chrome-extension-development
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional markdown intended to guide an AI agent in the role of a Chrome Extension Developer. It does not include any executable scripts, automated tool invocations, or configuration for external access.
- [PROMPT_INJECTION]: The instructions do not contain any bypass markers, role-play jailbreaks, or attempts to override the underlying AI safety guidelines. The content is strictly limited to professional development guidance.
- [DATA_EXFILTRATION]: No sensitive file paths (e.g., .ssh, .aws) or hardcoded credentials were found. The skill does not facilitate network communication as tool invocation is explicitly disabled in the frontmatter.
- [OBFUSCATION]: No Base64-encoded strings, zero-width characters, or homoglyph-based URL spoofing were detected in the text or metadata.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download and execution of remote scripts or the installation of unverified third-party packages.
- [INDIRECT_PROMPT_INJECTION]: Although the skill defines how an agent should process user-provided extension ideas, the threat surface is non-existent because
disable-model-invocationis set totrue, preventing the agent from executing any actions or tools based on potentially malicious user input.
Audit Metadata