browser-extension-launch

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches additional development skills and the Playwright MCP tool from external sources.
  • Evidence: references/required-skills.json defines a manifest of external repositories including GoogleChrome/modern-web-guidance, microsoft/playwright-mcp, quangpl/browser-extension-skills, and mattpocock/skills.
  • Safety controls: The skill uses pinned git revisions (hashes) for all external dependencies and strictly requires the agent to obtain explicit user permission before downloading or installing any external content.
  • [COMMAND_EXECUTION]: Executes local Python scripts for project orchestration and build auditing.
  • Evidence: SKILL.md and references/workflow.md instruct the agent to run scripts/project.py, scripts/release_bundle.py, and scripts/acceptance_gate.py.
  • Safety controls: These scripts are provided within the skill package, use only the Python standard library, and perform legitimate auditing tasks such as verifying file integrity and scanning for hardcoded secrets in the extension being built.
  • [DATA_EXFILTRATION]: Implements active countermeasures against the accidental leak of sensitive credentials during the build process.
  • Evidence: scripts/release_bundle.py contains a BLOCKED_NAMES list and a PRIVATE_HEADER regex used to identify and block sensitive files (e.g., SSH keys, .env files, API credentials) from being included in the generated extension bundle.
  • [INDIRECT_PROMPT_INJECTION]: Manages the risk associated with processing untrusted user requirements and local project files.
  • Evidence: The skill ingests user input to generate code and reads local project files for maintenance, which is a known attack surface.
  • Safety controls: references/development.md explicitly instructs the agent to treat web content as untrusted. The system uses SHA-256 fingerprinting to ensure the integrity of the generated artifacts and enforces human-in-the-loop checkpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:46 PM