Back to skill

Security audit

QR Code Tool

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward QR-code helper, with ordinary dependency and credential-sharing cautions but no hidden or mismatched behavior.

Install dependencies in an isolated Python environment and avoid elevated privileges. Use WiFi QR codes only for guest or intentionally shared networks, because the QR image contains the password in recoverable form.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:166
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 166-170
Vulnerability Type: Unpinned and unverifiable third-party package installation
Risk Level: Medium

Vulnerable Code

bash
pip install qrcode[pil]

Technical Analysis

The installation command retrieves the latest compatible qrcode package and its optional Pillow dependency from the configured Python package index without pinning reviewed versions or verifying cryptographic hashes. No lockfile, hash constraints, or trusted-index requirements are provided.

Consequently, the dependency code installed by this command may differ from the code reviewed when the Skill was published. If a dependency release, maintainer account, package-index account, or configured package source is compromised, following this instruction could install attacker-controlled package code. Python packages may execute build logic during installation and arbitrary code when imported or used.

This finding is limited to supply-chain exposure caused by the unpinned installation instruction. The audited file does not itself retrieve a remote executable payload, contain embedded malicious scripts, establish persistence, access credential files, or alter Agent instructions.

Attack Path

  1. An attacker compromises a relevant package release, maintainer account, dependency, or package source configured in the victim's environment.
  2. The attacker publishes a malicious version that remains compatible with the unconstrained pip install qrcode[pil] requirement.
  3. A user or Agent follows the installation instruction in SKILL.md.
  4. pip resolves and downloads the attacker-controlled package or transitive dependency because no reviewed version or hash is enforced.
  5. Malicious code executes during package build or installation, or later when the QR-generation examples import and use the package.
  6. The code runs with the privileges of the account performing the installation or executing the example ...[truncated 569 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a specifically reviewed version, for example through a version-controlled requirements file.
  2. Generate and enforce cryptographic hashes using a reproducible dependency-management workflow, such as pip-compile --generate-hashes followed by pip install --require-hashes.
  3. Pin and verify all transitive dependencies, including Pillow, rather than relying only on an unconstrained package extra.
  4. Install exclusively from an explicitly approved HTTPS package index or an internally controlled package mirror.
  5. Review package provenance, release history, maintainers, and known vulnerabilities before updating pinned versions.
  6. Perform dependency updates through a controlled review process with automated vulnerability and integrity scanning.
  7. Use an isolated virtual environment and avoid installation with root or other elevated privileges.

A hardened installation pattern is:

bash
python -m pip install --require-hashes -r requirements.txt

The associated requirements.txt should contain reviewed, exact versions and hashes for every resolved dependency.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes an example that encodes a WiFi SSID and password directly into a QR code and even states 'Scan to auto-connect to WiFi' without warning that anyone who can view, copy, or reprint the code can recover and reuse the credential. In this skill context, the omission is meaningful because the documented use case explicitly encourages sharing network access, which can lead users to expose production or home WiFi credentials more broadly than intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.