Dlazy Recraft V3

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper for dLazy's Recraft v3 image-generation CLI, with expected use of an API key and cloud uploads for prompts and input files.

Install only if you are comfortable using dLazy's hosted service. Prompts, parameters, and any local files you explicitly pass as inputs may be sent to dLazy, generated outputs are hosted by dLazy, and API use may consume account credits. Use the npx option or DLAZY_API_KEY if you want less local persistence than a global install plus saved config key.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords include broad everyday phrases like '生成图片、设计图' that are likely to match ordinary user requests unrelated to this specific tool. This can cause unintended invocation of the skill, leading to unnecessary external API calls, possible upload of user-supplied local files to a third-party service, and accidental disclosure of prompts or data.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords are broad enough to match many generic image-generation requests, which can cause this skill to be invoked in situations where the user did not explicitly ask for the dLazy service. Because the skill requires authentication and may upload local files to external endpoints, overbroad routing increases the chance of unintended third-party data disclosure or accidental paid API usage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal