Back to skill

Security audit

Dlazy Banana2

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed third-party image generation wrapper that uses dLazy's hosted API and does not show hidden or destructive behavior.

Install this only if you are comfortable using dLazy as an external cloud image service. Prompts and any local media paths you pass can be uploaded to dLazy, and login may store an API key locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger keywords include broad, everyday actions such as image generation/editing without tight scoping to the specific tool or provider. This can cause the agent to invoke the skill in situations where the user did not clearly intend to use an external SaaS, leading to unintended data transfer, credential prompts, or execution of third-party CLI actions.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The skill is entirely written to drive Chinese-language behavior and includes agent directives in Chinese without offering a language-choice mechanism. This can cause user-confusing behavior, misinterpretation of safety-relevant instructions, and incorrect handling of authentication, billing, or consent flows when the user is operating in another language.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include broad, generic phrases like "generate image, edit image" and "text to image, image to image," which can cause this third-party skill to activate for many ordinary image-related requests. That increases the chance of unintended routing to an external SaaS tool, leading to unexpected data transfer of prompts or local images to remote endpoints.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.