. 或者安装系统依赖:
    bash
    sudo apt-get install libcairo2-dev libpango1.0-dev
    

Tested Platforms

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation text is broad enough to trigger on common invoice-related requests, not just narrowly on QR-scanning tasks. That can cause the agent to invoke a workflow that opens external URLs, fills forms, and handles sensitive tax/contact data in situations where the user may not have intended those actions, increasing the risk of overreach and unsafe automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to submit online forms and update persistent memory with company and contact information, but it does not require explicit user consent or provide a clear warning that data will be stored and external systems modified. In this context, the data includes sensitive business identifiers, banking details, phone numbers, and email addresses, so silent persistence or submission can create privacy, compliance, and integrity risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill documentation consistently specifies the workflow, examples, and user interactions in Chinese, including quoted user prompts and assistant behavior, without indicating that another language can be used. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified with a caret range, which allows newer minor/patch releases to be installed without review. This weakens build reproducibility and can unintentionally pull in a compromised or breaking upstream version through the supply chain.

Content

Scanner excerpt · scripts/package.json (reported line 6)May include surrounding context.

json
"version": "1.0.0",
  "description": "QR code scanner for invoice receipts",
  "dependencies": {
    "qrcode-reader": "^1.0.4",
    "canvas": "^2.11.2"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The canvas dependency is not pinned to an exact version, so installs may resolve to different releases over time. In a package that processes attacker-controlled image content, this increases supply-chain and reliability risk because vulnerable or malicious updates could be introduced implicitly.

Content

Scanner excerpt · scripts/package.json (reported line 7)May include surrounding context.

json
"description": "QR code scanner for invoice receipts",
  "dependencies": {
    "qrcode-reader": "^1.0.4",
    "canvas": "^2.11.2"
  }
}

Unverifiable Dependency: canvas has 2 known advisory(ies) (CVE-2020-8215 (Buffer overflow in canvas); GHSA-vpq5-4rc8-c222 (Denial of Service in canvas)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest references canvas without pinning an exact release, while known advisories exist for some canvas versions including buffer overflow and denial-of-service issues. Because this skill scans QR codes from user-supplied invoice images, a vulnerable image-processing library could be exposed to malicious inputs, increasing the chance of crashes or memory corruption during parsing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits status and error messages only in Chinese (错误, 识别成功, 未能识别二维码). That imposes a specific language on users without any opt-in or documented locale justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.