browser-extension-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a pattern for browser extensions where content scripts ingest data from external web pages and communicate with a background service worker.\n
  • Ingestion points: Data is read from the DOM in content/content-script.js using document.querySelectorAll.\n
  • Boundary markers: The provided examples do not include delimiters or instructions to ignore embedded commands within the ingested page content.\n
  • Capability inventory: The skill utilizes chrome.storage.sync for persistent storage, chrome.runtime.sendMessage for cross-context messaging, and fetch in the background worker for network operations.\n
  • Sanitization: No sanitization or validation logic is present for the URLs or data being passed from the untrusted content script context to the privileged background context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — browser-extension-patterns