Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Dlazy Video Replicate

v1.0.4

Extracts the first frame and audio from a video, analyzes it with a prompt, and returns a Seedance 2.0 replicate bundle.

0· 93·1 current·1 all-time
bydlazy@dlazyai

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for dlazyai/dlazy-video-replicate.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Dlazy Video Replicate" (dlazyai/dlazy-video-replicate) from ClawHub.
Skill page: https://clawhub.ai/dlazyai/dlazy-video-replicate
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install dlazy-video-replicate

ClawHub CLI

Package manager switcher

npx clawhub@latest install dlazy-video-replicate
Security Scan
Capability signals
Requires sensitive credentials
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The described functionality (extract first frame/audio, call dLazy API, return hosted URLs) matches the instructions in SKILL.md. However, the skill registry entry lists no required binaries or env vars while SKILL.md metadata explicitly references npm/npx, an install of @dlazy/cli, and a DLAZY API key — an inconsistency between what the registry claims and what the skill actually needs.
!
Instruction Scope
SKILL.md instructs the agent to run the dLazy CLI (dlazy video-replicate) and states that local file paths supplied to the command will be uploaded to oss.dlazy.com. That is expected for a cloud SaaS tool, but the instructions also include 'CRITICAL' agent directives (how to handle insufficient_balance and unauthorized codes) and implicitly assume the agent/user has/will provide local files and the CLI — this grants the skill the ability to cause local files to be transmitted if the agent supplies them. There is no instruction-level restriction preventing sensitive files from being uploaded.
Install Mechanism
There is no formal install spec in the registry entry, but SKILL.md metadata points to an npm package (@dlazy/cli@1.0.6) and suggests using npx or npm install -g. Installing via npx/npm is common and the SKILL.md links to a GitHub repo and npm page, which lowers risk, but relying on npx means code will be fetched from the public registry at runtime — review the referenced GitHub/npm sources before running.
!
Credentials
The skill requires a dLazy API key (can be stored via 'dlazy auth set' in ~/.dlazy/config.json or supplied via DLAZY_API_KEY), but the registry's top-level metadata lists no required environment variables or primary credential. The skill will write credentials to a user config file and/or accept an env var — this is reasonable for a CLI wrapper, but the missing declaration in the registry is an inconsistency that could confuse automated policy checks. No other unrelated secrets are requested.
Persistence & Privilege
The skill is instruction-only and does not request always:true. The only persistent change described is the dLazy CLI storing the API key in the user's config (~/.dlazy/config.json), which is standard for CLIs. There is no indication this skill modifies other skills or system-wide agent settings.
What to consider before installing
Before installing or using this skill: 1) Verify the upstream project: inspect https://github.com/dlazyai/cli and the npm package @dlazy/cli@1.0.6 to ensure code and ownership match expectations. 2) Expect to provide a DLAZY API key; do not pass sensitive or private videos unless you trust dlazy.com's privacy policy because local files will be uploaded to oss.dlazy.com. 3) Prefer 'npx @dlazy/cli@1.0.6' for one-off runs if you don't want a global binary. 4) Be aware the registry entry did NOT declare required binaries or the API key even though SKILL.md requires them — this mismatch is why the skill is flagged as suspicious. 5) If you proceed, create/rotate a dedicated API key with minimal scope, and avoid using account-wide credentials. 6) If you need higher assurance, ask the publisher for a signed release or a link to the exact release tarball and reproduce the install from the verified repo.

Like a lobster shell, security has layers — review code before you run it.

latestvk972a79gw9kkc68fhn83w2skph85ne7b
93downloads
0stars
4versions
Updated 19h ago
v1.0.4
MIT-0

dlazy-video-replicate

English · 中文

Video replicate tool: extracts the first frame and audio from the source video, runs video understanding for a prompt, and returns a Seedance 2.0 replicate bundle (first frame + audio + video).

Trigger Keywords

  • video-replicate

Authentication

All requests require a dLazy API key, configured through the CLI:

dlazy auth set YOUR_API_KEY

The CLI saves the key in your user config directory (~/.dlazy/config.json on macOS/Linux, %USERPROFILE%\.dlazy\config.json on Windows), with file permissions restricted to your OS user account. You can also supply the key per-invocation via the DLAZY_API_KEY environment variable.

Getting Your API Key

  1. Sign in or create an account at dlazy.com
  2. Go to dlazy.com/dashboard/organization/api-key
  3. Copy the key shown in the API Key section

Each key is scoped to your dLazy organization and can be rotated or revoked at any time from the same dashboard.

About & Provenance

You can install on demand without persisting a global binary by running:

npx @dlazy/cli@1.0.6 <command>

Or, if you prefer a global install, the skill's metadata.clawdbot.install field declares the exact pinned version (npm install -g @dlazy/cli@1.0.6). Review the GitHub source before installing.

How It Works

This skill is a thin client over the dLazy hosted API. When you invoke it:

  • Prompts and parameters you provide are sent to the dLazy API endpoint (api.dlazy.com) for inference.
  • Any local file paths you pass to image / video / audio fields are uploaded to dLazy's media storage (oss.dlazy.com) so the model can read them — the same flow as any cloud-based generation API.
  • Generated output URLs returned by the API are hosted on oss.dlazy.com.

This is the standard SaaS pattern; the skill itself does not access network or filesystem resources beyond what the dLazy CLI already handles. See dlazy.com for the full service terms.

Usage

CRITICAL INSTRUCTION FOR AGENT: Execute dlazy video-replicate to get the result.

dlazy video-replicate -h

Options:
  --videos <videos...>                 Videos [video: url or local path]
  --durationSeconds <durationSeconds>  Duration (s)
  --input <spec>                       JSON payload: inline string, @file, or - (stdin)
  --dry-run                            Print payload + cost estimate without calling API
  --no-wait                            Return generateId immediately for async tasks
  --timeout <seconds>                  Max seconds to wait for async completion (default: "1800")
  -h, --help                           display help for command

Output Format

{
  "ok": true,
  "kind": "urls",
  "data": {
    "urls": [
      "https://oss.dlazy.com/result.mp4"
    ]
  }
}

Examples

dlazy video-replicate --prompt 'prompt content' 

Error Handling

CodeError TypeExample Message
401Unauthorized (No API Key)ok: false, code: "unauthorized", message: "API key is missing or invalid"
501Missing required parametererror: required option '--prompt <prompt>' not specified
502Local file read errorError: Image file/Video file not found: C:\path\to\your\file
503API request failed (no balance)ok: false, code: "insufficient_balance"
503API request failed (server error)HTTP status code error (500 server crash)
504Asynchronous task execution failed=== Generation Failed === / {Specific error reason returned by backend, for example "Prompt violates safety policy"}

AGENT CRITICAL INSTRUCTION:

  1. If the execution result returns code: "insufficient_balance", you MUST explicitly inform the user that their credits are insufficient and guide them to recharge: https://dlazy.com/dashboard/organization/settings?tab=credits
  2. If the execution result returns code: "unauthorized" or indicates missing API key, you MUST inform the user to get their API key from https://dlazy.com/dashboard/organization/api-key and save it using dlazy auth set <key> and resume the task.

Tips

Visit https://dlazy.com for more information.

Comments

Loading comments...