chrome-extensions

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/extensions/csp-sandbox.md

This is instructional documentation, not apparent malware. It explains legitimate CSP and sandbox techniques for a code playground. However, the examples contain security-sensitive patterns: unrestricted postMessage handling, direct insertion of untrusted HTML, and deliberate eval execution. These are acceptable only when the execution context is strongly isolated and communication is restricted and validated. No evidence of credential theft, exfiltration, persistence, sabotage, or other malicious supply-chain behavior appears in the supplied material.

Confidence: 97%Severity: 53%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:45 AM
Package URL
pkg:socket/skills-sh/googlechrome%2Fmodern-web-guidance%2Fchrome-extensions%2F@37e8b382786bfe1088a247f9a6f6825a62327d468715607e52941a39602375ad
Security Audit — socket — chrome-extensions