Back to skill

Security audit

Dlazy Wan2.6 R2v

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed wrapper for dLazy video generation, with expected cloud upload, API-key, and npm CLI risks but no artifact evidence of hidden or malicious behavior.

Before installing, review the dLazy CLI source or prefer the npx path over a global install, only pass media files you intend to upload to dLazy, and use a revocable API key or DLAZY_API_KEY when possible. The broad trigger wording may make the skill activate for generic video-generation requests, so confirm it is the dLazy Wan 2.6 R2V workflow before using it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Execution of an Unverified Third-Party npm CLI

Content
View full analysis
``` Or, if you prefer a global install, the skill's `metadata.clawdbot.install` field declares the exact pinned version (`npm install -g @dlazy/cli@1.0.9`). Review the GitHub source before installing. ``` The Chinese-language copy contains the same executable dependency declarations at `SKILL-cn.md:5` and `SKILL-cn.md:60-66`: ```yaml metadata: {"clawdbot":{"emoji":"🤖","requires":{"bins":["npm","npx"]},"install":"npm install -g @dlazy/cli@1.0.9","installAlternative":"npx @dlazy/cli@1.0.9","homepage":"https://github.com/dlazyai/cli","source":"https://github.com/dlazyai/cli","author":"dlazyai","license":"see-repo","npm":"https://www.npmjs.com/package/@dlazy/cli","configLocation":"~/.dlazy/config.json","apiEndpoints":["api.dlazy.com","files.dlazy.com"]},"openclaw":{"systemPrompt":"当调用此技能时,可以使用 dlazy wan2.6-r2v -h 查看帮助信息。"}} ``` ```bash npx @dlazy/cli@1.0.9 ``` ### Technical Analysis The Skill instructs the agent to download and execute `@dlazy/cli@1.0.9` from the npm registry. The ...[truncated 2706 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
[English](./SKILL.md) · [中文](./SKILL-cn.md)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

该文件是 markdown,适用 SQP-1。触发关键词中包含“wan 2.6”“生成视频”等宽泛短语,尤其“生成视频”属于常见能力描述,未限定必须使用 dLazy CLI、Wan 2.6 R2V、参考图输入等上下文,容易导致技能被误触发。

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL-cn.md (reported line 132)May include surrounding context.

md
## 错误处理

| Code | 错误类型                         | 示例信息                                                                                                                 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | 未授权 (API Key缺失或无效)       | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | 缺少必填参数                     | `error: required option '--prompt <prompt>' not specified`                                                               |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file defines activation keywords, so SQP-1 applies. The phrase 'generate video' is generic everyday task language and does not clearly constrain invocation to the dLazy Wan 2.6 reference-image-to-video workflow, increasing the chance of unintended activation.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
## Error Handling

| Code | Error Type                         | Example Message                                                                                                          |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401  | Unauthorized (No API Key)          | `ok: false, code: "unauthorized", message: "API key is missing or invalid"`                                                              |
| 501  | Missing required parameter         | `error: required option '--prompt <prompt>' not specified`                                                              |

Static analysis

No suspicious patterns detected.