Back to skill

Security audit

创意转视频 Idea to Video

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed dLazy video-generation helper, but it mixes a canvas workflow with mandatory raw terminal execution through an external CLI that stores an API key locally.

Install only if you trust the dLazy CLI and are comfortable with prompts, selected media inputs, generated outputs, and a locally stored dLazy API key being handled by that service. Prefer npx or review the linked CLI source before global installation, and do not approve generated terminal commands that include unexpected file paths or shell metacharacters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's final execution section overrides its earlier plan/template-and-canvas workflow by instructing the agent to execute terminal commands directly, step by step, against an external CLI. That creates a real security boundary violation: a user idea or prompt can be transformed into shell-invoked operations, increasing risk of unsafe command construction, unauthorized external API use, and workflow bypass that avoids the safer confirmation and structured-canvas path.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
[English](./SKILL.md) · [中文](./SKILL-cn.md)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s final 'critical execution instructions' conflict with the earlier documented canvas-only workflow and explicitly direct the agent to execute terminal commands using an externally installed CLI. This creates a real security risk because an agent may be induced to perform networked code/tool execution based on untrusted prompt content, expanding the attack surface from workflow planning into command execution and remote API interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The critical execution instructions are written as mandatory directives in Chinese, including prescribed user-facing interaction text, and do not offer any language or locale opt-in. This creates a natural-language policy issue because the skill appears to require a specific language for operation rather than letting the user choose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language instructions in this section are written as mandatory agent behavior in Chinese, including exact required prompts to send to the user, and they do not offer any user opt-in or alternative locale. Because the skill otherwise presents bilingual content, this mandatory Chinese interaction guidance creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.