Back to skill

Security audit

Advanced QR Intelligence

Security checks for vulnerabilities and agentic risk

Overview

This QR-code skill does what it claims at a modest scope: it generates QR images and reads QR contents from user-supplied image files.

Install in a virtual environment and consider pinning dependency versions if reproducibility matters. Be aware that the documented command paths may need adjustment because the scripts are packaged at the artifact root rather than under a scripts directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22–32
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable Code Snippet:

markdown
### For Generation

```bash
pip install qrcode pillow

For Reading

bash
pip install pillow pyzbar
text

### Technical Analysis

The installation instructions specify third-party packages without exact version constraints, cryptographic hashes, or a reviewed lock file. Consequently, package resolution depends on the mutable state of the configured Python package index at installation time.

This does not demonstrate that the named packages are currently malicious. However, it prevents users from obtaining a reproducible, previously reviewed dependency set. A compromised future release, compromised package index, or malicious package supplied through an incorrectly configured index could introduce attacker-controlled code. Python packages may execute code during installation, and their module-level initialization code runs when `qr_generate.py` or `qr_read.py` imports them.

### Attack Path

1. An attacker compromises a dependency release or controls a package index configured in the victim's environment.
2. The user follows the documented `pip install` commands.
3. `pip` resolves the uncontrolled package version or retrieves the package from the attacker-controlled index.
4. Attacker-controlled code executes during package installation or when the installed module is imported.
5. The malicious dependency operates with the permissions of the user running `pip` or the QR scripts.

### Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing or executing user's account. The accessible scope could include files, environment variables, credentials, network resources, and other data available to that account. If installation is performed with elevated pr
...[truncated 266 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define exact, reviewed dependency versions in a requirements file or lock file.

  2. Generate and verify cryptographic hashes for every package and transitive dependency.

  3. Install dependencies with hash enforcement, for example:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Configure an explicitly trusted package index and prevent unintended fallback to untrusted or internal indexes.

  5. Regularly scan and update pinned dependencies through a controlled review process.

  6. Install packages in an isolated virtual environment without administrative privileges.

  7. Document supported Python and system-library versions so dependency updates remain reproducible.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk implements only QR code generation: it accepts text/URL input, configures QR parameters, creates a QR image, and saves it to a specified file. There is no image-loading, screenshot-processing, or QR-decoding logic, and no decoder libraries are imported. Therefore, the declared description overstates the implemented behavior by including QR reading/decoding capabilities that are absent from the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk’s primary behavior is limited to decoding QR codes from an existing image path. It opens an image file, scans for QR codes, and prints either the first decoded payload or all results, optionally as JSON with bounding rectangle metadata. The declared description, however, claims the skill can both generate and read QR codes and specifically supports creating PNG/JPG output. None of the generation functionality appears in this code. The reading portion is consistent with the description, but the overall declared purpose materially overstates the implemented capabilities for this supplied code chunk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.