chrome-webstore-release-blueprint

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides step-by-step guidance for setting up API credentials manually in the Google Cloud Console and OAuth Playground. It explicitly forbids hardcoding secrets and instructs the user to store them in gitignored local configuration files or via GitHub repository secrets using standard gh CLI security practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data elements such as the manifest.json file paths and version strings. This creates a minor theoretical ingestion surface for untrusted repository assets; however, strict guardrails are specified to only operate on structurally defined values (like standard versions), requiring explicit user verification at every stage of the lifecycle.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:16 AM
Security Audit — agent-trust-hub — chrome-webstore-release-blueprint