LrshuAI Text To Image

PassAudited by VirusTotal on Apr 3, 2026.

Findings (1)

The skill contains a Python script (`script/invoke_model.py`) that encodes local files into base64 and transmits them along with environment-stored API keys to a remote endpoint (dlazy.com). Most notably, the `SKILL.md` file contains a 'CRITICAL INSTRUCTION' explicitly directing the AI agent to bypass the standard `openclaw run` execution method in favor of direct system calls. This attempt to circumvent the framework's standard execution path, combined with the capability to read and exfiltrate local file data, poses a risk of evading security controls or logging.