qr-code-generator

Warn

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The scripts/batch_generate.py script is vulnerable to path traversal. The id field from the input CSV is used directly to construct output file paths using os.path.join (lines 45-46) without sanitization, allowing an attacker to specify paths that write files outside the intended output directory.
  • [COMMAND_EXECUTION]: The scripts/batch_generate.py script uses subprocess.check_call to execute the companion script scripts/generate_qr.py. While the call uses an argument list to prevent shell injection, it executes commands with parameters derived from external CSV data.
  • [INDIRECT_PROMPT_INJECTION]: The skill's batch workflow in scripts/batch_generate.py processes external CSV data (URLs and labels) without boundary markers or specific isolation instructions, creating a surface where malicious instructions could be passed to the agent.
  • Ingestion points: Data is read from a CSV file path provided to scripts/batch_generate.py via the --csv argument (line 33).
  • Boundary markers: None identified for isolating or delimiting CSV input.
  • Capability inventory: Subprocess execution and local file system writes.
  • Sanitization: The skill implements URL validation and SVG text escaping, but lacks validation for the batch ID field used in file paths.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — qr-code-generator