Is "PromptProtect" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.0.1

PromptProtect acts as a protective shield for businesses when using GenAI tools by serving as a first line of defense against accidental data leaks. The extension automatically detects and blocks or redacts sensitive information such as passwords, API keys, credit card numbers, IP addresses, and other PII, PCI, or PHI before it is sent to AI systems or external services. By catching careless pastes and sensitive data exposure in real time, PromptProtect enables employees to safely use AI tools while preventing confidential enterprise data from leaving the organization. PromptProtect operates directly inside the browser and captures prompts before they are submitted to AI platforms such as ChatGPT, Gemini and other generative AI tools. The extension analyzes the text entered by the user, identifies sensitive information using multiple detection methods, and applies organizational policies to either block the submission or automatically redact sensitive data. This happens instantly and requires no manual configuration from employees other than signing in. In addition to AI tools, PromptProtect also monitors text inputs on search engines to prevent employees from accidentally entering sensitive company information into public search queries or external websites. If sensitive information is detected in a search query or form submission, the extension can alert the user, redact the data, or block the submission according to the organization's security policies. Administrators can centrally manage security rules using Role-Based Access Control (RBAC). Organizations can define custom policies that determine how different types of sensitive data should be handled for different employee roles. Policies can include blocking prompts, automatically redacting sensitive fields, or allowing specific data categories depending on the role and business need. PromptProtect also supports enterprise identity integration through SAML and LDAP, allowing organizations to deploy and enforce the extension across their workforce using existing identity providers. The PromptProtect Admin Portal provides centralized visibility and governance over all AI and monitored web interactions within the organization. Administrators can view real-time telemetry including total prompts scanned, detected risk categories such as PII, PCI, PHI, secrets, and infrastructure data, and user activity across AI platforms. Detailed audit logs allow administrators to review original prompts, redacted prompts, and AI responses to investigate potential data exposure incidents. For enterprise security operations, PromptProtect supports SIEM integration, enabling organizations to forward security events and logs to their existing monitoring systems for advanced threat detection, compliance reporting, and incident response. By combining browser-level protection, automated sensitive data detection, enterprise policy enforcement, and centralized visibility, PromptProtect enables organizations to confidently adopt generative AI tools while maintaining strict control over sensitive data. While PromptProtect uses advanced detection techniques to identify sensitive information, no automated system can guarantee perfect detection in every scenario. In some cases, certain sensitive values may not be detected or benign content may be flagged. The detection models and rules are continuously improved and updated over time to increase accuracy and reduce false positives, ensuring stronger protection as the system evolves.

Risk Assessment

Analyzed
84.72
out of 100
HIGH

167 security findings detected across all analyzers

Chrome extension requesting 19 permissions

Severity Breakdown

0
Critical
0
High
119
Medium
48
Low
0
Info

Finding Categories

11
Network
101
IoC Indicators

YARA Rules Matched

9 rules(48 hits)
postinstall system command postinstall obfuscation postinstall file manipulation postinstall network communication postinstall file download postinstall crypto operations postinstall environment access postinstall persistence mechanism AlertStatementsShouldNotBeUsed

Requested Permissions

19 permissions
tabs
Medium
storage
Low
webNavigation
Low
declarativeNetRequest
Low
*://*.google.com/*
Low
*://*.googleapis.com/*
Low
https://grok.com/*
Low
https://chatgpt.com/*
Low
https://claude.ai/*
Low
https://gemini.google.com/*
Low
https://bard.google.com/*
Low
https://www.perplexity.ai/*
Low
https://perplexity.ai/*
Low
https://copilot.microsoft.com/*
Low
https://www.bing.com/chat*
Low
https://www.bing.com/*
Low
https://www.msn.com/*
Low
*://*.msn.com/*
Low
https://ntp.msn.com/*
Low

