Back to skill

Security audit

Dlazy Banana Pro

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed image-generation SaaS skill that sends prompts and chosen input files to dLazy, with a minor risk of broad auto-triggering.

Install this only if you are comfortable using dLazy as a cloud image-generation service. Prompts and any local files you explicitly pass as inputs may be uploaded to dLazy endpoints, and login stores an API key locally; use the per-invocation environment variable or rotate/revoke the key if that better matches your security needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords include broad everyday phrases such as '生成图片、编辑图片' and '文生图、图生图', which can cause the agent to invoke this skill in contexts where the user did not explicitly request this specific third-party tool. Because the skill performs networked SaaS actions and may upload local files to external endpoints, accidental activation can lead to unintended data disclosure, unnecessary external calls, or credential-related prompts.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are broad and generic for common image-generation tasks, which increases the chance this skill will be auto-invoked for ordinary requests that do not specifically require this vendor tool. Because the skill routes prompts and possibly local image paths to external SaaS endpoints, overbroad matching can cause unintended data disclosure or unnecessary third-party dependency activation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.