chrome-extension
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/verify.shfile executes a local Node.js script to validatemanifest.jsonfiles against Manifest V3 standards. This is a read-only linting operation designed for local development use. - [SAFE]: The skill explicitly instructs developers to avoid security risks by banning remotely hosted code and recommending the 'least privilege' model for browser permissions (e.g., using
activeTabinstead of<all_urls>). - [SAFE]: The documentation references official developer documentation (
developer.chrome.com) and recommends well-known, trusted build tools like Vite and CRXJS. - [SAFE]: No obfuscation, data exfiltration, or persistence mechanisms were detected. The skill focuses on legitimate browser extension development workflows.
Audit Metadata