chrome-webstore-release-blueprint
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides step-by-step guidance for setting up API credentials manually in the Google Cloud Console and OAuth Playground. It explicitly forbids hardcoding secrets and instructs the user to store them in gitignored local configuration files or via GitHub repository secrets using standard
ghCLI security practices. - [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data elements such as the
manifest.jsonfile paths and version strings. This creates a minor theoretical ingestion surface for untrusted repository assets; however, strict guardrails are specified to only operate on structurally defined values (like standard versions), requiring explicit user verification at every stage of the lifecycle.
Audit Metadata