Back to skill

Security audit

动态图形视频 Motion Graphics

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper around the dLazy CLI for creating motion graphics, with expected use of a third-party API and optional file uploads.

Before installing, review the dLazy CLI package and understand that prompts, project context, and any files you attach will be sent to dLazy's service. Treat the saved API key like any other credential and rotate or revoke it from the dLazy dashboard if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
该文件主体说明和操作指导均以中文呈现,并将中文版本作为当前技能文档内容,但未在文内提供面向用户的语言选择说明或交互时的语言可选项。根据规则,强制特定语言而无用户 opt-in 可构成语言/locale 策略问题。

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.