Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Dlazy Banana Pro

v1.0.5

Generate/edit images with Nano Banana Pro. Supports text-to-image and image-to-image.

0· 535·1 current·1 all-time
bydlazy@dlazyai

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for dlazyai/dlazy-banana-pro.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Dlazy Banana Pro" (dlazyai/dlazy-banana-pro) from ClawHub.
Skill page: https://clawhub.ai/dlazyai/dlazy-banana-pro
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required binaries: npm, npx
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install dlazy-banana-pro

ClawHub CLI

Package manager switcher

npx clawhub@latest install dlazy-banana-pro
Security Scan
Capability signals
Requires sensitive credentials
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims to be a thin CLI client for dLazy's Banana Pro image API, and the metadata (npm package @dlazy/cli, api endpoints api.dlazy.com and oss.dlazy.com) aligns with that purpose. Requiring npm/npx is reasonable for installing/using the CLI. However, there are minor inconsistencies: the SKILL.md lists version 1.0.3 while registry metadata lists 1.0.5 and the install metadata pins @dlazy/cli@1.0.6. These mismatched versions are unexpected for well-curated packages and should be confirmed.
Instruction Scope
Runtime instructions are narrowly scoped to running the dlazy CLI and uploading any user-specified local image files to the service — this is expected for image-to-image workflows. The SKILL.md explicitly tells the agent to run `dlazy banana-pro`. A portion of the SKILL.md is truncated (cut off mid-sentence), reducing clarity about full agent behavior and error handling; that missing text should be recovered and reviewed before use.
Install Mechanism
There is no top-level install spec in the registry (instruction-only skill), but the SKILL.md metadata suggests installing the npm package @dlazy/cli@1.0.6 or using npx. Installing from npm is a standard mechanism (moderate trust), not an arbitrary URL download. Because the registry entry does not itself provide an install spec, confirm whether you should run `npx @dlazy/cli@1.0.6` or `npm install -g @dlazy/cli@1.0.6` and inspect the npm package/GitHub source before installing.
Credentials
The skill does not require unrelated credentials. It reasonably requires a dLazy API key (optionally via DLAZY_API_KEY or stored in ~/.dlazy/config.json). Storing the API key in the user's config file is expected for CLI tools; verify file permissions and the key's scope before use.
Persistence & Privilege
The skill is not force-enabled (always:false) and does not request elevated platform privileges. It will persist only normal CLI configuration in the user's home (~/.dlazy/config.json) if you run `dlazy auth set`. This is standard for CLI-based SaaS clients.
What to consider before installing
This skill appears to be a straightforward CLI wrapper for a cloud image-generation service, but take these precautions before installing or invoking it: 1) Confirm provenance: inspect the GitHub repo (https://github.com/dlazyai/cli) and the npm package @dlazy/cli@1.0.6 to ensure the code matches the skill's claims. 2) Prefer on-demand usage with npx (npx @dlazy/cli@1.0.6) instead of a global npm install if you don't want to persist new binaries. 3) Verify the API key scope and store it only if you trust the service; check ~/.dlazy/config.json permissions and rotate/revoke keys if needed. 4) Do not upload sensitive images you wouldn't want stored on an external service (oss.dlazy.com). 5) Note the SKILL.md is truncated and version numbers mismatch (1.0.3/1.0.5/1.0.6); ask the publisher or check the upstream repo to resolve these inconsistencies before proceeding. If you need higher assurance, obtain the CLI source and audit it locally before running it.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🤖 Clawdis
Binsnpm, npx
latestvk9718jfj9rk1p8bahyvpd2shkx85m0pz
535downloads
0stars
6versions
Updated 21h ago
v1.0.5
MIT-0

dlazy-banana-pro

English · 中文

Generate/edit images with Nano Banana Pro. Supports text-to-image and image-to-image.

