chrome-extension

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The analyzed files consist entirely of Markdown documentation, YAML metadata, and static JavaScript/TypeScript code snippets illustrating best practices for Chrome Extensions. There is no evidence of executable malicious code.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain any patterns for downloading or executing remote code. The README.md includes standard developer build instructions (e.g., pnpm install, pnpm build), but these are generic and not linked to malicious scripts.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file path access (such as .ssh or .aws) were identified. The code examples use standard Chrome Extension APIs like chrome.storage.local and chrome.runtime.sendMessage for their intended purposes.
  • [PROMPT_INJECTION]: The SKILL.md and AGENTS.md files contain meta-instructions directing AI agents to prioritize certain performance rules. These are benign educational guidelines and do not attempt to bypass safety filters or override the system prompt for malicious ends.
  • [OBFUSCATION]: No obfuscated content, Base64-encoded payloads, homoglyphs, or zero-width characters were found. The documentation and code are transparent and readable.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — chrome-extension