Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The examples explicitly include sensitive payloads such as WiFi credentials and vCard contact data, but the skill provides no warning that generated QR codes may expose secrets to anyone who can view, scan, or receive the image. In an agent setting, this is riskier because the agent is instructed to display generated files, which can unintentionally surface confidential information in chat transcripts or shared workspaces.
