Back to skill

Security audit

大模型对话 Claude Opus 4.7

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper around the dLazy hosted CLI/API, with expected cloud data transfer and local API-key storage for that purpose.

Before installing, understand that prompts and selected local media files will be sent to dLazy's hosted service, and that using dlazy login stores an API key locally. Prefer the npx option if you do not want a global CLI install, verify the intended @dlazy/cli version because the prose contains a stale version reference, and avoid passing sensitive files unless you are comfortable uploading them to dLazy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documentation minimizes the skill's security-relevant behavior by claiming the skill itself will not access the network or file system, while the documented workflow explicitly sends prompts to api.dlazy.com and uploads local media files to files.dlazy.com. This can mislead users and agents about data exfiltration and file-handling risk, causing sensitive prompts or local files to be transmitted off-host without fully informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.