Back to skill

Security audit

Dlazy Seedance 1.5 Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed cloud video-generation wrapper, but users should be careful because it installs a third-party CLI, stores an API key, and uploads selected media to dLazy.

Install only if you trust dLazy and the @dlazy/cli npm package. Prefer the on-demand npx form or a sandboxed environment, review the linked source/package before use, keep the dLazy API key revocable, and confirm which local media files will be uploaded before running billable generation commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Third-Party npm Package Executed Without Artifact Integrity Verification

Content
View full analysis
``` ```bash npm install -g @dlazy/cli@1.0.9 ``` ### Technical Analysis The Skill directs the agent to install or immediately execute the externally hosted npm package `@dlazy/cli@1.0.9`. Pinning the package version reduces uncontrolled version drift, but it does not verify the integrity or provenance of the downloaded artifact. No package digest, trusted lockfile, vendored implementation, signature verification, or reproducible-build verification is provided in the audited project. The linked GitHub repository improves transparency but does not establish that the npm artifact is identical to the reviewed repository source. In addition, npm installation may execute package lifecycle scripts and load transitive dependencies. Consequently, the effective executable payload is outside the two audited documentation files. No evidence establishes that the current package is malicious. The confirmed issue is the trust boundary created by executing an external package without cryptographic artifact verification. ### Attack Path 1. An attacker compromises the npm publisher account, the package release process, or a transitive dependency used by ...[truncated 1441 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
[English](./SKILL.md) · [中文](./SKILL-cn.md)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger keywords are broad enough to match normal user requests about dance or motion video generation, increasing the chance that an agent auto-invokes this skill without sufficiently explicit user intent. In this skill's context, invocation can lead to outbound API calls and upload of local media paths to remote infrastructure, so accidental activation has privacy and cost implications.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL-cn.md (reported line 134)May include surrounding context.

md
## 错误处理

| Code | 错误类型                         | 示例信息                                                                                                                 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | 未授权 (API Key缺失或无效)       | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | 缺少必填参数                     | `error: required option '--prompt <prompt>' not specified`                                                               |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger keywords include "dancing video" and especially "action video," which are broad natural phrases that could match many unrelated user requests. The file does not provide exclusion conditions or tighter scope to distinguish when this specific skill should activate versus other video-generation or editing skills.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and surrounding documentation repeatedly state that this skill converts images into dance videos, but the documented JSON output example shows an output object with type: "image", a .png URL, and mimeType: "image/png". This is an active contradiction in the skill's own documentation, not merely an omission, and can mislead an agent about what artifact the command actually produces.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
## Error Handling

| Code | Error Type                         | Example Message                                                                                                          |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | Unauthorized (No API Key)          | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | Missing required parameter         | `error: required option '--prompt <prompt>' not specified`                                                              |

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

该技能在清单描述和全文中都说明其用途是“将图片转化为动感的跳舞视频”,且参数也围绕视频生成展开。但输出示例中的 outputs[0].type 为 image,URL 也指向 result.png,这与技能应产出视频的预期直接矛盾。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

帮助信息列出的图像输入参数为 --firstFrame 和 --lastFrame,未出现 --image。但后续“基础调用/复杂调用”示例均使用 --image,这会让文档对实际调用方式产生相互矛盾的指示。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The help output documents --firstFrame and --lastFrame as the image inputs, but the command examples instruct use of --image, which is not listed in the options. This is an intent/documentation contradiction that can cause an agent to invoke the skill incorrectly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.