Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md [English](./SKILL.md) · [中文](./SKILL-cn.md)
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed wrapper for a hosted video segmentation CLI, with documentation issues but no artifact-backed evidence of hidden, destructive, or deceptive behavior.
Before installing, treat this as a third-party cloud CLI: review the pinned npm package/source if you rely on it, expect user-provided media files to be uploaded to dLazy endpoints, and store the API key only if that persistence is acceptable. The publisher should fix the `--prompt` and image/video documentation mismatches to avoid failed or misprocessed calls.
Referenced artifact was not completely inspected
[English](./SKILL.md) · [中文](./SKILL-cn.md)
Manifest 和正文多次说明该技能返回“与原视频同时长的 mask 视频”。然而输出示例中的 outputs[0] 被标记为 type: "image"、mimeType: "image/png",这与“视频分割返回 mask 视频”的描述形成直接冲突,可能导致使用方错误处理结果类型。
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## 错误处理
| Code | 错误类型 | 示例信息 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | 未授权 (API Key缺失或无效) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | 缺少必填参数 | `error: required option '--prompt <prompt>' not specified` |
The agent instruction text mandates that responses to certain error conditions '必须明确告知用户' using Chinese-language guidance, but this Chinese skill file does not state that the user has opted into Chinese-only responses. That creates a locale/language policy concern because the behavior is prescribed rather than offered as a choice.
The manifest and main description repeatedly say this skill performs video human segmentation and returns a same-length mask video. However, the documented JSON output shows an output object with type: "image", url: "...result.png", and mimeType: "image/png", which conflicts with the stated video output behavior in a security-relevant way because it misrepresents what artifact is produced.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Error Handling
| Code | Error Type | Example Message |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | Unauthorized (No API Key) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | Missing required parameter | `error: required option '--prompt <prompt>' not specified` |
该技能整体描述为“视频人像分割”,帮助信息中也只展示了 --video 等与视频处理相关的参数。但命令示例写成 dlazy videoseg --prompt '提示词内容',与前述接口用途和参数定义直接不一致,容易误导调用方按文本生成类用法使用该技能。
帮助信息仅定义了 --video、--dry-run、--no-wait、--timeout、--save 等参数,没有显示 --prompt。但错误处理表中把“缺少必填参数”的示例写成 required option '--prompt <prompt>' not specified,这与该技能宣称和展示的实际命令接口相冲突。
The usage section lists only --video, --dry-run, --no-wait, --timeout, and --save, but the example invokes dlazy videoseg --prompt 'prompt content' and the error table says --prompt is required. This is an active contradiction within the skill documentation about what inputs the command accepts and requires.
No suspicious patterns detected.