Dlazy Jimeng Omnihuman 1.5

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed dLazy cloud video-generation wrapper that uses an API key and uploads user-selected media for its stated digital-human video purpose.

Install only if you are comfortable trusting @dlazy/cli@latest, storing or passing a dLazy API key, and sending prompts plus any selected image/audio files to dLazy's hosted service. Review the CLI source/package first if media privacy or unpinned latest-version installs matter to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger keywords are broad terms like '数字人' and '生成数字人视频', which can overlap with ordinary user requests and cause the skill to activate unexpectedly. In this skill, activation can lead to prompting for authentication, local file references, and uploads to remote SaaS endpoints, so false activation increases the chance of unintended external API use or accidental data disclosure to the service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal