chrome-health-check
Fail
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill executes a Python script designed to scrape the Claude Desktop Application's local storage directory (
~/Library/Application Support/Claude/Local Storage/leveldb/). It uses regular expressions to extract sensitive user data, specifically email addresses and UUIDs, and brings this information into the agent's context. - [COMMAND_EXECUTION]: The skill utilizes shell commands and AppleScript (
osascript) to control local software behavior, including forcefully quitting and restarting the 'Claude' and 'Google Chrome' applications. It also reads local system logs (~/Library/Logs/Claude/main.log) to extract connection metadata. - [CREDENTIALS_UNSAFE]: The skill includes hardcoded user identifiers and email addresses (e.g.,
ms.apps@msapps.mobi,da5d00b9-5ca9-40ea-a8b5-5052603ff35b). It also provides specific instructions for accessing a private Zoho Workplace email inbox, which is outside the scope of a standard health-check utility.
Recommendations
- AI detected serious security threats
Audit Metadata