Back to skill

Security audit

一键替换服装面料 Fabric on Body

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed image-generation workflow that uploads user-selected garment and fabric images to dLazy to create fabric replacement previews.

Before installing or using this skill, confirm you are comfortable sending garment references, fabric swatches, prompts, and generated outputs to dLazy cloud services. Avoid uploading confidential designs, proprietary samples, customer imagery, or regulated data unless you have authorization and have reviewed dLazy's terms and retention practices. Prefer the pinned npx command if you do not want a persistent global CLI install, and rotate or revoke the dLazy API key if it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill routes prompts and uploaded local images to third-party dLazy services for inference and hosting, but the top-level skill description does not clearly warn users about this data transfer at the point of use. This can cause users to provide sensitive product imagery or proprietary design assets without informed consent, creating privacy, confidentiality, and compliance risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.