chrome-extension-development

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional markdown intended to guide an AI agent in the role of a Chrome Extension Developer. It does not include any executable scripts, automated tool invocations, or configuration for external access.
  • [PROMPT_INJECTION]: The instructions do not contain any bypass markers, role-play jailbreaks, or attempts to override the underlying AI safety guidelines. The content is strictly limited to professional development guidance.
  • [DATA_EXFILTRATION]: No sensitive file paths (e.g., .ssh, .aws) or hardcoded credentials were found. The skill does not facilitate network communication as tool invocation is explicitly disabled in the frontmatter.
  • [OBFUSCATION]: No Base64-encoded strings, zero-width characters, or homoglyph-based URL spoofing were detected in the text or metadata.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download and execution of remote scripts or the installation of unverified third-party packages.
  • [INDIRECT_PROMPT_INJECTION]: Although the skill defines how an agent should process user-provided extension ideas, the threat surface is non-existent because disable-model-invocation is set to true, preventing the agent from executing any actions or tools based on potentially malicious user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — chrome-extension-development