Back to skill

Security audit

网站转视频 Website to Video

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed dLazy SaaS integration for turning website links into videos, with external API use and optional file upload clearly described.

Before installing, be aware that this sends prompts, website/link context, and any explicitly attached files to dLazy's hosted service, and it stores a dLazy API key locally unless you provide it per run with an environment variable. Use it when you intend to use dLazy for website-to-video generation, and avoid attaching private files unless you are comfortable uploading them to that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad English phrases like 'promo video', 'social ad', and 'product demo' that can match many ordinary user requests outside the intended website-to-video context. In an agent-routing system, this can cause unintended invocation of a third-party SaaS-backed skill, leading to unnecessary data transfer, confusing behavior, or accidental use of external services when the user did not explicitly ask for this tool.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.