Back to skill

Security audit

QR Code Generator & Reader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward QR code generator and reader with ordinary dependency and documentation caveats.

Install dependencies in a virtual environment, prefer pinned package versions if you need reproducibility, and note that the documented scripts/ command paths may need adjustment to the actual packaged file locations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22-28
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

bash
pip install qrcode pillow

For Reading

bash
pip install pillow pyzbar

Technical Analysis

The installation instructions specify third-party packages without fixed versions or cryptographic hashes. As a result, pip resolves mutable package releases from the user's configured package index at installation time. The installed code may therefore differ from the code that was reviewed.

This creates a supply-chain exposure if a package publisher account, package index, configured mirror, or future dependency release is compromised. Python packages may execute code during installation and are subsequently imported by qr_generate.py and qr_read.py, so a malicious package release could execute with the privileges of the user running the installation or scripts.

No evidence indicates that the named dependencies are currently malicious. The vulnerability is the absence of reproducible, integrity-verified dependency resolution.

Attack Path

  1. An attacker compromises a referenced package, its publisher account, or a package source used by the victim.
  2. The attacker publishes a malicious release under one of the referenced package names.
  3. A user follows the documented unpinned pip install commands.
  4. pip resolves and downloads the attacker-controlled release because no reviewed version or hash is enforced.
  5. Malicious code executes during package installation or when the package is imported by the QR scripts.

Impact Assessment

Successful exploitation could execute arbitrary code with the permissions of the user who installs or invokes the package. This may permit access to that user's files, credentials, environment variables, and network resources. If installation is performed with administrative privileges, the impact could extend to ...[truncated 107 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every direct dependency to a reviewed version rather than allowing unconstrained resolution.

  • Maintain a lock file that includes resolved transitive dependencies.

  • Require cryptographic hashes, such as through pip install --require-hashes -r requirements.txt.

  • Retrieve packages only from a trusted, explicitly configured package index or internal artifact repository.

  • Scan dependencies for known vulnerabilities and review updates before changing pinned versions.

  • Avoid privileged installation; use an isolated virtual environment with least-privilege permissions.

  • Example hardened workflow:

    bash
    python -m venv .venv
    . .venv/bin/activate
    python -m pip install --require-hashes -r requirements.txt
    
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is a description-behavior mismatch because the declared purpose presents the skill as both a QR generator and QR reader/decoder, while the code chunk only implements QR generation. There is no image parsing, barcode decoding, screenshot handling, or QR reading logic. The code's primary purpose is a subset of the declared description. Additionally, the interface explicitly labels the output as PNG, so the stated PNG/JPG output support is not demonstrated by this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk's primary purpose is QR code decoding from existing image files. That aligns with part of the description about reading QR codes from images/screenshots. However, the declared description also claims the skill can generate QR codes and support PNG/JPG output, which this code does not implement at all. There are no suspicious extra capabilities beyond decoding image files, but the declared functionality overstates what this code chunk actually does, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.