qr-bridge-0ef92d — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited qr-bridge-0ef92d (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Entry point reconnaissance tool. Decode QR codes, trace redirect chains, inspect gated destinations, and explain what the link actually needs.
Activate when the user asks to:
Before first use, compile the Swift decoder binary:
bash ~/.claude/skills/qr-bridge/scripts/setup.shIf setup was already run, the binary exists at ~/.claude/skills/qr-bridge/scripts/qr-decode. Skip setup if it exists.
Step 1: Check if binary exists
ls ~/.claude/skills/qr-bridge/scripts/qr-decode 2>/dev/null && echo "COMPILED" || echo "NEED_SETUP"If NEED_SETUP, run:
swiftc ~/.claude/skills/qr-bridge/scripts/qr-decode.swift -o ~/.claude/skills/qr-bridge/scripts/qr-decode -OStep 2: Run decoder (compiled binary - fast)
~/.claude/skills/qr-bridge/scripts/qr-decode "/path/to/image.png"Step 3: If compiled binary fails, use interpreted mode (slower but always works)
swift ~/.claude/skills/qr-bridge/scripts/qr-decode.swift "/path/to/image.png"Step 4: If CoreImage fails, try pyzbar fallback
python3 -c "
from pyzbar.pyzbar import decode
from PIL import Image
import json, sys
img = Image.open(sys.argv[1])
results = decode(img)
out = [{'message': r.data.decode(), 'symbology': r.type} for r in results]
print(json.dumps({'ok': bool(out), 'count': len(out), 'results': out}, indent=2))
" "/path/to/image.png"Output format (JSON):
{
"ok": true,
"count": 1,
"results": [
{
"message": "https://example.com/path",
"symbology": "QRCode",
"bounds": { "x": 0, "y": 0, "width": 200, "height": 200 }
}
],
"file": "/path/to/image.png",
"error": null
}After decoding a URL from a QR code (or given a URL directly), trace the full redirect chain:
curl -sIL -o /dev/null -w '%{url_effective}\n' --max-redirs 15 --connect-timeout 10 "URL_HERE" 2>&1For the full chain with each hop, use:
curl -sIL --max-redirs 15 --connect-timeout 10 -w '\n--- FINAL: %{url_effective} (HTTP %{http_code}) ---\n' "URL_HERE" 2>&1Parse the Location: headers from the output to build the chain:
1. https://short.link/abc → 302
2. https://tracking.example.com → 301
3. https://final-destination.com → 200After tracing, inspect the final URL for access gates. Check for these patterns:
WeChat/WeCom Gates (common in Chinese QR codes):
weixin.qq.com, work.weixin.qq.com, mp.weixin.qq.com, open.weixin.qq.comopen.weixin.qq.com/connect/oauth2/authorize请在微信客户端打开, 请在企业微信客户端打开logicret: -2 = article not found / deleted / unpublishedweixin://dl/business/?appid= — cannot be opened outside WeChatApp-Gated Links:
tb.cn, m.tb.cn — returns 200 with JS redirect to Taobao app. Look for tbopen:// scheme or s_status: STATUS_NORMAL headerv.douyin.com — 302 redirect to www.douyin.com, then 404 for invalid links. Valid links redirect to www.douyin.com/video/xhslink.com — 307 → www.xiaohongshu.com. Look for snssdk:// or xhsdiscover:// deep-link schemesur.alipay.com — redirects to alipays:// schemeweixin://, alipays://, tbopen://, snssdk://, xhsdiscover://Login Walls:
/login, /signin, /oauth/authorizeContent Validity Check (run AFTER gate detection):
logicret value — -2 means content invalid/deleted对不起 or 宝贝不存在 = product delistedDetection commands:
# Step 1: Check response headers for platform signals
curl -sI --max-redirs 10 --connect-timeout 10 "URL_HERE" 2>&1
# Step 2: Check with browser-like UA
curl -sL --max-redirs 10 --connect-timeout 10 \
-H "User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15" \
"URL_HERE" | head -c 5000
# Step 3: Check with WeChat UA (reveals WeChat-gated content)
curl -sL --max-redirs 10 --connect-timeout 10 \
-H "User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 MicroMessenger/8.0.0" \
"URL_HERE" | head -c 5000
# Step 4: Compare — if Step 2 and Step 3 return different content, the link is UA-gatedHeader signals to check:
logicret: -2 → WeChat article invalids_status: STATUS_NORMAL → Taobao link activeLocation: containing app deep-link schemes → app-gated redirectBased on decode + trace + inspect results, provide a structured diagnosis:
Output format:
## QR Bridge Diagnosis
**Source:** [image filename]
**Decoded:** [raw content from QR]
**Type:** [URL | Text | vCard | WiFi | other]
### Redirect Chain
1. [url] → [status]
2. [url] → [status]
3. [url] → [final status]
### Access Gate
- **Gate type:** [WeChat | WeCom | Login | App-only | None]
- **Why it fails:** [explanation in plain language]
- **What it needs:** [specific requirement]
### Next Steps
- [actionable suggestion 1]
- [actionable suggestion 2]Common diagnoses to provide:
| Gate Type | Why It Fails | What It Needs |
|---|---|---|
| Link requires WeChat's built-in browser | Open in WeChat app > scan QR | |
| WeChat (invalid) | logicret: -2 — article deleted/unpublished | Request a valid article link |
| WeCom | Enterprise WeChat only | Must be a WeCom member of that org |
| Taobao | JS redirect to Taobao app | Open link in Taobao/淘宝 app |
| Douyin | 302→douyin.com, content requires app | Open in Douyin/抖音 app |
| Xiaohongshu | 307→xiaohongshu.com, app deep-link | Open in 小红书 app |
| Alipay | alipays:// scheme redirect | Open in Alipay/支付宝 app |
| Mini Program | weixin://dl/business/ scheme | Open in WeChat > scan QR to launch mini-program |
| Login Wall | Requires authentication | Sign in at [domain] first |
| App-Only | Deep link to native app | Install [app name] and scan in-app |
| Expired | Short link no longer resolves | Link has expired, request a new one |
| Geo-blocked | Returns different content by region | May need VPN to [region] |
python3 -c "
import qrcode, sys, os
data = sys.argv[1]
out = sys.argv[2] if len(sys.argv) > 2 else os.path.expanduser('~/Desktop/qr-output.png')
qr = qrcode.QRCode(version=None, error_correction=qrcode.constants.ERROR_CORRECT_H, box_size=10, border=4)
qr.add_data(data)
qr.make(fit=True)
img = qr.make_image(fill_color='black', back_color='white')
img.save(out)
print(f'QR code saved to: {out}')
print(f'Content: {data}')
print(f'Size: {img.size[0]}x{img.size[1]}px')
" "CONTENT_HERE" "/output/path.png"If qrcode is not installed:
pip3 install "qrcode[pil]"When the user provides a QR code image, run the full pipeline automatically:
a. TRACE the redirect chain b. INSPECT the final destination for gates c. DIAGNOSE with full report
a. Present the content with type identification b. Skip trace/inspect
Always present results in the structured diagnosis format above.
Image cannot be read:
sips -s format png input.webp --out converted.pngNo QR code detected:
Redirect fails (timeout/DNS):
--connect-timeout 30Cannot determine gate type:
X-Powered-By, Server, custom headers~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.