Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md [English](./SKILL.md) · [中文](./SKILL-cn.md)
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed wrapper for a third-party dLazy motion-graphics CLI, with clear network/API-key behavior and no hidden local code in the artifact.
Install only if you are comfortable using dLazy's hosted service. Prompts and any files you attach may be sent to dLazy, and the CLI may save an API key locally; prefer the documented `npx` path if you do not want a persistent global install, and attach only files you intend to upload.
Referenced artifact was not completely inspected
[English](./SKILL.md) · [中文](./SKILL-cn.md)
The trigger list includes broad terms such as “动效” and “remotion”, which can match ordinary user requests that are not clearly asking to invoke this external SaaS-backed skill. Because the skill uploads prompts and optional files to remote dLazy services, accidental invocation can cause unintended data disclosure or unnecessary external actions.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## 错误处理
| Code | 错误类型 | 示例信息 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | 未授权 (API Key缺失或无效) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | 缺少必填参数 | `error: required option '--prompt <prompt>' not specified` |
The trigger list mixes specific terms like "remotion" with broader phrases such as "motion graphics," "动态图形," and especially "动效," which can refer to many generic animation requests. The file does not provide negative examples or clear boundaries for when this skill should activate versus when a different design/video skill should be used.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Error Handling
| Code | Error Type | Example Message |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | Unauthorized (No API Key) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | Missing required parameter | `error: required option '--prompt <prompt>' not specified` |
The trigger section lacks clear activation boundaries and exclusion conditions, so there is ambiguity about when this skill should run versus when a user is merely discussing motion graphics conceptually. In this skill, ambiguous invocation is more concerning because usage sends prompts to a third-party API and may upload local files, increasing the chance of unintended external data transfer.
The document presents the main heading in Chinese first ("动态图形视频") with English secondary, but does not state any user language preference or opt-in policy in the skill instructions themselves. Under the language/locale policy rule, this can be interpreted as imposing a locale choice without explicit user selection.
No suspicious patterns detected.