Security audit
文生图 通义 Qwen Image 2 Pro
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed wrapper for a third-party image-generation CLI/API and its sensitive behaviors are expected for that purpose.
Before installing, be comfortable using a third-party cloud service: prompts and selected input files may be sent to dLazy, generated files may be hosted by dLazy, and your API key may be stored locally by the CLI. Use npx instead of global install if you want less local persistence, and rotate or revoke the API key from the dLazy dashboard if needed.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
