chrome-extensions
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalyreferences/extensions/csp-sandbox.md
LOWAnomalyLOW
references/extensions/csp-sandbox.md
This is instructional documentation, not apparent malware. It explains legitimate CSP and sandbox techniques for a code playground. However, the examples contain security-sensitive patterns: unrestricted postMessage handling, direct insertion of untrusted HTML, and deliberate eval execution. These are acceptable only when the execution context is strongly isolated and communication is restricted and validated. No evidence of credential theft, exfiltration, persistence, sabotage, or other malicious supply-chain behavior appears in the supplied material.
Confidence: 97%Severity: 53%
Audit Metadata