Back to skill

Security audit

Dlazy Audio音频生成

Security checks across malware telemetry and agentic risk

Overview

This skill is a hosted audio-generation helper that clearly relies on the dLazy CLI, API key authentication, and external dLazy services.

Install only if you are comfortable sending prompts and any selected audio, image, or video files to dLazy-hosted services. Do not use voice samples, private media, secrets, or sensitive internal content unless you intend to upload them, and only provide callback URLs you control and trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill instructs use of external hosted APIs, supports local file uploads, and accepts a `callback_url`, but does not prominently warn users that their prompts, files, and callback destinations may send data off-platform. This creates a real risk of unintentional disclosure of sensitive local content or metadata to third-party infrastructure, especially in an agent context with read/exec/write capabilities.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.