Back to skill

Security audit

Dlazy Pixverse C1

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cloud video-generation wrapper, with a broad trigger and API-key storage that users should understand before using it.

Install only if you intend to use dLazy/PixVerse C1. Prefer explicit prompts such as "pixverse c1" to avoid accidental routing, review the npm/GitHub package before installing globally, and do not pass local images or videos unless you are comfortable uploading them to dLazy's service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords include a very generic term, “视频生成” (“video generation”), which can overlap with ordinary user requests unrelated to this specific skill. In an agent environment, overly broad triggers can cause unintended auto-invocation of the skill, leading to unexpected network calls, file uploads, or credential-dependent actions through the external CLI.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger keyword "video generation" is broad enough to match many generic user requests that are not specifically asking for this vendor or model. That can cause unintended activation of this skill, leading an agent to route prompts, local file references, or media uploads to a third-party cloud service when the user did not explicitly choose it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.