Security audit
一图裂变套图 Fission Pattern
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed e-commerce image-generation workflow that uses a pinned dLazy CLI and uploads only user-supplied image inputs for cloud generation.
Before installing, understand that product images and prompts you provide will be sent to dLazy's cloud service, generated outputs are hosted by dLazy, and using the CLI requires a dLazy API key that may be saved locally. Prefer npx if you do not want a global install, and review the third-party CLI and service terms for your data and cost requirements.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
