Back to skill

Security audit

QR

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only QR code guidance skill with one minor disclosure gap around WiFi QR passwords.

Before using the WiFi QR pattern, use it only for intended guest or public networks, not sensitive internal networks, and rotate the password when access should end. The skill otherwise appears to be static QR guidance with no executable behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The markdown includes a WiFi QR payload with a password field and presents it as suitable for guest networks, cafes, retail, and events, but it does not warn that QR codes can expose network credentials to anyone who scans or views them. Because this file describes user-facing behavior involving sensitive access data, a disclosure about credential exposure is expected.

Static analysis

No suspicious patterns detected.