Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md [English](./SKILL.md) · [中文](./SKILL-cn.md)
Security audit
Security checks for vulnerabilities and agentic risk
This logo-design skill is a disclosed SaaS CLI wrapper that uses a dLazy API key and can upload user-attached files, with no hidden or destructive behavior found.
Install only if you are comfortable using dLazy's hosted service: prompts and options go to api.dlazy.com, files you attach with --files are uploaded to files.dlazy.com, and login can save an API key under your user config. Prefer npx if you do not want a global CLI install, and rotate or revoke the API key from the dLazy dashboard if needed.
Referenced artifact was not completely inspected
[English](./SKILL.md) · [中文](./SKILL-cn.md)
The trigger list includes very broad terms such as "logo", "品牌", and especially "VI", which can appear in many ordinary contexts and abbreviations unrelated to this specific skill. The file does not provide narrowing conditions, exclusions, or negative examples to clarify when the skill should or should not activate.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## 错误处理
| Code | 错误类型 | 示例信息 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | 未授权 (API Key缺失或无效) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | 缺少必填参数 | `error: required option '--prompt <prompt>' not specified` |
The trigger list contains generic terms such as "logo", "品牌", and especially "VI", which are broad and ambiguous outside a narrowly constrained invocation context. The file does not provide exclusion conditions or negative examples to clarify when these keywords should and should not activate the skill.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Error Handling
| Code | Error Type | Example Message |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | Unauthorized (No API Key) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | Missing required parameter | `error: required option '--prompt <prompt>' not specified` |
This Chinese skill file ends with an English-only tip ("Visit https://dlazy.com for more information.") and also presents bilingual headings without stating a user language preference policy. That can impose a language choice without opt-in in a locale-specific file intended for Chinese users.
No suspicious patterns detected.