Back to skill

Security audit

Dlazy Seedream 4.5

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud image-generation skill; users should mainly be aware that prompts, selected image files, and API credentials are handled by dLazy.

Install only if you intend to use dLazy for image generation. Treat prompts and any local files you pass as data sent to dLazy, prefer explicit provider requests, use `--dry-run` when checking payloads, and rotate or revoke the API key from the dLazy dashboard if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger keywords include very broad phrases such as '生成图片' that can overlap with ordinary user requests, increasing the chance that this skill activates when the user did not explicitly intend to use this third-party service. In this skill’s context, accidental activation can cause prompts and local file paths/images to be sent to external endpoints, creating privacy, cost, and consent risks.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keyword 'generate image' is extremely broad and likely to match many ordinary user requests unrelated to this specific provider skill. That increases the chance of accidental invocation, causing prompts, local file references, or authentication-dependent actions to be routed to the dLazy CLI and its remote API without sufficiently explicit user intent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger section does not define clear activation boundaries, and combines generic phrases with no requirement for explicit user consent to use this external SaaS-backed tool. In context, this is more dangerous because the skill can upload local files and send prompts to third-party endpoints, so ambiguous activation can lead to unintended data transfer or unauthorized tool execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.