Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePrompt Optimizer - SecondBrain
Findings · 3
+3 more findings locked
CRITICAL FINDINGS · 3
  1. 01Eight executor scripts injected into AI chatbot pages monkeypatch fetch/XHR to intercept user prompts and AI responses, encrypt them with a server-held key, and upload encrypted captures to secondbrain.is/context. Consent is bypassed by hardcoding CONSENT_STATE=agreed in ldp-defaults.js.
  2. 02The service worker registers chrome.webRequest.onBeforeRequest with the requestBody extra info spec on chatgpt.com URLs, giving the extension direct access to ChatGPT API POST request bodies containing user messages before they reach ChatGPT servers.
  3. 03The extension fetches collector configuration from https://secondbrain.is/collector-config.json on startup, which controls which AI platforms are intercepted, what URL patterns trigger capture, and how prompt/response data is extracted from request payloads.
+3 more findings locked
OTHER EXTENSIONS

Is Prompt Optimizer - SecondBrain safe?

Critical risk

No summary available.

EVOLVv1.0.6Chrome Web Store
100Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026aajjgdpofhhcjmjoombjdfepplndhgcp

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact