Back to skill

Security audit

商品换背景 Item Change Background

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed product-image background replacement workflow that uses the dLazy CLI and cloud API, with no artifact evidence of hidden or unrelated behavior.

Before installing, users should understand that product images and prompts are sent to dLazy's hosted service, generated files may be stored on dLazy-hosted URLs, and `dlazy login` or `dlazy auth set` stores an organization API key locally. Use the pinned CLI version, review the CLI source if needed, and avoid passing confidential product images unless dLazy's terms and access controls fit the use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.