QRCode

Security checks across malware telemetry and agentic risk

Overview

This is a QR-code generator whose behavior matches its purpose, with the main caution that generated QR images and filenames can reveal sensitive data if users encode it.

Install this for ordinary QR-code generation if you are comfortable running its npm dependencies. Avoid encoding real secrets unless you intend the QR image, chat preview, workspace file, and possibly the default filename to be visible; use an explicit neutral output filename for private payloads.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The examples explicitly include sensitive payloads such as WiFi credentials and vCard contact data, but the skill provides no warning that generated QR codes may expose secrets to anyone who can view, scan, or receive the image. In an agent setting, this is riskier because the agent is instructed to display generated files, which can unintentionally surface confidential information in chat transcripts or shared workspaces.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal