chrome-extensions

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by googlechrome and provides legitimate, well-documented patterns for Chrome Extension development, including Manifest V3 requirements, side panels, and service worker management.
  • [DYNAMIC_EXECUTION]: Provides detailed instructions and code samples for the secure use of eval() within sandboxed iframes, which is the platform-recommended approach for executing dynamic code while adhering to Content Security Policy (CSP) restrictions.
  • [INDIRECT_PROMPT_INJECTION]: Includes guidance on implementing the chrome.userScripts API, correctly highlighting the requirement for user enablement (Developer Mode or 'Allow User Scripts' toggle) and providing patterns for managing script persistence across extension updates.
  • [EXTERNAL_DOWNLOADS]: Contains example scripts for asset generation that reference standard libraries such as Pillow (for Python) and canvas (for Node.js).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 10:44 AM
Security Audit — agent-trust-hub — chrome-extensions