Back to skill

Security audit

一键去水印去文字 Remove Watermark

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed wrapper for a cloud image-editing service, with the main privacy consideration that images and prompts are uploaded to dLazy.

Install only if you are comfortable using dLazy as a cloud processor for the selected images. Do not submit confidential, regulated, rights-sensitive, or third-party-owned material unless you have permission, and review the pinned CLI/source if your environment has strict supply-chain rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
96% confidence
Finding
The skill begins with usage guidance and examples for removing watermarks before prominently warning that prompts and images are uploaded to dLazy-hosted services. Users may therefore provide sensitive or proprietary images without understanding that local files and prompts are transmitted to third-party infrastructure. In an image-processing skill, this omission is a real privacy and data-handling risk even if the upload behavior is later documented.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.