qr-code-generator
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection (LOW): The skill processes untrusted input from users and external data sources which could be used to embed malicious instructions.
- Ingestion points: Processes
URLandlabel/caption textfrom user input, and data fromCSVfiles during batch generation. - Boundary markers: The workflow mentions URL validation (scheme + domain) but lacks specific boundary markers or sanitization for caption labels which are reflected in the output.
- Capability inventory: Executes local Python scripts (
scripts/generate_qr.py,scripts/batch_generate.py) and performs file-write operations for PNG and SVG exports. - Sanitization: Includes basic URL validation, but no explicit sanitization for label text or CSV content is mentioned.
- Command Execution (SAFE): The skill utilizes local Python scripts for its primary logic. No patterns indicating arbitrary command execution, shell spawning, or unsafe
subprocesscalls were found in the skill definition. - External Downloads (SAFE): No remote scripts, package installations (pip/npm), or external binary downloads are requested in the skill's workflow.
Audit Metadata