Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md [English](./SKILL.md) · [中文](./SKILL-cn.md)
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed dLazy CLI wrapper for recreating reference images or videos, with expected cloud API use, optional file uploads, local API-key storage, and project history.
Install only if you are comfortable using dLazy as a third-party service: your prompts and any files you attach can be uploaded, and the CLI may store an API key locally. Start a new project for unrelated work, clear project context when switching subjects, and rotate or revoke the API key from the dLazy dashboard if needed.
Referenced artifact was not completely inspected
[English](./SKILL.md) · [中文](./SKILL-cn.md)
The trigger list includes very broad, everyday terms such as '复刻', '同款', and 'replicate' that can match benign user requests unrelated to this specific external-tool skill. In an agent environment, overbroad activation can cause unintended invocation of a networked SaaS workflow, resulting in unexpected file upload, data disclosure to third-party endpoints, or execution of actions the user did not clearly request.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## 错误处理
| Code | 错误类型 | 示例信息 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | 未授权 (API Key缺失或无效) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | 缺少必填参数 | `error: required option '--prompt <prompt>' not specified` |
SQP-3 适用于所有文件。这里的自然语言指令要求在特定错误场景下“必须明确告知用户”固定内容,且整段仅以中文给出,没有说明可根据用户语言偏好切换,可能构成语言/locale 策略上的强制单一语言输出。
The skill explicitly describes project-scoped follow-up behavior and persistence via dlazy chat --project <id>, meaning prior conversation state can be reused across turns. In a skill that handles user-provided reference media and prompts, persistent session context can increase the chance of unintended retention or cross-task leakage if users continue work in an existing project without clear isolation boundaries.
---
name: dlazy-video-image-replicate
version: 1.3.5
description: "replicate this image, remake this video, recreate a reference, same video with my content, 同款视频, 照着做 — study the reference image or video the user provides, then recreate the same look and structure with the user's own subject, product, or characters."
metadata: {"clawdbot":{"emoji":"🔁","requires":{"bins":["npm","npx"]},"install":"npm install -g @dlazy/cli@1.2.3","installAlternative":"npx @dlazy/cli@1.2.3","homepage":"https://github.com/dlazy-ai/cli","source":"https://github.com/dlazy-ai/cli","author":"dlazyai","license":"see-repo","npm":"https://www.npmjs.com/package/@dlazy/cli","configLocation":"~/.dlazy/config.json","apiEndpoints":["api.dlazy.com","files.dlazy.com"]},"openclaw":{"systemPrompt":"When this skill is called, run 'dlazy chat --skill video-image-replicate --prompt ...' for a new task, or 'dlazy chat --project <id> --prompt ...' to continue (discover ids via 'dlazy projects list'). Never pass both --skill and --project."}}
---
The trigger list includes generic phrases such as "replicate", "同款", and the description also advertises broad prompts like "recreate a reference" and "same video with my content." These phrases can overlap with ordinary user requests and the file does not provide limiting conditions or negative examples to clarify when the skill should or should not activate.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Error Handling
| Code | Error Type | Example Message |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | Unauthorized (No API Key) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | Missing required parameter | `error: required option '--prompt <prompt>' not specified` |
The document presents the primary heading and key skill labeling in Chinese while also linking to an English version, but it does not explicitly state that the user can choose their preferred language for interaction. This can create a locale expectation without clear opt-in or documented language-selection behavior.
No suspicious patterns detected.