Back to skill

Security audit

Erdmannsilva Perplexity

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward Perplexity web-search helper that sends user-provided queries to Perplexity using the required API key.

Install only if you are comfortable providing a Perplexity API key and sending search queries to Perplexity. Avoid putting secrets, private personal data, or confidential business information in search queries, and verify the publisher if provenance matters to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill documentation describes web search behavior but does not clearly warn users that their prompts are transmitted to the external Perplexity API. This creates a real privacy and data-handling risk because users may provide sensitive, proprietary, or regulated information under the assumption that processing is local or agent-contained.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.