About This Extension

PromptProtect acts as a protective shield for businesses when using GenAI tools by serving as a first line of defense against accidental data leaks. The extension automatically detects and blocks or redacts sensitive information such as passwords, API keys, credit card numbers, IP addresses, and other PII, PCI, or PHI before it is sent to AI systems or external services. By catching careless pastes and sensitive data exposure in real time, PromptProtect enables employees to safely use AI tools while preventing confidential enterprise data from leaving the organization. PromptProtect operates directly inside the browser and captures prompts before they are submitted to AI platforms such as ChatGPT, Gemini and other generative AI tools. The extension analyzes the text entered by the user, identifies sensitive information using multiple detection methods, and applies organizational policies to either block the submission or automatically redact sensitive data. This happens instantly and requires no manual configuration from employees other than signing in. In addition to AI tools, PromptProtect also monitors text inputs on search engines to prevent employees from accidentally entering sensitive company information into public search queries or external websites. If sensitive information is detected in a search query or form submission, the extension can alert the user, redact the data, or block the submission according to the organization's security policies. Administrators can centrally manage security rules using Role-Based Access Control (RBAC). Organizations can define custom policies that determine how different types of sensitive data should be handled for different employee roles. Policies can include blocking prompts, automatically redacting sensitive fields, or allowing specific data categories depending on the role and business need. PromptProtect also supports enterprise identity integration through SAML and LDAP, allowing organizations to deploy and enforce the extension across their workforce using existing identity providers. The PromptProtect Admin Portal provides centralized visibility and governance over all AI and monitored web interactions within the organization. Administrators can view real-time telemetry including total prompts scanned, detected risk categories such as PII, PCI, PHI, secrets, and infrastructure data, and user activity across AI platforms. Detailed audit logs allow administrators to review original prompts, redacted prompts, and AI responses to investigate potential data exposure incidents. For enterprise security operations, PromptProtect supports SIEM integration, enabling organizations to forward security events and logs to their existing monitoring systems for advanced threat detection, compliance reporting, and incident response. By combining browser-level protection, automated sensitive data detection, enterprise policy enforcement, and centralized visibility, PromptProtect enables organizations to confidently adopt generative AI tools while maintaining strict control over sensitive data. While PromptProtect uses advanced detection techniques to identify sensitive information, no automated system can guarantee perfect detection in every scenario. In some cases, certain sensitive values may not be detected or benign content may be flagged. The detection models and rules are continuously improved and updated over time to increase accuracy and reduce false positives, ensuring stronger protection as the system evolves.

Detailed Findings

60 total

YARA Rule Matches

9 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
24
IP Addresses
2
Domains
75
Strings
101

All Indicators · 101

Domain
detected Domain: ms-auto.flex.flex-row.items-end.gap

XIOC detected Domain: ms-auto.flex.flex-row.items-end.gap

extracted_from_files

Domain
detected Domain: proxyinput.id

XIOC detected Domain: proxyinput.id

extracted_from_files

Domain
detected Domain: i.gd

XIOC detected Domain: i.gd

extracted_from_files

Domain
detected Domain: o.ng

XIOC detected Domain: o.ng

extracted_from_files

Domain
detected Domain: 0.ls

XIOC detected Domain: 0.ls

extracted_from_files

Domain
detected Domain: z.ua

XIOC detected Domain: z.ua

extracted_from_files

Domain
detected Domain: se.py

XIOC detected Domain: se.py

extracted_from_files

Domain
detected Domain: 9a.je

XIOC detected Domain: 9a.je

extracted_from_files

IP
detected IP: 2e::

XIOC detected IP: 2e::

