chrome-extension

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/verify.sh file executes a local Node.js script to validate manifest.json files against Manifest V3 standards. This is a read-only linting operation designed for local development use.
  • [SAFE]: The skill explicitly instructs developers to avoid security risks by banning remotely hosted code and recommending the 'least privilege' model for browser permissions (e.g., using activeTab instead of <all_urls>).
  • [SAFE]: The documentation references official developer documentation (developer.chrome.com) and recommends well-known, trusted build tools like Vite and CRXJS.
  • [SAFE]: No obfuscation, data exfiltration, or persistence mechanisms were detected. The skill focuses on legitimate browser extension development workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — chrome-extension