Back to skill

Security audit

Dlazy Gen Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed image-generation helper that uses the dlazy CLI and cloud API, with some scope and privacy caveats users should notice.

Install only if you are comfortable with a global dlazy CLI, a dlazy account/API key, and sending prompts or selected images to dlazy's cloud service. Avoid using confidential, regulated, or personal images unless that external processing is acceptable, and keep the API key out of chats, logs, screenshots, and source repositories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger condition is so broad ('需要AI模型调用、智能对话、Agent编排、LLM应用时使用') that an agent may invoke this skill for many unrelated tasks. In a tool-enabled environment with exec and external API usage, unintended invocation can cause accidental command execution, image upload, or third-party API calls outside the user's actual intent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to set and persist an API key but does not clearly warn against exposing credentials in prompts, logs, screenshots, shared terminals, or checked-in config files. This increases the chance of credential leakage, especially because the skill is designed for local CLI use and may be used in multi-tool agent sessions where outputs are logged.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill documents cloud-backed image generation and image editing/upload flows but does not clearly disclose that prompts and user-supplied images are transmitted to a third-party service. Users may unknowingly send sensitive text, proprietary designs, or personal images to an external provider, creating privacy, confidentiality, and compliance risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.