Back to skill

Security audit

换模特换背景 One Shot

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed ecommerce image-editing workflow that uploads user-selected product photos to dLazy to replace models or backgrounds.

Before installing, understand that selected images and prompts are sent to dLazy's hosted service and outputs may be hosted on files.dlazy.com. Use demographic model changes only where you have rights to the source material and the use is lawful, non-discriminatory, and not presented as a real person's endorsement.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill explicitly encourages generating market-specific variants by changing model attributes including skin color and age, but it does not require a user-provided business justification, consent, or fairness guardrails. In context, this enables potentially discriminatory or manipulative audience targeting and synthetic demographic alteration of advertising assets, which raises policy, compliance, and misuse risks even if it is not a classic code-execution issue.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.