Back to skill

Security audit

服装图一键上身 Flat Lay

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed fashion image-generation workflow that uploads user-provided garment/reference images to dLazy and saves generated outputs locally.

Before installing, review dLazy's CLI and service terms, understand that supplied images and prompts are sent to dLazy-hosted services, and avoid using the model-selection filters in ways that discriminate, imply endorsement, or generate inappropriate images involving minors.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises very broad activation phrases such as “平铺图变模特图”, “服装上身”, “AI 试穿”, and “一键做同款”, which are common user intents that could cause the skill to trigger in contexts beyond its intended scope. Over-broad routing increases the chance the agent invokes this skill when a user did not explicitly request image generation or when a safer/more appropriate workflow should have been used.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill explicitly supports selecting or filtering models by protected or sensitive attributes, including age bands (notably children), skin color/ethnicity proxies, sex/gender, and body type, without any visible consent, policy gating, or necessity checks. In this context, that creates risk of discriminatory targeting, inappropriate generation involving minors, and unsafe personalization defaults embedded directly into the skill behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.