qr-code-generator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
batch_generate.pyscript executes the companiongenerate_qr.pyscript usingsubprocess.check_call. The implementation correctly uses a list-based argument structure rather than a shell string, which is a secure practice that prevents shell injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from CSV files for its batch generation feature. It incorporates the following security controls:
- Ingestion points: Data including IDs, URLs, and labels are read from a CSV file in
batch_generate.py. - Boundary markers: The workflow instructions include a step to validate URLs before generation.
- Capability inventory: The skill possesses file-writing capabilities (
PathWriteandPIL.save) and local command execution capabilities (subprocess.check_call). - Sanitization: The
validate_urlfunction ensures destination links use http/https and contain a domain, whileEscapeXMLsanitizes caption labels to prevent injection in SVG output files. - [SAFE]: The project dependencies (
qrcode,pillow) are standard, reputable packages for image and QR code generation. The skill does not attempt to access sensitive system directories, perform network exfiltration, or maintain persistence.
Audit Metadata