extension-qr-code
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external QR codes via the device camera, which is then processed by the agent. This content is untrusted and could contain adversarial instructions intended to bypass agent safety filters or manipulate its behavior.
- Ingestion points: The
dataproperty in theQRResultinterface (located in@caffeinelabs/qr-code/src/hooks/useQRScanner.ts) contains the decoded string from the scanned QR code. - Boundary markers: There are no specific delimiters or instruction-isolation markers implemented in the example usage to differentiate scanned content from agent instructions.
- Capability inventory: While this specific skill focuses on scanning, the agent context in which it operates may have access to tools for file manipulation, network requests, or code execution.
- Sanitization: The implementation does not show any sanitization or validation of the decoded QR string before it is presented to the agent context.
- [EXTERNAL_DOWNLOADS]: The skill is configured to download external software at runtime to perform its primary function.
- Evidence: The
QRScannerConfiginterface in@caffeinelabs/qr-code/src/hooks/useQRScanner.tsidentifies a default behavior of loading thejsQRlibrary from the jsdelivr CDN. - [DYNAMIC_EXECUTION]: The scanner hook supports loading and executing JavaScript from a path that can be dynamically determined at runtime.
- Evidence: The
jsQRUrlparameter in theuseQRScannerhook allows the library loading path to be set via configuration, representing a dynamic loading pattern from a computed path.
Audit Metadata