chrome-extension
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The analyzed files consist entirely of Markdown documentation, YAML metadata, and static JavaScript/TypeScript code snippets illustrating best practices for Chrome Extensions. There is no evidence of executable malicious code.
- [REMOTE_CODE_EXECUTION]: The skill does not contain any patterns for downloading or executing remote code. The
README.mdincludes standard developer build instructions (e.g.,pnpm install,pnpm build), but these are generic and not linked to malicious scripts. - [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file path access (such as
.sshor.aws) were identified. The code examples use standard Chrome Extension APIs likechrome.storage.localandchrome.runtime.sendMessagefor their intended purposes. - [PROMPT_INJECTION]: The
SKILL.mdandAGENTS.mdfiles contain meta-instructions directing AI agents to prioritize certain performance rules. These are benign educational guidelines and do not attempt to bypass safety filters or override the system prompt for malicious ends. - [OBFUSCATION]: No obfuscated content, Base64-encoded payloads, homoglyphs, or zero-width characters were found. The documentation and code are transparent and readable.
Audit Metadata