Perplexity Wrapped Search
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is designed for AI-powered web search via the Perplexity API, which aligns with its stated purpose. It makes network calls exclusively to the legitimate Perplexity API endpoint and handles the API key via environment variables. Crucially, the `SKILL.md` documentation and `scripts/search.mjs` code include explicit and robust measures to prevent prompt injection from external content, such as untrusted content boundaries, character folding, and direct instructions to the OpenClaw agent to treat all returned content as untrusted data. There is no evidence of data exfiltration, malicious execution, persistence, or prompt injection attempts within the skill's own instructions or code.
