Back to skill

Security audit

Dlazy Image Amazon Product Image Suite

Security checks across malware telemetry and agentic risk

Overview

The skill matches its Amazon product image purpose, but users should review it because it drives a third-party CLI that uploads prompts/media and stores an API key while some runtime instructions and disclosures are Chinese-only metadata.

Install only if you are comfortable using dLazy's hosted service, sending prompts and any supplied local media to dLazy endpoints, and storing or supplying a dLazy API key. Prefer the npx or environment-variable options if you do not want a persistent global CLI or saved key, and review the Chinese instructions before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The document asserts that the skill 'will not access network or files,' but the same skill explicitly instructs the agent to run a CLI that sends prompts to api.dlazy.com and uploads local media to files.dlazy.com. This mismatch can mislead users or higher-level agents into granting trust or approvals they would not otherwise give, creating a transparency and consent problem around network and file handling.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad capability descriptions rather than narrowly scoped invocation terms, which can cause the skill to activate in many loosely related Amazon-image or product-design contexts. Over-broad activation increases the chance that the agent follows this skill's embedded execution guidance unexpectedly, including installing and using an external CLI and sending user-provided assets to remote services.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The metadata embeds a mandatory Chinese-only system instruction telling the agent to strictly follow the skill's guidance and use the dlazy CLI for image rendering, without any user language opt-in. This can override or distort user understanding, reduce transparency, and push the agent into executing external-tool workflows under hidden instructions that some users may not be able to read or meaningfully consent to.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.