Back to skill

Security audit

Dlazy Start

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a coherent quickstart for a media CLI, but it includes under-scoped guidance that can cause an agent to use browser session cookies for downloads.

Install only if you are comfortable giving the CLI access to your dLazy API key, cloud media services, local media tools, and optional runtime installers. Do not allow an agent to use cookies_from_browser unless you explicitly approve that specific download and understand it may use browser login/session cookies; avoid logging or reusing those inputs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Content
- YouTube anti-bot challenge. Pass `"cookies_from_browser": "chrome"`
  (or firefox / safari / edge) in the input JSON.

**`video_compose` returns "render_runtime=hyperframes not yet implemented":**
- HyperFrames runtime not shipped. Switch `edit_decisions.render_runtime` to
  `remotion` or `ffmpeg`, then re-validate via `pre_render_validator`.
Confidence
84% confidence
Finding
cookies_from_browser": "chrome

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.