Back to skill

Security audit

Dlazy Jimeng I2v First

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud image-to-video skill, with documentation accuracy issues and broad triggers that users should handle carefully.

Install only if you are comfortable using dLazy's cloud service for prompts and media files, storing or supplying a dLazy API key, and potentially spending credits. Agents should prefer --firstFrame rather than the documented --image examples and should confirm before uploading local files for generic image-to-video requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill claims to generate video from a first-frame image, but its documented output schema returns an image object and its examples use a mismatched --image flag instead of the documented --firstFrame flag. This inconsistency can cause an agent to invoke the tool incorrectly, mis-handle returned artifacts, or route the wrong media type into downstream automation, creating unsafe behavior in chained workflows.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger keywords are broad enough that an agent may invoke this skill on loosely related user requests, causing unintended transmission of prompts and local media paths to the vendor API. In this skill's context, accidental activation is more concerning because it can upload user-supplied local files to external services (`api.dlazy.com` / `files.dlazy.com`) and incur charges.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger keyword "image to video" is broad enough to match many generic user requests, increasing the chance this skill is auto-selected when the user did not specifically intend to use this third-party SaaS tool. In agent environments, overbroad routing can unexpectedly send prompts and local files to remote endpoints, which is a privacy and consent risk even if the tool itself is not overtly malicious.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.