Back to skill

Security audit

多模态大模型 Gemini 3.1

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed dLazy cloud-model wrapper that sends user-provided prompts and selected media files to dLazy, with only minor documentation inconsistencies to consider.

Before installing, understand that using this skill sends prompts to dLazy and may upload any local media file paths you provide. Use the per-invocation DLAZY_API_KEY option if you do not want the CLI to persist an API key locally, and verify the intended @dlazy/cli version because one documentation line still references an older version.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The documentation minimizes the skill's security impact by claiming it 'will not' access the network or file system, while the same document explicitly states that prompts are sent to api.dlazy.com and local image/video paths are uploaded to files.dlazy.com. This can mislead users and downstream agents into exposing sensitive prompts or local files under a false assumption of no external data transfer.

Intent-Code Divergence

Low
Confidence
80% confidence
Finding
The provenance section states the install field is pinned to version 1.0.9, but the manifest actually pins 1.2.0. This inconsistency undermines trust in the documented supply-chain provenance and can cause reviewers or automated systems to validate the wrong package version.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.