clerk-chrome-extension-patterns
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: CRITICALCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The documentation provides instructions for managing sensitive authentication credentials, including Clerk Publishable Keys and Secret Keys. It includes shell command examples (
curl) that utilize Bearer tokens for API interaction, utilizingYOUR_SECRET_KEYas a placeholder for the Clerk Secret Key. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and install various Node.js packages using
npm install @clerk/chrome-extension,plasmo,react, andreact-domat theirlatestversions. It also recommends usingnpx create-plasmofor project scaffolding, which executes external setup scripts. - [COMMAND_EXECUTION]: Multiple reference files (
sync-host.md,headless-extension.md) provide shell commands for the user to execute locally to configure the Clerk instance via their API, specifically for setting allowed origins for the extension. - [DATA_EXFILTRATION]: A template example in
references/headless-extension.mddemonstrates an extension pattern where the browser's background script monitors tab updates and transmits the full URL of every visited page to a remote API endpoint (https://api.yourapp.com/page-visit). While presented as telemetry, this pattern tracks user browsing history. - [INDIRECT_PROMPT_INJECTION]: The skill provides templates that ingest untrusted data from the browser environment (e.g.,
tab.url) while requesting broad manifest permissions such ashost_permissions: ["<all_urls>"]andpermissions: ["cookies"]to facilitate authentication syncing. - Ingestion points:
references/headless-extension.md(viachrome.tabs.onUpdatedlistener which captures thetab.url). - Boundary markers: None provided in the code examples to delimit the URL data from other context.
- Capability inventory:
fetch(network access),chrome.storage(data persistence),chrome.cookies(sensitive session data access). - Sanitization: No sanitization or validation of the captured
tab.urldata is demonstrated before it is transmitted to the backend API.
Recommendations
- CRITICAL: 3 file(s) identified as malware by FileRep - DO NOT USE
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata