Back to skill

Security audit

Wifi Qr

Security checks across malware telemetry and agentic risk

Overview

This skill is a small Wi-Fi QR-code helper whose sensitive password handling is expected for its purpose, with no evidence of hidden behavior.

Install qrencode only from a trusted package manager. Treat the QR code, saved images, screenshots, terminal history, and command examples containing the password as sensitive; use a guest network when possible and delete or protect generated QR outputs after use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to generate a QR code containing Wi-Fi credentials but does not warn that the resulting code effectively exposes the network password to anyone who can view, capture, or retain the code. In this context, omission of that warning can lead to accidental credential disclosure through screenshots, terminal history, shared screens, or saved image files.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.