QR

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only QR code guidance skill with no executable behavior or hidden access, though users should be mindful about analytics and sensitive data encoded in QR codes.

Safe to install as a QR guidance skill. Before publishing QR codes, review what is encoded, avoid exposing private WiFi or payment details unnecessarily, and provide notice when using scan analytics or short links that may track users.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The deployment guidance explicitly recommends scan tracking via UTM parameters or QR analytics platforms without any mention of notice, consent, retention, or minimizing collected data. In a QR deployment context, this can normalize privacy-invasive implementations that collect behavioral or location-linked scan data without appropriate disclosure, creating compliance and trust risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal