Back to skill

Security audit

Dlazy Jimeng I2v First Tail

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cloud video-generation wrapper, with the main caution that broad trigger wording could make it run for generic transition-video requests.

Install only if you intend to use dLazy's hosted Jimeng video service. Treat prompts and local first/last-frame images as data sent to dLazy, consider using npx or DLAZY_API_KEY for less persistent setup, and confirm intent before invoking it for generic transition-video tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger phrases are broad enough to overlap with generic video-editing requests, which can cause the agent to invoke this third-party cloud skill unexpectedly for normal media tasks. In this skill's context, that increases the chance of unintended routing of user prompts and local image paths to the dLazy service, creating privacy, cost, and data-handling risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.