Back to skill

Security audit

Dlazy Recraft V3

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed wrapper around a third-party image-generation CLI, with expected cloud API use and credential storage but no evidence of hidden, destructive, or deceptive behavior.

Install this only if you are comfortable trusting the dLazy npm CLI and sending prompts, selected media files, and generated outputs through dLazy's cloud service. Prefer `npx @dlazy/cli@1.0.9` over a global install when possible, review the upstream package/source, and do not pass private files unless you intend to upload them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:58
Finding

Unreviewed Third-Party CLI Installation and Execution

Content
View full analysis
``` ```bash npm install -g @dlazy/cli@1.0.9 ``` ```markdown **CRITICAL INSTRUCTION FOR AGENT**: Run the `dlazy recraft-v3` command to get results. ``` The equivalent installation and execution instructions also appear in `SKILL-cn.md`. ### Technical Analysis The skill delegates its principal behavior to the external npm package `@dlazy/cli@1.0.9`. The package implementation is not included in the audited project, so its installation scripts, transitive dependencies, authentication handling, filesystem operations, and network behavior cannot be verified from the supplied files. Pinning the package to version `1.0.9` reduces exposure to unexpected future upgrades but does not provide artifact integrity. The project supplies no lockfile, vendored package, cryptographic digest, signature-verification procedure, or reproducible-build evidence. Both `npm install -g` and `npx` retrieve and execute code from an external package registry. A global installation also expands the package's lasting footprint in the user's environment. The documentation states that the CLI: - Stores an API key in `~/.dlazy/config.json` or reads it from `DLAZY_API_KEY`. - Reads user-selected ...[truncated 2428 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
[English](./SKILL.md) · [中文](./SKILL-cn.md)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description at L004 and repeated description at L013 state the skill supports both text-to-image and image-to-image. However, the embedded dlazy recraft-v3 -h help output at L082-L089 lists no --image or equivalent input-image flag, while later examples use --image at L120-L123. This is an active contradiction within the file about what the command actually accepts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger keywords include broad everyday phrases like '生成图片、设计图', which can cause unintended activation of this skill in contexts where the user did not explicitly request this external CLI or API. In an agent setting, accidental invocation can lead to unnecessary network calls, file uploads, billing, or disclosure of user prompts/media to the third-party service.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL-cn.md (reported line 128)May include surrounding context.

md
## 错误处理

| Code | 错误类型                         | 示例信息                                                                                                                 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | 未授权 (API Key缺失或无效)       | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | 缺少必填参数                     | `error: required option '--prompt <prompt>' not specified`                                                               |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

L137-L139 的“智能体关键指令”要求代理在特定错误场景下按固定中文话术告知用户,但文档未说明这是用户可选的语言策略,也未给出仅面向中文环境的明确约束。根据语言/locale 政策,这类强制单一语言输出而无 opt-in 的要求属于自然语言策略风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger keywords are broad enough to match many generic image-generation requests, which can cause the agent to invoke this third-party skill unexpectedly. Because the skill transmits prompts and referenced local files to remote dLazy endpoints, overbroad routing increases the chance of unintended data disclosure or needless execution of an external tool.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
## Error Handling

| Code | Error Type                         | Example Message                                                                                                          |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | Unauthorized (No API Key)          | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | Missing required parameter         | `error: required option '--prompt <prompt>' not specified`                                                              |

Static analysis

No suspicious patterns detected.