browser-extension-builder
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides code templates for extension content scripts that are designed to read and interact with external web page content (DOM), creating a surface for indirect prompt injection.\n
- Ingestion points: content.js (DOM access using querySelector and textContent).\n
- Boundary markers: Absent from the provided code templates.\n
- Capability inventory: chrome.storage API, DOM manipulation, and cross-component messaging.\n
- Sanitization: Basic templates do not include explicit input sanitization or validation.\n- [PROMPT_INJECTION]: No direct prompt injection or safety bypass attempts were found in the skill instructions.\n- [DATA_EXFILTRATION]: No hardcoded credentials or unauthorized data exfiltration patterns were identified.
Audit Metadata