Back to skill

Security audit

Dlazy Image Social Media

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper around a pinned dLazy CLI for user-confirmed social-media image generation, with expected cloud API use and credential setup.

Install this only if you are comfortable using dLazy's npm CLI, sending prompts and selected media files to dLazy's cloud services, and storing or supplying a dLazy API key. Prefer the environment-variable option if you do not want a long-lived key in the CLI config, and review the pinned package source before global installation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a social-media planning/design skill, but it instructs the agent to execute terminal commands that invoke an external CLI to render images. That expands the trust boundary from content planning into local code/tool execution and networked API use, creating unnecessary execution risk for a task that could otherwise remain purely advisory.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The instructions require the agent to use terminal commands even though the stated purpose is social-media design optimization. This mismatch can cause users or orchestrators to grant a design skill more capabilities than expected, enabling local command execution, remote API calls, and file handling under misleading functional scope.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The documentation minimizes risk by saying the skill will not overreach file or network access, yet it explicitly describes storing API keys in local config and uploading user-provided local files to remote storage. That contradiction can mislead users about sensitive data handling and increase the chance they expose credentials or private media without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.