extracted_from_files

Domain
detected Domain: promptprotect.dataelicit.com

XIOC detected Domain: promptprotect.dataelicit.com

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

URL
detected URL: https://www.bing.com/search

XIOC detected URL: https://www.bing.com/search

extracted_from_files

URL
detected URL: https://ntp.msn.com/*

XIOC detected URL: https://ntp.msn.com/*

extracted_from_files

URL
detected URL: https://grok.com/*

XIOC detected URL: https://grok.com/*

extracted_from_files

URL
detected URL: https://chatgpt.com/*

XIOC detected URL: https://chatgpt.com/*

extracted_from_files

URL
detected URL: https://claude.ai/*

XIOC detected URL: https://claude.ai/*

extracted_from_files

URL
detected URL: https://bard.google.com/*

XIOC detected URL: https://bard.google.com/*

extracted_from_files

URL
detected URL: https://perplexity.ai/*

XIOC detected URL: https://perplexity.ai/*

extracted_from_files

URL
detected URL: https://www.bing.com/chat*

XIOC detected URL: https://www.bing.com/chat*

extracted_from_files

URL
detected URL: https://www.perplexity.ai/*

XIOC detected URL: https://www.perplexity.ai/*

extracted_from_files

URL
detected URL: https://copilot.microsoft.com/*

XIOC detected URL: https://copilot.microsoft.com/*

extracted_from_files

URL
detected URL: https://www.bing.com/*

XIOC detected URL: https://www.bing.com/*

extracted_from_files

URL
detected URL: https://www.msn.com/*

XIOC detected URL: https://www.msn.com/*

extracted_from_files

URL
detected URL: https://search.yahoo.com/search?p=

XIOC detected URL: https://search.yahoo.com/search?p=

extracted_from_files

Domain
detected Domain: jdq.sm

XIOC detected Domain: jdq.sm

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://gemini.google.com/*

XIOC detected URL: https://gemini.google.com/*

extracted_from_files

URL
detected URL: https://promptprotect.dataelicit.com

XIOC detected URL: https://promptprotect.dataelicit.com

extracted_from_files

URL
detected URL: https://www.bing.com/search?q=

XIOC detected URL: https://www.bing.com/search?q=

extracted_from_files

URL
detected URL: https://www.google.com

XIOC detected URL: https://www.google.com

extracted_from_files

URL
detected URL: https://www.google.com/search?q=

XIOC detected URL: https://www.google.com/search?q=

extracted_from_files

URL
detected URL: https://duckduckgo.com/?q=

XIOC detected URL: https://duckduckgo.com/?q=

extracted_from_files

URL
detected URL: https://www.ecosia.org/search?q=

XIOC detected URL: https://www.ecosia.org/search?q=

extracted_from_files

URL
detected URL: https://www.baidu.com/s?wd=

XIOC detected URL: https://www.baidu.com/s?wd=

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: location.host

XIOC detected Domain: location.host

extracted_from_files

Domain
detected Domain: bing.com

XIOC detected Domain: bing.com

extracted_from_files

Domain
detected Domain: div.pointer-events-none.select

XIOC detected Domain: div.pointer-events-none.select

extracted_from_files

Domain
detected Domain: nativesend.click

XIOC detected Domain: nativesend.click

extracted_from_files

Domain
detected Domain: t.id

XIOC detected Domain: t.id

extracted_from_files

URL
detected URL: https://api.pp.dataelicit.com

XIOC detected URL: https://api.pp.dataelicit.com

extracted_from_files

Domain
detected Domain: perplexity.ai

XIOC detected Domain: perplexity.ai

extracted_from_files

Domain
detected Domain: copilot.microsoft.com

XIOC detected Domain: copilot.microsoft.com

extracted_from_files

Domain
detected Domain: www.msn.com

XIOC detected Domain: www.msn.com

extracted_from_files

Domain
detected Domain: ntp.msn.com

XIOC detected Domain: ntp.msn.com

extracted_from_files

Domain
detected Domain: google.com

XIOC detected Domain: google.com

extracted_from_files

Domain
detected Domain: googleapis.com

XIOC detected Domain: googleapis.com

extracted_from_files

Domain
detected Domain: msn.com

XIOC detected Domain: msn.com

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Domain
detected Domain: grok.com

