Back to skill

Security audit

Dlazy Audio音频生成

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed dLazy audio-generation wrapper, but it needs review because it gives risky credential, upload, and privilege guidance.

Review before installing. Use device login or a narrowly scoped environment variable instead of typing API keys into commands, avoid running the agent or dlazy CLI as administrator, and do not provide sensitive or regulated local media unless you are comfortable uploading it to dLazy-hosted services.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:112
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 112, 195, and 264
Vulnerability Type: Credential exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

Line 112:

bash
dlazy auth set YOUR_API_KEY

Line 195 recommends the same command as an authentication option:

bash
dlazy auth set YOUR_API_KEY

Line 264 repeats the recommendation for persistent configuration:

bash
dlazy auth set YOUR_API_KEY

Technical Analysis

The Skill instructs users to provide a dLazy API key directly as a command-line argument. Secrets supplied this way can be exposed through shell-history files, terminal logging, process monitoring, audit systems, support bundles, or process-listing interfaces available to other local users.

Although the document separately states that API keys must not be logged or exposed, this authentication method does not reliably satisfy that requirement. Persistence of the key in the dLazy configuration also depends on the external CLI correctly enforcing restrictive file permissions.

Attack Path

  1. A user replaces YOUR_API_KEY with a valid organization API key and runs the documented command.
  2. The shell records the complete command in its history, or a local monitoring mechanism captures the process arguments.
  3. Another local user, malicious process, administrator, diagnostic collector, or attacker with access to copied history files retrieves the key.
  4. The attacker authenticates to the dLazy service using the compromised credential.
  5. The attacker consumes organization credits or accesses any service capabilities authorized to that key until it is revoked.

Impact Assessment

Exploitation does not directly grant local operating-system privileges. It can grant the attacker the remote service permissions assigned to the exposed key. Potential consequences include unauthorized API use, consumption of paid c ...[truncated 260 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace command-line secret entry with an interactive, no-echo authentication prompt.
  • Where supported, accept the key through standard input or an operating-system credential manager.
  • If an environment variable is required, scope it to a single process rather than exporting it for an entire long-lived shell session.
  • Explicitly warn users not to place API keys in command arguments, scripts, copied terminal transcripts, or shell-history files.
  • Ensure persisted credentials are stored with owner-only permissions and reject configuration files with unsafe permissions.
  • Recommend narrowly scoped, short-lived keys where the service supports them.
  • Add instructions for immediately rotating a key that may have appeared in shell history or logs.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:361
Finding

Unnecessary Recommendation to Run with Administrator Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 361
Vulnerability Type: Violation of least privilege
Risk Level: Medium

Vulnerable Code

Complete Markdown table row, rendered in English:

text
| Insufficient permissions | The current user lacks read/write permission | Check file permissions and run as administrator |

Technical Analysis

The troubleshooting guidance recommends running as an administrator when a file operation encounters insufficient permissions. Audio generation, media upload, credential configuration, and writing output files do not inherently require system-wide administrative privileges.

Elevating the entire Agent or dlazy CLI grants substantially more authority than necessary. This increases the consequences of a compromised executable, unsafe path resolution, malicious local input, CLI vulnerability, or unintended file operation. The correct response is normally to use a user-owned output location or narrowly correct ownership and permissions for the specific resource.

Attack Path

  1. The user encounters a permission error while reading an input file or writing generated output.
  2. Following the Skill guidance, the user restarts the Agent, terminal, or dlazy process with administrator privileges.
  3. The elevated environment resolves and runs a compromised or attacker-controlled executable from the command search path, or the legitimate CLI processes malicious input while elevated.
  4. The process performs file, credential, or network operations with administrator authority.
  5. Depending on the executable or vulnerability involved, the attacker can modify protected files, access data unavailable to the normal user, or establish broader system compromise.

This path requires a malicious executable, vulnerable CLI, or other attacker-controlled execution condition in addition to the documented elevation recommendation. The recommendation nevertheless removes an im ...[truncated 553 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the recommendation to run the Agent or CLI as an administrator.
  • Direct users to select a user-owned input and output directory.
  • Diagnose the exact inaccessible file or directory before changing permissions.
  • Correct ownership or permissions only for the required resource, using the minimum necessary access rights.
  • Avoid recursive permission changes and globally writable directories.
  • Preserve privilege separation for API authentication, media uploads, and generated output handling.
  • If an operation genuinely requires elevation, isolate that single documented operation instead of elevating the entire Agent session or network-enabled CLI.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use the skill whenever the user needs '视频处理、音频编辑、媒体转换、配音生成', which spans several broad, common media tasks well beyond the skill's actual audio-generation scope. Because the trigger scope is not narrowly constrained and lacks negative examples beyond copyright content, this could cause unintended invocation for general video or media-editing requests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly tells users to set API credentials via a raw command line argument (dlazy auth set YOUR_API_KEY) while also stating keys must never be accepted, echoed, or stored from chat input. Command-line secrets are often exposed through shell history, process listings, terminal recordings, and logs, so this guidance increases the chance of credential leakage even if the intent is not malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that local image/video/audio paths are automatically uploaded to dLazy-hosted media storage, but this data transmission is not surfaced as a prominent upfront warning near usage and activation guidance. Users may unintentionally send sensitive local files to a third-party service, creating confidentiality and compliance risks, especially in enterprise or regulated environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.