browser-extension-launch
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches additional development skills and the Playwright MCP tool from external sources.
- Evidence:
references/required-skills.jsondefines a manifest of external repositories includingGoogleChrome/modern-web-guidance,microsoft/playwright-mcp,quangpl/browser-extension-skills, andmattpocock/skills. - Safety controls: The skill uses pinned git revisions (hashes) for all external dependencies and strictly requires the agent to obtain explicit user permission before downloading or installing any external content.
- [COMMAND_EXECUTION]: Executes local Python scripts for project orchestration and build auditing.
- Evidence:
SKILL.mdandreferences/workflow.mdinstruct the agent to runscripts/project.py,scripts/release_bundle.py, andscripts/acceptance_gate.py. - Safety controls: These scripts are provided within the skill package, use only the Python standard library, and perform legitimate auditing tasks such as verifying file integrity and scanning for hardcoded secrets in the extension being built.
- [DATA_EXFILTRATION]: Implements active countermeasures against the accidental leak of sensitive credentials during the build process.
- Evidence:
scripts/release_bundle.pycontains aBLOCKED_NAMESlist and aPRIVATE_HEADERregex used to identify and block sensitive files (e.g., SSH keys,.envfiles, API credentials) from being included in the generated extension bundle. - [INDIRECT_PROMPT_INJECTION]: Manages the risk associated with processing untrusted user requirements and local project files.
- Evidence: The skill ingests user input to generate code and reads local project files for maintenance, which is a known attack surface.
- Safety controls:
references/development.mdexplicitly instructs the agent to treat web content as untrusted. The system uses SHA-256 fingerprinting to ensure the integrity of the generated artifacts and enforces human-in-the-loop checkpoints.
Audit Metadata