chrome-extension-store-kit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill employs secure-by-default packaging logic in
scripts/build_extension_zip.py, specifically excluding.envfiles,.gitdirectories, and other development artifacts from the final extension ZIP. - [SAFE]: Static analysis of user code in
scripts/audit_extension.pyis performed using regular expressions without executing the target code, minimizing the risk of exploitation during the audit phase. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user content from Chrome extension source files to generate reports and store materials.
- Ingestion points: Extension source code is read in
scripts/audit_extension.pyto populate audit signals from file contents. - Boundary markers: The skill uses template files in the
assets/directory with{{PLACEHOLDERS}}to structure the generated output. - Capability inventory: Capabilities are limited to standard file system operations (read, write, directory creation) and ZIP archive creation; no shell execution or dynamic evaluation of user-provided content is present in the scripts.
- Sanitization: Code excerpts included in reports are escaped to maintain Markdown formatting integrity.
Audit Metadata