Back to skill

Security audit

Dlazy Suno Music

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper for a third-party music-generation CLI and does not show hidden or purpose-mismatched behavior.

Before installing, review the third-party dLazy CLI and remember that prompts, parameters, and any local files you explicitly pass may be sent to dLazy's hosted service. Use `DLAZY_API_KEY` per invocation if you do not want the API key saved in the local config file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The manifest and surrounding documentation consistently describe this skill as generating music, but the documented JSON output shows an `outputs` entry with `type: "image"`, a `.png` URL, and `mimeType: "image/png"`. This is an active contradiction in the skill documentation about what the command returns, not merely an omitted detail.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The file contains imperative agent instructions in Chinese and directs execution behavior without any language or locale opt-in. Because this skill file is specifically a Chinese variant and does not state that language selection is optional at runtime, it can be interpreted as enforcing a locale-specific interaction style.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.