Security audit
Dlazy Seedance 2.0
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed cloud video-generation wrapper that uses the pinned dLazy CLI, sends prompts and selected media to dLazy, and stores an API key if the user logs in.
Before installing, understand that prompts and any media files you pass are sent to dLazy's cloud service and that login stores an API key locally. Use DLAZY_API_KEY for temporary use if you do not want a saved config file, and rotate or revoke the key from the dLazy dashboard if it may have been exposed.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
