Back to skill

Security audit

QR Code Generator

Security checks for vulnerabilities and agentic risk

Overview

This QR-code skill appears useful and not malicious, but it automatically installs an unpinned Python package at runtime and handles WiFi passwords through command-line arguments.

Review before installing. Use this only in an isolated or controlled Python environment, preinstall and pin qrcode[pil] yourself, and avoid putting real WiFi passwords directly on the command line. There is no evidence of malicious exfiltration or persistence, but the dependency-install behavior is too broad for automatic approval.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/generate_qr.py:8
Finding

Automatic Installation of an Unpinned Runtime Dependency

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_qr.py, lines 8-15
Vulnerability Type: Supply-chain risk caused by automatic installation of an unpinned dependency
Risk Level: High

Vulnerable Code

python
def ensure_qrcode():
    try:
        import qrcode
        return qrcode
    except ImportError:
        import subprocess
        subprocess.check_call([sys.executable, "-m", "pip", "install", "qrcode[pil]", "-q"])
        import qrcode
        return qrcode

The behavior is also explicitly documented in SKILL.md, lines 56-59:

markdown
## Dependencies

The script auto-installs `qrcode[pil]` via pip if missing. No manual setup needed.

Technical Analysis

If the qrcode module is unavailable, the script invokes pip and installs qrcode[pil] from the package source configured in the runtime environment. The requested dependency has no fixed version, integrity hash, lock file, or trusted repository constraint.

Python package installation may execute package-controlled build or installation logic. Consequently, the effective code executed by the skill can change after review without any modification to the audited project. Relevant attack conditions include compromise of the legitimate package or its publishing account, unsafe package-index configuration, dependency resolution from an untrusted mirror, or malicious package substitution.

This is an insecure dependency-management pattern rather than evidence that the currently named package is malicious.

Attack Path

  1. The skill runs in an environment where qrcode is not installed.
  2. An attacker compromises or influences a package source used by pip, such as the configured index, mirror, or resolved package release.
  3. ensure_qrcode() catches ImportError.
  4. The script automatically executes:
    bash
    python -m pip install "qrcode[pil]" -q
    
  5. Pip downloads and installs mutab ...[truncated 696 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic dependency installation from normal program execution.
  2. Declare dependencies in a dedicated project manifest and lock file.
  3. Pin qrcode and its transitive dependencies to reviewed versions.
  4. Require package hashes during installation, such as through a hash-locked requirements file.
  5. Install dependencies during an explicit, controlled setup or build phase rather than when processing user requests.
  6. Restrict installation to an approved package index and validate repository configuration.
  7. Run dependency installation and QR generation inside a least-privileged virtual environment or sandbox.
  8. If the module is missing at runtime, fail safely with clear setup instructions instead of invoking pip automatically.
  9. Continuously scan pinned dependencies and update them through a reviewed release process.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_qr.py:41
Finding

WiFi Password Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_qr.py, lines 41-43
Vulnerability Type: Plaintext sensitive information exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

python
parser.add_argument("--wifi-ssid", help="Generate WiFi QR: SSID")
parser.add_argument("--wifi-pass", help="Generate WiFi QR: password")
parser.add_argument("--wifi-security", default="WPA", help="WiFi security type (default: WPA)")

The insecure invocation pattern is documented in SKILL.md, lines 20-23:

bash
python3 scripts/generate_qr.py "wifi" --wifi-ssid "MyNetwork" --wifi-pass "secret123" -o wifi.png

Technical Analysis

The interface accepts a WiFi password as the value of the --wifi-pass command-line option. Command-line arguments are not an appropriate secret transport mechanism because they may be recorded in shell history, terminal logs, process accounting, diagnostics, automation logs, or command telemetry. Depending on operating-system configuration, they may also be temporarily visible to other local processes through process-inspection facilities.

The script does not print the password directly, but the exposure occurs before the value reaches the application because the invoking shell and operating system process interface handle it as plaintext.

Attack Path

  1. A user follows the documented example and supplies a real WiFi password through --wifi-pass.
  2. The shell records the command in its history or an automation system records the full invocation.
  3. While the command is running, the argument may also be exposed through local process-inspection interfaces.
  4. A local user, support tool, log collector, backup reader, or other party with access to those records retrieves the plaintext password.
  5. The exposed credential is used to authenticate to the corresponding wireless network, subject to network reachability and any additional c ...[truncated 655 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace --wifi-pass with a hidden interactive prompt implemented through getpass.getpass().
  2. For non-interactive use, accept the password through standard input or a narrowly scoped file descriptor rather than a command-line argument.
  3. Do not use an environment variable as the primary replacement because environment data may also be exposed through diagnostics and process inspection.
  4. If file-based secret input is necessary, require restrictive permissions, avoid predictable temporary files, and delete temporary material promptly.
  5. Update SKILL.md so no example places a real password directly on the command line.
  6. Display a clear warning if the legacy --wifi-pass option is retained temporarily, then deprecate and remove it.
  7. Ensure the password is never printed, logged, included in exceptions, or retained longer than required to construct the QR payload.
  8. Advise affected users to remove exposed commands from shell and automation histories and rotate any password previously supplied through this interface.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented behavior omits a significant capability: runtime dependency installation via pip, which can trigger network access and arbitrary package retrieval at execution time. That creates a larger trust and supply-chain attack surface than users would expect from a simple local QR generator, and the mismatch also means operators may approve or route the skill under false assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A QR generation utility should not need to modify the host environment by installing software during execution. In this skill context, the behavior is especially suspicious because the declared purpose is simple content encoding, yet the code silently fetches and installs packages, creating unnecessary remote code and package-trust risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using subprocess-based pip installation at runtime is unjustified for the stated functionality and exposes users to unreviewed package retrieval during normal tool execution. Even if the package name is fixed, this still creates avoidable supply-chain and integrity risks and violates least surprise for a utility that should only generate local QR output.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises executable behavior that can write files and invoke shell commands, but it declares no explicit tool scope or permission boundaries. In an agent environment, that increases the chance the skill is invoked with broader capabilities than intended and makes review, sandboxing, and policy enforcement harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to use the skill when the user wants to generate QR codes from 'any data' or 'produce any scannable barcode image.' These phrases are broader than the actual QR-focused functionality and lack constraints or negative examples, which could cause unintended invocation on generic barcode or data-formatting requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation encourages placing WiFi credentials directly on the command line without warning that shell histories, process listings, logs, or agent traces may capture the password. In this context, the skill handles exactly the kind of sensitive secret that can be unintentionally exposed through normal operational telemetry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script silently installs a package without warning or user confirmation, which is unsafe even if done for convenience. This can change the execution environment unexpectedly, trigger network access, and conceal security-relevant behavior from users or calling systems that expect a non-mutating QR generation tool.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The script invokes pip at runtime via subprocess to install a package automatically when import fails. This is dangerous because it performs network-dependent code installation and execution in the user's environment without explicit consent, expanding the attack surface to package supply-chain compromise, dependency confusion, or environment tampering.

Content

Scanner excerpt · scripts/generate_qr.py (reported line 14)May include surrounding context.

python
return qrcode
    except ImportError:
        import subprocess
        subprocess.check_call([sys.executable, "-m", "pip", "install", "qrcode[pil]", "-q"])
        import qrcode
        return qrcode

Static analysis

No suspicious patterns detected.