Back to skill

Security audit

Dlazy Keling Sfx

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed cloud sound-effect generator, but its documentation has an output-format mistake showing an image instead of audio.

Before installing, confirm you are comfortable using dLazy's cloud API: prompts and any media paths you provide may be uploaded, and an API key may be stored locally. Treat the documented image/png output example as inaccurate for this audio tool and validate actual outputs in your workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documented output format claims this sound-effect generation skill returns an `image/png` hosted at `result.png`, which conflicts with the skill’s stated purpose of producing audio. This kind of interface mismatch can cause downstream agents or automations to treat the result incorrectly, leading to unsafe tool chaining, broken validation, or accidental disclosure/processing of unexpected content types.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.