Back to skill

Security audit

矢量图生成 Recraft V4 Vector

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a disclosed dLazy API wrapper, but its central SVG/vector promise conflicts with its documented PNG output.

Review before installing if you specifically need editable or scalable SVG output. The API key storage, network calls, optional uploads, and pinned npm CLI are disclosed and appear purpose-aligned, but the advertised output format should be clarified before relying on this skill in automated design workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The skill is presented as a vector/SVG generator, but its documented output example returns a PNG URL with image/png MIME type. This mismatch can mislead users and downstream agents into treating raster output as vector-safe, causing incorrect automation decisions, format handling failures, or trust issues around generated assets.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The top-level description promises SVG/vector output, while the rest of the file documents PNG output. In a tool-selection or agentic workflow, this deception can cause the wrong tool to be chosen for tasks requiring editable or scalable vector assets, leading to broken pipelines or unsafe assumptions about file content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.