XIOC detected Domain: grok.com

extracted_from_files

Domain
detected Domain: chatgpt.com

XIOC detected Domain: chatgpt.com

extracted_from_files

Domain
detected Domain: claude.ai

XIOC detected Domain: claude.ai

extracted_from_files

Domain
detected Domain: gemini.google.com

XIOC detected Domain: gemini.google.com

extracted_from_files

Domain
detected Domain: bard.google.com

XIOC detected Domain: bard.google.com

extracted_from_files

Domain
detected Domain: www.perplexity.ai

XIOC detected Domain: www.perplexity.ai

extracted_from_files

Domain
detected Domain: yandex.com

XIOC detected Domain: yandex.com

extracted_from_files

Domain
detected Domain: window.location.search

XIOC detected Domain: window.location.search

extracted_from_files

Domain
detected Domain: company.com

XIOC detected Domain: company.com

extracted_from_files

Domain
detected Domain: data.data

XIOC detected Domain: data.data

extracted_from_files

Domain
detected Domain: st.email

XIOC detected Domain: st.email

extracted_from_files

Domain
detected Domain: continuebtn.click

XIOC detected Domain: continuebtn.click

extracted_from_files

Domain
detected Domain: loginbtn.click

XIOC detected Domain: loginbtn.click

extracted_from_files

Domain
detected Domain: proxysendbtn.style

XIOC detected Domain: proxysendbtn.style

extracted_from_files

Domain
detected Domain: submit.click

XIOC detected Domain: submit.click

extracted_from_files

Domain
detected Domain: www.google.com

XIOC detected Domain: www.google.com

extracted_from_files

Domain
detected Domain: duckduckgo.com

XIOC detected Domain: duckduckgo.com

extracted_from_files

Domain
detected Domain: www.ecosia.org

XIOC detected Domain: www.ecosia.org

extracted_from_files

Domain
detected Domain: www.baidu.com

XIOC detected Domain: www.baidu.com

extracted_from_files

Domain
detected Domain: search.yahoo.com

XIOC detected Domain: search.yahoo.com

extracted_from_files

Domain
detected Domain: dst.style

XIOC detected Domain: dst.style

extracted_from_files

Domain
detected Domain: b.r.top

XIOC detected Domain: b.r.top

extracted_from_files

Domain
detected Domain: a.r.top

XIOC detected Domain: a.r.top

extracted_from_files

Domain
detected Domain: container.style.gap

XIOC detected Domain: container.style.gap

extracted_from_files

Domain
detected Domain: data.email

XIOC detected Domain: data.email

extracted_from_files

Domain
detected Domain: proxyinput.style

XIOC detected Domain: proxyinput.style

extracted_from_files

Domain
detected Domain: r.top

XIOC detected Domain: r.top

extracted_from_files

Domain
detected Domain: rn.host

XIOC detected Domain: rn.host

extracted_from_files

Domain
detected Domain: auth.email

XIOC detected Domain: auth.email

extracted_from_files

Domain
detected Domain: row.style

XIOC detected Domain: row.style

extracted_from_files

Domain
detected Domain: inputwrap.style

XIOC detected Domain: inputwrap.style

extracted_from_files

Domain
detected Domain: proxy.style

XIOC detected Domain: proxy.style

extracted_from_files

Domain
detected Domain: proxysend.style

XIOC detected Domain: proxysend.style

extracted_from_files

Domain
detected Domain: setter.call

XIOC detected Domain: setter.call

extracted_from_files

Domain
detected Domain: api.pp.dataelicit.com

XIOC detected Domain: api.pp.dataelicit.com

extracted_from_files

Domain
detected Domain: proxybtn.id

XIOC detected Domain: proxybtn.id

extracted_from_files

Domain
detected Domain: fallbackbtn.click

XIOC detected Domain: fallbackbtn.click

extracted_from_files

Domain
detected Domain: btn.click

XIOC detected Domain: btn.click

extracted_from_files

Domain
detected Domain: t.style

XIOC detected Domain: t.style

extracted_from_files

Domain
detected Domain: style.id

XIOC detected Domain: style.id

extracted_from_files

Domain
detected Domain: chrome.storage

XIOC detected Domain: chrome.storage

extracted_from_files

Domain
detected Domain: browser.storage

XIOC detected Domain: browser.storage

extracted_from_files

Domain
detected Domain: data.credentials.email

XIOC detected Domain: data.credentials.email

extracted_from_files

Domain
detected Domain: e.name

XIOC detected Domain: e.name

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: matchedengine.name

XIOC detected Domain: matchedengine.name

extracted_from_files

Domain
detected Domain: www.bing.com

XIOC detected Domain: www.bing.com

extracted_from_files

Domain
detected Domain: 3.lc

XIOC detected Domain: 3.lc

extracted_from_files

Domain
detected Domain: s.gr

XIOC detected Domain: s.gr

extracted_from_files

Domain
detected Domain: a.as

XIOC detected Domain: a.as

extracted_from_files

Domain
detected Domain: 1.re

XIOC detected Domain: 1.re

extracted_from_files

URL
detected URL: https://yandex.com/search/?text=

XIOC detected URL: https://yandex.com/search/?text=

extracted_from_files

Security Analysis Summary

Security Analysis Overview

PromptProtect is a Chrome Web Store extension published by [email protected]. Version 1.0.1 has been analyzed by the Risky Plugins security platform, receiving a risk score of 84.72/100 (HIGH risk) based on 167 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Medium: 119 finding(s)
  • Low: 48 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

PromptProtect is published by [email protected] on the Chrome Web Store marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions