Back to skill

Security audit

动态图形视频 Motion Graphics

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed wrapper for a third-party dLazy motion-graphics CLI, with clear network/API-key behavior and no hidden local code in the artifact.

Install only if you are comfortable using dLazy's hosted service. Prompts and any files you attach may be sent to dLazy, and the CLI may save an API key locally; prefer the documented `npx` path if you do not want a persistent global install, and attach only files you intend to upload.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
[English](./SKILL.md) · [中文](./SKILL-cn.md)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad terms such as “动效” and “remotion”, which can match ordinary user requests that are not clearly asking to invoke this external SaaS-backed skill. Because the skill uploads prompts and optional files to remote dLazy services, accidental invocation can cause unintended data disclosure or unnecessary external actions.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL-cn.md (reported line 115)May include surrounding context.

md
## 错误处理

| Code | 错误类型                         | 示例信息                                                                                                                 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | 未授权 (API Key缺失或无效)       | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | 缺少必填参数                     | `error: required option '--prompt <prompt>' not specified`                                                               |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger list mixes specific terms like "remotion" with broader phrases such as "motion graphics," "动态图形," and especially "动效," which can refer to many generic animation requests. The file does not provide negative examples or clear boundaries for when this skill should activate versus when a different design/video skill should be used.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
## Error Handling

| Code | Error Type                         | Example Message                                                                                                          |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | Unauthorized (No API Key)          | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | Missing required parameter         | `error: required option '--prompt <prompt>' not specified`                                                              |

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The trigger section lacks clear activation boundaries and exclusion conditions, so there is ambiguity about when this skill should run versus when a user is merely discussing motion graphics conceptually. In this skill, ambiguous invocation is more concerning because usage sends prompts to a third-party API and may upload local files, increasing the chance of unintended external data transfer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The document presents the main heading in Chinese first ("动态图形视频") with English secondary, but does not state any user language preference or opt-in policy in the skill instructions themselves. Under the language/locale policy rule, this can be interpreted as imposing a locale choice without explicit user selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.