chrome-health-check

Fail

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill executes a Python script designed to scrape the Claude Desktop Application's local storage directory (~/Library/Application Support/Claude/Local Storage/leveldb/). It uses regular expressions to extract sensitive user data, specifically email addresses and UUIDs, and brings this information into the agent's context.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands and AppleScript (osascript) to control local software behavior, including forcefully quitting and restarting the 'Claude' and 'Google Chrome' applications. It also reads local system logs (~/Library/Logs/Claude/main.log) to extract connection metadata.
  • [CREDENTIALS_UNSAFE]: The skill includes hardcoded user identifiers and email addresses (e.g., ms.apps@msapps.mobi, da5d00b9-5ca9-40ea-a8b5-5052603ff35b). It also provides specific instructions for accessing a private Zoho Workplace email inbox, which is outside the scope of a standard health-check utility.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 28, 2026, 01:39 PM
Security Audit — agent-trust-hub — chrome-health-check