Back to skill

Security audit

Dlazy Generate

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent media-generation purpose, but it should be reviewed because it broadly triggers external CLI execution and persistent API-key handling with inconsistent setup guidance.

Install only if you trust the dLazy CLI and are comfortable sending prompts and selected media files to dLazy. Prefer a reviewed local installation over ad hoc npx/global installs, avoid pasting API keys into chat or command arguments, use a per-process environment secret when possible, and revoke or rotate the dLazy key after use on shared or agent-managed machines.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:58
Finding

Execution of an Unverified Third-Party npm Package

Content
View full analysis
``` Or, if you prefer a global install, the skill's `metadata.SkillHub.install` field declares the exact pinned version (`npm install -g @dlazy/cli@1.2.0`). Review the GitHub source before installing. ``` ### Technical Analysis The skill instructs the agent to download and execute `@dlazy/cli` from the npm registry through `npx`, or to install it globally. The package source is not included in the audited project, so its runtime behavior, transitive dependencies, and npm lifecycle scripts cannot be verified from the artifact. Version provenance is also inconsistent: the document claims that the package is pinned to `1.0.9`, while both executable installation examples use `1.2.0`. No lockfile, package integrity hash, verified source URL, or signature is provided. Version pinning alone does not establish package integrity if the registry account, package distribution channel, or a transitive dependency is compromised. Running `npx` creates a code-execution channel for externally distributed package code. A global installation increases persistence and makes the executable available outside the immediate skill invocation. ### Attack Path 1. A user asks the agent to generate image, video, or audio content. 2. The skill directs the agent to run `npx @dlazy/cli@1.2.0` or install that package globally. 3. npm retrieves the package and its dependencies from an external registry. 4. Package lifecycle scripts and CLI code execute with the privileges of the agent process. 5. If the package, publisher account, registry response, or a transitive depe ...[truncated 1214 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:36
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis
2. If the execution result returns `code: "unauthorized"` or indicates missing API key, you MUST inform the user to get their API key from and save it using `dlazy auth set ` and resume the task. ``` ### Technical Analysis Passing an API key directly as a command-line argument can expose it through several operating-system and automation surfaces: - Shell command history. - Process listings available while the command is running. - Terminal session capture. - Agent execution transcripts and diagnostic logs. - Process-monitoring or audit tooling. - Error reports that reproduce the executed command. Although the document states that the resulting configuration file is protected by user-only permissions, those permissions do not prevent exposure before the key is written. The alternative use of `DLAZY_API_KEY` can also leak the key if the environment is inherited by unrelated child processes or captured in diagnostic output. ### Attack Path 1. The CLI reports that authentication is missing or invalid. 2. The skill tells the user or agent to execute `dlazy auth set `. 3. The actual API key is substituted directly into the command. 4. The command is retained in she ...[truncated 974 chars]
Remediation
View remediation
` flow with a secure command such as `dlazy auth set`, followed by a hidden interactive prompt. ]]>
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are extremely broad and overlap with normal user requests such as 'generate' or 'create image, video, audio'. In agent environments, this can cause the skill to activate unintentionally and steer routine prompts into executing the external CLI, increasing the chance of unintended command execution, data transfer to a third-party API, and unexpected billing.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill instructs users to authenticate via a flow that automatically saves the API key to local CLI config, creating persistent credentials on the host. In shared, ephemeral, or agent-managed environments, this can leave reusable secrets behind for later sessions or other processes, increasing the risk of credential misuse and unauthorized API consumption.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
## Trigger Keywords

* generate
* create image, video, audio
* multimodal generation

## Authentication

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states that all requests require a dLazy API key, but later claims the skill needs no extra API key except where explicitly noted. This inconsistency can mislead users or agents about authentication requirements, causing failed runs, insecure workarounds, or accidental reliance on cached credentials already present on the system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The summary and description are written in a mixed Chinese/English form, and the document continues in mixed-language sections, but it does not state that the user can choose their preferred language for interaction. This can violate language/locale policy expectations when a skill implicitly defaults to a language presentation without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.