Back to skill

Security audit

PicSee URL Shortener & QR Codes (Web)

Security checks for vulnerabilities and agentic risk

Overview

The skill does the PicSee URL-shortening job it advertises, but its optional QR flow installs unpinned Python packages into a persistent local virtual environment and users should review that before installing.

Review this before installing. Use it only for URLs you are comfortable sending to PicSee, and avoid internal, private, authenticated, or tokenized links. The QR feature should be treated as higher risk because it can install Python packages locally; a safer version would pin dependencies, verify hashes, or use a constrained built-in QR generator.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:92
Finding

Unpinned Third-Party Packages Installed at Runtime

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 92–98
Vulnerability Type: Unpinned runtime dependencies
Risk Level: Medium

bash
# Check if venv exists, create if not
if [ ! -d ~/openclaw_python_venv ]; then
  python3 -m venv ~/openclaw_python_venv
  source ~/openclaw_python_venv/bin/activate
  pip install qrcode pillow
else
  source ~/openclaw_python_venv/bin/activate
fi

Technical Analysis

The Skill instructs the agent to install qrcode and pillow dynamically from the package index without pinning versions or verifying package hashes. Consequently, the installed artifacts are mutable and may differ from those available when the Skill was reviewed.

This creates a software supply-chain risk. If a package release, distribution account, package-index response, or transitive dependency is compromised, malicious installation or runtime code could execute under the agent user's account. The package names do not appear to be typosquatted, and the audited files contain no evidence that the author intentionally introduced malicious packages; the finding concerns missing dependency integrity controls.

Attack Path

  1. An attacker compromises a future release or distribution channel for qrcode, pillow, or one of their resolved dependencies.
  2. A user explicitly requests QR-code generation.
  3. If ~/openclaw_python_venv does not exist, the agent creates it and runs pip install qrcode pillow.
  4. pip resolves and downloads the currently available, unverified package artifacts.
  5. Malicious package installation logic can execute during installation; malicious library code can also execute when the subsequent Python QR-generation script imports the package.
  6. The payload runs with the permissions of the account executing the Skill.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the agent user's privileges. Depending on that account' ...[truncated 445 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every direct and transitive dependency to a reviewed version in a committed lock or requirements file.
  • Record cryptographic hashes and install with hash enforcement, for example:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  • Use an approved package repository or internally mirrored artifact source with provenance and integrity controls.
  • Prefer dependencies preinstalled and reviewed by the runtime instead of downloading packages during Skill execution.
  • Build the virtual environment during a controlled deployment phase rather than in response to a user request.
  • Run QR generation in a restricted environment with minimal filesystem and network access.
  • Regularly scan and update the locked dependencies through a documented review process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger language is broad enough to match common requests such as 'shorten URL' without clearly constraining when this skill should be invoked. Overbroad activation can cause unintended routing of user requests to this skill, increasing the chance that sensitive URLs are sent to a third-party service without sufficient user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill does not disclose that submitted URLs will be transmitted to PicSee, a third-party service, for processing and storage/analytics. Users may provide private, internal, tokenized, or sensitive links, and sending them externally can expose secrets, metadata, or business information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill goes beyond simple browser-based URL shortening and instructs the agent to create a local Python virtual environment, install packages, and write a file under /tmp. Expanding scope to local code execution and filesystem modification increases attack surface and creates unnecessary supply-chain and execution risk for a feature that could be handled by the remote service or a safer built-in mechanism.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.