Prompt Finder

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned prompts.chat search skill, with the main risk being that search terms are sent to an external service.

Install if you are comfortable with search queries being sent to prompts.chat. Do not include passwords, tokens, private customer data, unreleased product details, or other confidential terms in searches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill explicitly searches prompts.chat, but the user-facing description around usage does not clearly warn that user-entered query terms will be sent to an external third-party service. This can expose sensitive or proprietary search terms off-platform, especially if users assume the search is local or platform-native.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal