clerk-chrome-extension-patterns

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: CRITICALCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The documentation provides instructions for managing sensitive authentication credentials, including Clerk Publishable Keys and Secret Keys. It includes shell command examples (curl) that utilize Bearer tokens for API interaction, utilizing YOUR_SECRET_KEY as a placeholder for the Clerk Secret Key.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and install various Node.js packages using npm install @clerk/chrome-extension, plasmo, react, and react-dom at their latest versions. It also recommends using npx create-plasmo for project scaffolding, which executes external setup scripts.
  • [COMMAND_EXECUTION]: Multiple reference files (sync-host.md, headless-extension.md) provide shell commands for the user to execute locally to configure the Clerk instance via their API, specifically for setting allowed origins for the extension.
  • [DATA_EXFILTRATION]: A template example in references/headless-extension.md demonstrates an extension pattern where the browser's background script monitors tab updates and transmits the full URL of every visited page to a remote API endpoint (https://api.yourapp.com/page-visit). While presented as telemetry, this pattern tracks user browsing history.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates that ingest untrusted data from the browser environment (e.g., tab.url) while requesting broad manifest permissions such as host_permissions: ["<all_urls>"] and permissions: ["cookies"] to facilitate authentication syncing.
  • Ingestion points: references/headless-extension.md (via chrome.tabs.onUpdated listener which captures the tab.url).
  • Boundary markers: None provided in the code examples to delimit the URL data from other context.
  • Capability inventory: fetch (network access), chrome.storage (data persistence), chrome.cookies (sensitive session data access).
  • Sanitization: No sanitization or validation of the captured tab.url data is demonstrated before it is transmitted to the backend API.
Recommendations
  • CRITICAL: 3 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — clerk-chrome-extension-patterns