Back to skill

Security audit

Dlazy Veo 3.1 Fast

Security checks across malware telemetry and agentic risk

Overview

This is a coherent video-generation skill, but it needs Review because broad triggers can cause third-party uploads and the packaged CLI stores a persistent API key without clearly enforced restrictive file permissions.

Install only if you intend to use dLazy for cloud video generation. Invoke it explicitly by name, confirm any local file paths before running, and consider using DLAZY_API_KEY per invocation instead of storing a persistent key if your machine has other local users or stricter credential-handling needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
Broad trigger keywords like '快速生成视频' can cause the skill to activate in unintended contexts, increasing the chance that user prompts, local file paths, or media references are sent to the external dLazy service without clear user intent. In this skill, accidental invocation is more concerning because the tool explicitly uploads local media to remote endpoints and performs authenticated network actions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include broad phrases like 'fast generate video' and 'text to video, image to video', which can cause the skill to activate in response to ordinary user requests without clear intent to use this specific external tool. In an agent setting, this increases the chance of unintended invocation of a networked third-party CLI that may upload local files and send prompts to remote services.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.