Back to skill

Security audit

Dlazy Doubao Tts

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud text-to-speech skill with privacy and documentation cautions, but no artifact-backed malicious behavior.

Install only if you are comfortable using the dLazy CLI and sending requested text to dLazy's hosted API. Prefer the documented npx invocation if you do not want a persistent global install, avoid sensitive prompts unless the service is trusted, and verify returned result types because the skill's output example appears to use an image schema instead of an audio schema.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documented output schema for a text-to-speech skill claims the primary output is an image with a PNG URL. This mismatch can mislead downstream agents or automation into handling the result incorrectly, causing unsafe parsing, broken workflow assumptions, or accidental forwarding of unexpected content types from a remote service.

Vague Triggers

Medium
Confidence
85% confidence
Finding
Broad trigger phrases like 'text to speech' and 'generate speech' increase the chance that an agent auto-invokes this skill in contexts where the user did not specifically intend to send content to a third-party SaaS. Because this skill transmits prompts to external endpoints, accidental invocation can expose sensitive user text or cause unintended billable API usage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.