Trigger Keywords

  • nano banana pro, nano banana
  • generate image, edit image
  • text to image, image to image

Authentication

All requests require a dLazy API key, configured through the CLI:

dlazy auth set YOUR_API_KEY

The CLI saves the key in your user config directory (~/.dlazy/config.json on macOS/Linux, %USERPROFILE%\.dlazy\config.json on Windows), with file permissions restricted to your OS user account. You can also supply the key per-invocation via the DLAZY_API_KEY environment variable.

Getting Your API Key

  1. Sign in or create an account at dlazy.com
  2. Go to dlazy.com/dashboard/organization/api-key
  3. Copy the key shown in the API Key section

Each key is scoped to your dLazy organization and can be rotated or revoked at any time from the same dashboard.

About & Provenance

You can install on demand without persisting a global binary by running:

npx @dlazy/cli@1.0.6 <command>

Or, if you prefer a global install, the skill's metadata.clawdbot.install field declares the exact pinned version (npm install -g @dlazy/cli@1.0.6). Review the GitHub source before installing.

How It Works

This skill is a thin client over the dLazy hosted API. When you invoke it:

  • Prompts and parameters you provide are sent to the dLazy API endpoint (api.dlazy.com) for inference.
  • Any local file paths you pass to image / video / audio fields are uploaded to dLazy's media storage (oss.dlazy.com) so the model can read them — the same flow as any cloud-based generation API.
  • Generated output URLs returned by the API are hosted on oss.dlazy.com.

This is the standard SaaS pattern; the skill itself does not access network or filesystem resources beyond what the dLazy CLI already handles. See dlazy.com for the full service terms.

Usage

CRITICAL INSTRUCTION FOR AGENT: Run the dlazy banana-pro command to get results.

dlazy banana-pro -h

Options:
  --prompt <prompt>                    Prompt
  --images <images...>                 Images [image: url or local path] (max 1) [default: ]
  --aspectRatio <aspectRatio>          Aspect Ratio [default: auto] (choices: "auto", "1:1", "4:3", "3:4", "16:9", "9:16", "21:9")
  --imageSize <imageSize>              Image Size [default: 1K] (choices: "1K", "2K", "4K")
  --input <spec>                       JSON payload: inline string, @file, or - (stdin)
  --dry-run                            Print payload + cost estimate without calling API
  --no-wait                            Return generateId immediately for async tasks
  --timeout <seconds>                  Max seconds to wait for async completion (default: "1800")
  -h, --help                           display help for command

Output Format

{
  "ok": true,
  "kind": "urls",
  "data": {
    "urls": [
      "https://oss.dlazy.com/result.mp4"
    ]
  }
}

Command Examples

# text to image:
dlazy banana-pro --prompt 'prompt text' --image '/path/to/image.png'

# image to image:
dlazy banana-pro --prompt 'prompt text' --image 'https://oss.dlazy.com/image.png'

Error Handling

CodeError TypeExample Message
401Unauthorized (No API Key)ok: false, code: "unauthorized", message: "API key is missing or invalid"
501Missing required parametererror: required option '--prompt <prompt>' not specified
502Local file read errorError: Image file/Video file not found: C:\path\to\your\file
503API request failed (no balance)ok: false, code: "insufficient_balance"
503API request failed (server error)HTTP status code error (500 server crash)
504Asynchronous task execution failed=== Generation Failed === / {Specific error reason returned by backend, for example "Prompt violates safety policy"}

AGENT CRITICAL INSTRUCTION:

  1. If the execution result returns code: "insufficient_balance", you MUST explicitly inform the user that their credits are insufficient and guide them to recharge: https://dlazy.com/dashboard/organization/settings?tab=credits
  2. If the execution result returns code: "unauthorized" or indicates missing API key, you MUST inform the user to get their API key from https://dlazy.com/dashboard/organization/api-key and save it using dlazy auth set <key> and resume the task.

Tips

Visit https://dlazy.com for more information.

Comments

Loading comments...