Back to skill

Security audit

Dali by Lulu

Security checks across malware telemetry and agentic risk

Overview

The skill is purpose-aligned but should be reviewed because it tells the agent to automatically send prompts to an external Dali service without confirmation, including pasted prompts.

Review this skill before installing if your prompts may include confidential work, client details, proprietary ideas, or personal information. It does not appear destructive or deceptive, but it is designed to call an external prompt-scoring service automatically rather than asking each time.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

High
Confidence
95% confidence
Finding
The activation criteria are broad enough to trigger on many ordinary creative requests, causing the skill to intervene and potentially send user content to the external Dali MCP even when the user did not explicitly ask for prompt scoring. In this context, the risk is primarily over-collection and unexpected third-party disclosure rather than direct code execution, but it still creates a meaningful privacy and consent issue.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill description does not warn users that their prompts may be transmitted to an external MCP endpoint for scoring. Because prompts can contain sensitive business ideas, personal details, or unpublished creative work, this omission undermines informed consent and can lead to unintended data sharing with a third party.

Missing User Warnings

Medium
Confidence
99% confidence
Finding
The instruction to automatically score any pasted raw prompt without asking the user directs unsolicited transmission of user content to an external service. This is especially risky because pasted prompts may include confidential project details, client material, or proprietary creative assets, and the user is given no warning or chance to refuse.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
- Keywords: generate, create, make, draw, render, animate, illustrate, design, produce
- Media types: image, photo, picture, video, clip, footage, reel, scene, animation

Also activate when a user pastes a raw prompt without asking to score it — score it anyway.

## The Flow
Confidence
90% confidence
Finding
without asking

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.