Back to skill

Security audit

Advanced QR Intelligence

Security checks for vulnerabilities and agentic risk

Overview

This QR code skill does what it claims, with ordinary dependency and terminal-output cautions but no hidden or high-impact behavior found.

Install this only in a controlled Python environment, preferably with pinned dependency versions. Treat decoded QR text as untrusted, use JSON output when inspecting unfamiliar QR codes, and avoid running commands or opening links just because a decoded QR payload suggests them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned Third-Party Dependencies Allow Unreviewed Package Updates

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18-28
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

markdown
### For Generation

```bash
pip install qrcode pillow

For Reading

bash
pip install pillow pyzbar
text

### Technical Analysis

The installation instructions request third-party packages by name without pinning their versions or verifying package hashes. Consequently, each installation may retrieve different package releases from the configured Python package index. The installed code has not necessarily been reviewed alongside this Skill and can change after the Skill itself has been audited.

This does not establish that the named packages are currently malicious. However, it creates a supply-chain exposure: compromise of a publisher account, malicious future releases, package-index compromise, or unsafe index configuration could cause users to install attacker-controlled code. Python packages may execute code during installation or when imported by `scripts/qr_generate.py` and `scripts/qr_read.py`.

### Attack Path

1. An attacker compromises a dependency publisher, distribution channel, or package-index configuration used by the victim.
2. The attacker publishes or serves a malicious release under one of the dependency names.
3. A user follows the documented command, such as `pip install qrcode pillow`, without a version or hash constraint.
4. The package installer resolves the attacker-controlled release.
5. Malicious code executes during installation or when the scripts import the installed package.

### Impact Assessment

Malicious dependency code would generally execute with the privileges of the user running `pip` or invoking the QR scripts. It could access that user's files, environment variables, credentials, and network resources, and could modify data available to the process. If installation is performed with ad
...[truncated 142 chars]
Remediation
View remediation

Remediation Suggestions

  • Define reviewed dependency versions in a lock file or requirements file rather than installing unconstrained package names.

  • Pin exact versions and include cryptographic hashes, then install them with a command such as:

    bash
    pip install --require-hashes -r requirements.txt
    
  • Generate and review the hashes from trusted package artifacts.

  • Use an isolated virtual environment and avoid installing dependencies with administrative privileges.

  • Periodically scan and deliberately update pinned dependencies rather than accepting new releases automatically.

  • If organizational infrastructure is available, retrieve dependencies from a controlled package mirror containing approved artifacts.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/qr_read.py:80
Finding

Attacker-Controlled QR Payloads Are Written to the Terminal Without Control-Character Sanitization

Content
View full analysis

Vulnerability Details

File Location: scripts/qr_read.py, lines 80-85
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Low

Vulnerable Code

python
else:
    if args.all:
        for i, r in enumerate(results, 1):
            print(f"[{i}] {r['data']}")
    else:
        print(results[0]['data'])

The displayed value originates from decoded QR bytes at lines 44-46:

python
result = {
    # FIX: Use errors='replace' to prevent crashes on non-UTF8 payloads
    'data': obj.data.decode('utf-8', errors='replace'),

Technical Analysis

QR payloads are untrusted, attacker-controlled data. UTF-8 decoding with errors='replace' handles malformed byte sequences, but it does not remove ASCII control characters or terminal escape sequences. The plain-text output path passes the decoded value directly to print().

When the script runs in an interactive terminal, a crafted payload containing ANSI or other supported terminal control sequences may be interpreted by the terminal instead of being rendered as inert text. Depending on terminal capabilities and configuration, such sequences can alter colors, move the cursor, clear or overwrite visible output, manipulate the window title, or create misleading terminal content. More severe effects would depend on a separate vulnerability or unsafe feature in the terminal emulator and are not established by this code alone.

The JSON path is less exposed because json.dumps() escapes control characters, but the default plain-text output and the --all plain-text output remain unsafe.

Attack Path

  1. An attacker creates a QR code whose payload includes terminal escape or control sequences.
  2. The attacker convinces a user to save or scan the crafted image with scripts/qr_read.py.
  3. pyzbar decodes the payload and the script converts it to a string without removing terminal control characters.
  4. The default outpu ...[truncated 726 chars]
Remediation
View remediation

Remediation Suggestions

  • Escape non-printable characters before writing decoded data to an interactive terminal.

  • Render control characters visibly, for example as \x1b, rather than emitting their raw byte values.

  • Consider making JSON output the default because json.dumps() escapes embedded control characters.

  • Keep an explicit raw-output option only when required for machine consumption, document its risks, and avoid sending raw output to a terminal.

  • A defensive plain-text formatter can be implemented as follows:

    python
    import unicodedata
    
    def terminal_safe(value: str) -> str:
        return ''.join(
            ch if ch in '\n\t' or not unicodedata.category(ch).startswith('C')
            else f'\\u{ord(ch):04x}'
            for ch in value
        )
    
  • Apply the formatter to both print(f"[{i}] {r['data']}") and print(results[0]['data']).

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk implements only QR code generation. It accepts text/URL input, configures QR error correction and sizing, and saves the generated QR image to a specified file path. There is no functionality for loading image files, scanning screenshots, or decoding existing QR codes. Therefore, the declared description overstates the skill's capabilities by claiming both generation and reading/decoding support. While PNG/JPG output may be partially possible depending on the imaging backend and output filename, the explicit decoding/read capability is clearly absent, making this a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code chunk implements only QR-code reading/decoding from image files. It opens an image, decodes QR symbols, and outputs decoded data plus metadata. There is no functionality to generate QR codes, no handling of text/URL input for creation, and no image output production. The reading portion of the description is accurate, but the overall declared purpose overstates the skill by claiming generation capabilities that are absent from the provided code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.