qr-code-generator
Warn
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The
scripts/batch_generate.pyscript is vulnerable to path traversal. Theidfield from the input CSV is used directly to construct output file paths usingos.path.join(lines 45-46) without sanitization, allowing an attacker to specify paths that write files outside the intended output directory. - [COMMAND_EXECUTION]: The
scripts/batch_generate.pyscript usessubprocess.check_callto execute the companion scriptscripts/generate_qr.py. While the call uses an argument list to prevent shell injection, it executes commands with parameters derived from external CSV data. - [INDIRECT_PROMPT_INJECTION]: The skill's batch workflow in
scripts/batch_generate.pyprocesses external CSV data (URLs and labels) without boundary markers or specific isolation instructions, creating a surface where malicious instructions could be passed to the agent. - Ingestion points: Data is read from a CSV file path provided to
scripts/batch_generate.pyvia the--csvargument (line 33). - Boundary markers: None identified for isolating or delimiting CSV input.
- Capability inventory: Subprocess execution and local file system writes.
- Sanitization: The skill implements URL validation and SVG text escaping, but lacks validation for the batch ID field used in file paths.
Audit Metadata