Back to skill

Security audit

Dlazy Recraft V3 Svg

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed cloud image-generation skill, but users should be aware it installs or runs a third-party npm CLI and sends prompts or selected files to dLazy.

Install only if you trust dLazy and the @dlazy/cli npm package. Prefer npx or a contained environment over a global install, avoid passing sensitive prompts or private local file paths unless you intend to upload them, and rotate the dLazy API key if you later stop using the service.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unverified Third-Party CLI Is Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 5 and 60; duplicated in SKILL-cn.md, lines 5 and 60
Vulnerability Type: Third-party dependency and supply-chain risk
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"🤖","requires":{"bins":["npm","npx"]},"install":"npm install -g @dlazy/cli@1.0.9","installAlternative":"npx @dlazy/cli@1.0.9","homepage":"https://github.com/dlazyai/cli","source":"https://github.com/dlazyai/cli","author":"dlazyai","license":"see-repo","npm":"https://www.npmjs.com/package/@dlazy/cli","configLocation":"~/.dlazy/config.json","apiEndpoints":["api.dlazy.com","files.dlazy.com"]},"openclaw":{"systemPrompt":"When invoking this skill, use dlazy recraft-v3-svg -h for help."}}
bash
npx @dlazy/cli@1.0.9 <command>

Technical Analysis

The Skill does not include the executable implementation used to perform its primary operation. Instead, it instructs the environment to retrieve and execute @dlazy/cli@1.0.9 from the npm registry, either through a global installation or an on-demand npx invocation.

Pinning the package to version 1.0.9 limits ordinary version drift, but the Skill provides no package integrity digest, vendored artifact, lockfile, signed provenance, or reproducible-build verification. The referenced GitHub repository therefore does not, by itself, prove that the npm artifact fetched during execution is identical to the reviewed source.

npm package installation can execute package code and lifecycle scripts with the permissions of the invoking user. The global installation option also persists an executable outside the Skill directory. No evidence in the reviewed files establishes that the named package is currently malicious; the finding concerns the unverified remote dependency and the resulting supply-chain trust boundary.

Attack Path

  1. An attacker compromises the npm publisher account, registry delivery path, o ...[truncated 1336 chars]
Remediation
View remediation

Remediation Suggestions

  1. Bundle a locally auditable implementation or a verified package artifact with the Skill rather than downloading executable code during use.
  2. Publish and enforce a cryptographic integrity digest for the exact npm tarball. Verify it before installation or execution.
  3. Provide signed release provenance and reproducible-build instructions that allow users to confirm that the npm artifact matches the referenced source revision.
  4. Use a lockfile and an explicitly trusted registry URL, and verify the integrity of all transitive dependencies.
  5. Prefer an isolated, non-global installation to prevent persistent modification of the user's executable environment.
  6. Disable npm lifecycle scripts where compatible, such as by using --ignore-scripts, and explicitly document any scripts that are required.
  7. Execute the CLI in a sandbox with narrowly scoped filesystem and network access. Only mount files deliberately selected by the user.
  8. Store API credentials using an operating-system credential manager where possible, apply least-privilege API scopes, and support prompt rotation and revocation.
  9. Apply the same hardened installation instructions consistently to both SKILL.md and SKILL-cn.md.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
[English](./SKILL.md) · [中文](./SKILL-cn.md)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to match ordinary requests like 'generate svg' or 'text-to-image,' which can cause the skill to activate unexpectedly. In an agent environment, overbroad activation can route user content and local file references to an external SaaS without sufficiently clear user intent, increasing the risk of unintended data disclosure or tool use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill manifest and description repeatedly state that this tool generates SVG vector graphics, but the documented JSON output shows url: https://files.dlazy.com/result.png with mimeType: image/png. This is an active contradiction in the skill's own documentation about what the command produces.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL-cn.md (reported line 129)May include surrounding context.

md
## 错误处理

| Code | 错误类型                         | 示例信息                                                                                                                 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | 未授权 (API Key缺失或无效)       | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | 缺少必填参数                     | `error: required option '--prompt <prompt>' not specified`                                                               |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation contains mandatory agent instructions dictating specific response behavior, including fixed-language and prescriptive follow-up actions, without user opt-in. In a tool-skill context, embedded control instructions can override user preference and steer agent behavior in ways that are not strictly necessary for tool operation, which is a prompt-injection style policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like 'generate svg' and 'text to image', which can cause the skill to activate in contexts the user did not intend. Because this skill can transmit prompts and local file references to external services (api.dlazy.com and files.dlazy.com), unintended invocation increases the chance of accidental data disclosure or unwanted third-party API use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and surrounding documentation repeatedly describe this skill as generating SVG vector graphics, but the explicit JSON output example shows mimeType: "image/png" and a .png result URL. That is an active contradiction between stated behavior and documented actual result format, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
## Error Handling

| Code | Error Type                         | Example Message                                                                                                          |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | Unauthorized (No API Key)          | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | Missing required parameter         | `error: required option '--prompt <prompt>' not specified`                                                              |

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The options listing for dlazy recraft-v3-svg does not include an --image parameter, yet the later examples invoke the command with --image. This creates intent/documentation divergence by instructing users and agents to use a capability not documented as supported by the command.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The usage section documents only prompt, aspect ratio, style, and async-related flags, but the later examples invoke --image with both local and remote paths. This creates intent/documentation divergence because the examples suggest image-input behavior not described by the command's own interface or the manifest's text-only generation purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.