Back to skill

Security audit

Dlazy Wan2.6 R2v Flash

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed cloud video-generation wrapper, with ordinary but real caution around using a third-party npm CLI, storing a dLazy API key, and uploading chosen media files.

Install only if you are comfortable running the pinned @dlazy/cli npm package and sending prompts plus selected media files to dLazy. Prefer npx over a global install when possible, avoid running npm as administrator/root, and use a revocable or limited dLazy API key.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Third-Party CLI Is Installed and Executed Without Project-Level Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 5 and 54-62; mirrored in SKILL-cn.md, lines 5 and 54-62
Vulnerability Type: Supply-chain dependency execution without cryptographic integrity verification
Risk Level: Medium

Complete Code Snippet

From SKILL.md:

yaml
metadata: {"clawdbot":{"emoji":"🤖","requires":{"bins":["npm","npx"]},"install":"npm install -g @dlazy/cli@1.0.9","installAlternative":"npx @dlazy/cli@1.0.9","homepage":"https://github.com/dlazyai/cli","source":"https://github.com/dlazyai/cli","author":"dlazyai","license":"see-repo","npm":"https://www.npmjs.com/package/@dlazy/cli","configLocation":"~/.dlazy/config.json","apiEndpoints":["api.dlazy.com","files.dlazy.com"]},"openclaw":{"systemPrompt":"When invoking this skill, use dlazy wan2.6-r2v-flash -h for help."}}
bash
npx @dlazy/cli@1.0.9 <command>
text
Or, if you prefer a global install, the skill's `metadata.clawdbot.install` field declares the exact pinned version (`npm install -g @dlazy/cli@1.0.9`). Review the GitHub source before installing.

The same dependency installation behavior appears in SKILL-cn.md.

Technical Analysis

The skill contains no locally auditable implementation and delegates its functionality to the externally distributed @dlazy/cli npm package. Although the package version is pinned to 1.0.9, the project does not include a lockfile, expected package digest, vendored artifact, signature verification procedure, or reproducible mapping between the reviewed GitHub source and the npm archive that is executed.

Both documented installation mechanisms execute package-controlled code:

  • npx @dlazy/cli@1.0.9 downloads and executes the npm artifact.
  • npm install -g @dlazy/cli@1.0.9 installs it globally and may execute npm lifecycle scripts.

Version pinning protects against automatic upgrades but does not independently establish the integrity or provenance of the na ...[truncated 2295 chars]

Remediation
View remediation

Remediation Suggestions

  1. Distribute a reviewed implementation with the skill or vendor the exact CLI artifact so the executable code is included in the audit scope.
  2. Publish and verify a cryptographic SHA-256 digest or signed provenance attestation for the expected npm package archive before installation or execution.
  3. Include a lockfile with integrity entries for the complete transitive dependency graph and install using a deterministic mechanism such as npm ci.
  4. Verify that the npm archive corresponds to a signed source tag and reproducible build from the referenced GitHub repository.
  5. Avoid global installation. Run the dependency in an isolated, unprivileged container or sandbox with a read-only filesystem and narrowly scoped access to required media files.
  6. Never run the installation as root or administrator. Explicitly document this restriction.
  7. Disable npm lifecycle scripts where they are unnecessary, for example by using --ignore-scripts, after confirming that the CLI functions correctly without them.
  8. Restrict network egress to the documented API endpoints and prevent access to unrelated credentials, home-directory files, SSH material, and cloud metadata endpoints.
  9. Use a short-lived, least-privilege API credential rather than exposing a long-lived organization key to the CLI process.
  10. Add automated dependency scanning, publisher monitoring, provenance verification, and periodic review of the package and its transitive dependencies.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
[English](./SKILL.md) · [中文](./SKILL-cn.md)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该技能的触发关键词包含“生成视频”这类非常通用的表述,且文档未说明明确的触发边界、限定上下文或负例。如此宽泛的触发描述容易与用户的普通多媒体请求重叠,导致技能被意外调用。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest and surrounding documentation repeatedly describe this skill as generating short videos from reference images, but the documented JSON output example shows an output object with type: "image", a .png URL, and mimeType: "image/png". This is an active contradiction in the skill documentation about what the command produces, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL-cn.md (reported line 133)May include surrounding context.

md
## 错误处理

| Code | 错误类型                         | 示例信息                                                                                                                 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | 未授权 (API Key缺失或无效)       | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | 缺少必填参数                     | `error: required option '--prompt <prompt>' not specified`                                                               |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase "generate video" is generic everyday language rather than a narrowly scoped invocation cue. In a markdown skill description, this can cause unintended activation because it lacks constraints tying it specifically to this Wan 2.6 Flash reference-image workflow.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
## Error Handling

| Code | Error Type                         | Example Message                                                                                                          |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | Unauthorized (No API Key)          | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | Missing required parameter         | `error: required option '--prompt <prompt>' not specified`                                                              |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

文件中的关键代理执行指令仅以中文表述,且未说明可根据用户语言偏好切换。这可能构成语言/locale 策略上的硬性约束,尤其在跨语言使用场景下缺少明确的用户选择或 opt-in。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest and surrounding documentation consistently describe this skill as generating short videos from reference images, but the example JSON output lists an output object with type: "image", url: ...result.png, and mimeType: "image/png". This is an active contradiction in the documentation about what the command produces, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.