Back to skill

Security audit

Dlazy Veo 3.1

Security checks across malware telemetry and agentic risk

Overview

The skill matches its video-generation purpose, but it should be reviewed because it can be triggered broadly, uses a paid cloud API with media uploads, and the referenced CLI does not clearly support the skill's API-key file-permission claim.

Install only if you are comfortable sending prompts and selected media files to dLazy and potentially using paid credits. Prefer per-invocation DLAZY_API_KEY or verify local permissions on ~/.dlazy/config.json after login, and require explicit user confirmation before uploading local media or running a non-dry-run generation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are broad and overlap with common user intent such as '生成视频', which can cause the skill to activate in situations where the user did not explicitly intend to invoke this third-party SaaS tool. In this skill, accidental activation is more concerning because use of the tool may lead to network requests, cloud uploads of local media paths, and consumption of paid API credits.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword 'generate video' is extremely broad and likely to match many ordinary user requests unrelated to this specific dLazy Veo 3.1 skill. In an agent environment, broad activation can cause the wrong tool to be selected, leading to unintended API calls, file uploads, or credential-dependent execution against a third-party service.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger section lacks clear scope boundaries and includes generic phrases, making skill routing ambiguous. Because this skill sends prompts to external API endpoints and may upload local file paths to hosted storage, accidental activation increases privacy, cost, and data-handling risk beyond a harmless misclassification.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.