Back to skill

Security audit

一图裂变套图 Fission Pattern

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed e-commerce image-generation workflow that uses a pinned dLazy CLI and uploads only user-supplied image inputs for cloud generation.

Before installing, understand that product images and prompts you provide will be sent to dLazy's cloud service, generated outputs are hosted by dLazy, and using the CLI requires a dLazy API key that may be saved locally. Prefer npx if you do not want a global install, and review the third-party CLI and service terms for your data and cost requirements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.