Back to skill

Security audit

Dlazy Imageseg

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper for a hosted image background-removal API, with expected API-key storage and media upload behavior.

Install only if you are comfortable using the external dLazy CLI and uploading selected media to dLazy's hosted service. Prefer DLAZY_API_KEY for temporary use, rotate or revoke the key if it may have been exposed, and do not pass private media files unless you intend them to be processed remotely.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs users to store a long-lived API key in a local config file and states that local image/video/audio paths will be uploaded to remote services, but it does not prominently warn about the confidentiality implications of uploading local content or persisting credentials on disk. This can lead users or agents to disclose sensitive files or leave reusable credentials stored locally without informed consent, especially in automated environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.