Back to skill

Security audit

文生图 通义 Qwen Image 2 Pro

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper for a third-party image-generation CLI/API and its sensitive behaviors are expected for that purpose.

Before installing, be comfortable using a third-party cloud service: prompts and selected input files may be sent to dLazy, generated files may be hosted by dLazy, and your API key may be stored locally by the CLI. Use npx instead of global install if you want less local persistence, and rotate or revoke the API key from the dLazy dashboard if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.