Back to skill

Security audit

Mega Prompt Optimizer

Security checks across malware telemetry and agentic risk

Overview

This prompt optimizer has no executable installer, but its bundled prompt library includes unsafe templates that could be recommended during normal use.

Install only if you will review every optimized prompt before using it. Keep the optimizer off by default, remove or filter unsafe templates before shared or production use, and avoid using it for jailbreaks, memory/system-prompt disclosure, unauthorized security testing, credential handling, or regulated medical/legal/financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file marketed as a prompt-optimizer library is actually a broad, uncurated prompt dump containing thousands of unrelated role prompts. That creates a prompt-injection supply-chain risk: the skill can surface or reuse unsafe instructions far outside its declared scope, making harmful behavior or policy bypass much more likely when prompts are matched automatically.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
This library includes unsafe or policy-evasion capabilities unrelated to prompt optimization, which means the skill may retrieve adversarial prompts under benign-looking matching logic. In the context of a prompt-optimizer, embedding such prompts is especially dangerous because the system's purpose is to transform user requests, potentially amplifying malicious instructions.

Context-Inappropriate Capability

High
Confidence
100% confidence
Finding
The DAN-style jailbreak prompt explicitly instructs a model to ignore restrictions and fabricate capabilities. Keeping jailbreak templates in a prompt library used by an agent materially increases the chance of safety bypass, instruction hierarchy confusion, and downstream harmful outputs.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Prompts that ask for verbatim memory or prior-conversation disclosure directly target sensitive retained context. In an optimization skill, accidental retrieval of these prompts could cause unauthorized exposure of user data, system memory, or confidential context.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The corpus includes many medical, legal, financial, and security-operation prompts unrelated to prompt optimization. Even if individually benign, their presence broadens the attack surface and enables unsafe domain crossover where a simple optimization request could be transformed into high-risk advice generation.

Ssd 1

High
Confidence
100% confidence
Finding
The DAN prompt is an explicit role-play jailbreak that tries to override safety controls, suppress refusals, and encourage fabricated compliance. In a prompt-optimization skill, such content is dangerous because the system may reframe or recommend it as a 'better prompt,' effectively weaponizing the library against the host model's safeguards.

Ssd 4

High
Confidence
99% confidence
Finding
The terminal-escape scenario is effectively a staged prompt for eliciting commands aimed at escaping containment or reaching external systems. Even though framed as pretend terminal interaction, it is a strong escalation artifact that can induce users or agents to perform risky system actions.

Ssd 3

High
Confidence
99% confidence
Finding
A prompt requesting verbatim memory contents is a direct confidentiality threat because it targets internal retention and prior conversation data. In a library consumed by an optimizer, this can facilitate unauthorized disclosure even when the user's original intent had nothing to do with memory extraction.

Ssd 3

Medium
Confidence
95% confidence
Finding
A prompt asking for a summary of everything known about the user encourages broad extraction of personal profile information from conversation history. While less severe than verbatim memory dumping, it still creates a privacy risk if surfaced automatically or without explicit, informed user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.install_untrusted_source

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/prompt_library_lite.json:24424

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
references/prompt_library_lite.json:9913