Back to skill

Security audit

Dlazy Seedream 5.0 Lite

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud image-generation skill that uses a pinned dLazy CLI, with normal SaaS data-sharing and credential-storage cautions but no hidden or destructive behavior found.

Install only if you are comfortable using dLazy as a cloud image-generation provider. Prompts and any local images you pass will be sent to dLazy, generated assets are hosted by dLazy, and the CLI may store your dLazy API key locally; use the per-invocation environment variable or verify config-file permissions if this is a shared machine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are broad and overlap with common conversational terms such as '生成图片', '文生图', '图生图', and vendor/model names. This can cause unintended skill activation, which may lead an agent to invoke an external CLI, transmit prompts or local file paths to remote services, or steer a workflow away from the user's intended tool.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad terms like "doubao," "seedream," and generic phrases such as "generate image" and "text to image," which can cause the skill to activate in contexts where the user did not explicitly intend to use this specific third-party SaaS tool. In an agent environment, accidental activation can lead to unintended network calls, prompting for authentication, or uploading local image paths to remote infrastructure, increasing privacy and operational risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.