Back to skill

Security audit

视频对口型 Video Retalk

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper for a hosted lip-sync video API, with expected cloud upload and API-key use for that purpose.

Install only if you are comfortable using dLazy's cloud service for the media you provide. Avoid sending private, biometric, or non-consensual face/voice/video material unless you have permission and accept that local paths passed to the CLI will be uploaded for processing and hosted output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The example command is presented without an adjacent warning that local media paths supplied to the CLI will be uploaded to remote dLazy services. In this skill context, users are likely to pass sensitive face images, voice recordings, or private videos, so omission of a clear disclosure can cause unintended exfiltration of highly sensitive biometric and personal media to third-party infrastructure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.