Back to skill

Security audit

Dlazy Keling Tts

Security checks across malware telemetry and agentic risk

Overview

This TTS skill is mostly purpose-aligned, but it needs Review because the installed CLI saves a reusable dLazy API key with weaker local file permissions than the skill claims.

Install only if you are comfortable sending TTS text to dLazy and storing a dLazy API key locally. Prefer `DLAZY_API_KEY` per invocation or manually restrict `~/.dlazy/config.json` permissions after login; review the pinned CLI before global installation, and be aware that generic TTS requests may trigger this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger keywords are very broad and map to common user intents like 'text to speech' and 'generate speech', increasing the chance this skill is auto-invoked in ordinary conversations without sufficiently specific user consent. Because the skill sends prompts to a hosted third-party API and may store credentials locally, overbroad matching can cause unintended external data disclosure or unexpected tool execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.