Back to skill

Security audit

Dlazy File To Video

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed SaaS document-to-video skill that sends prompts and selected files to dLazy, with no artifact evidence of hidden or destructive behavior.

Install only if you are comfortable sending prompts, project context, and any files you attach to dLazy's hosted service. Avoid uploading confidential documents unless your organization approves that service, and protect or rotate the dLazy API key stored in the local CLI config if you use login or auth set.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation claims the skill itself will not access the network or file system, yet the same section explicitly states that prompts are sent to api.dlazy.com and local files passed via --files are uploaded to files.dlazy.com. This mismatch can mislead users about data handling and trust boundaries, increasing the risk of unintended disclosure of sensitive documents or prompts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad, generic phrases like 'document to video' and 'explainer video', which can match many ordinary user requests that are not clearly intended for this specific third-party SaaS skill. Because invoking this skill uploads user prompts and attached files to external dLazy services, overbroad activation increases the risk of unintended data transfer and surprising tool execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.