extension-qr-code

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external QR codes via the device camera, which is then processed by the agent. This content is untrusted and could contain adversarial instructions intended to bypass agent safety filters or manipulate its behavior.
  • Ingestion points: The data property in the QRResult interface (located in @caffeinelabs/qr-code/src/hooks/useQRScanner.ts) contains the decoded string from the scanned QR code.
  • Boundary markers: There are no specific delimiters or instruction-isolation markers implemented in the example usage to differentiate scanned content from agent instructions.
  • Capability inventory: While this specific skill focuses on scanning, the agent context in which it operates may have access to tools for file manipulation, network requests, or code execution.
  • Sanitization: The implementation does not show any sanitization or validation of the decoded QR string before it is presented to the agent context.
  • [EXTERNAL_DOWNLOADS]: The skill is configured to download external software at runtime to perform its primary function.
  • Evidence: The QRScannerConfig interface in @caffeinelabs/qr-code/src/hooks/useQRScanner.ts identifies a default behavior of loading the jsQR library from the jsdelivr CDN.
  • [DYNAMIC_EXECUTION]: The scanner hook supports loading and executing JavaScript from a path that can be dynamically determined at runtime.
  • Evidence: The jsQRUrl parameter in the useQRScanner hook allows the library loading path to be set via configuration, representing a dynamic loading pattern from a computed path.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:05 PM
Security Audit — agent-trust-hub — extension-qr-code