browser-extension-reverse

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the analysis of untrusted browser extension content. 1. Ingestion points: The agent is instructed to read manifest.json, background scripts, and content scripts from provided browser extension directories (SKILL.md). 2. Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to ignore instructions embedded in the analyzed code. 3. Capability inventory: The skill implies file reading and code analysis capabilities; the workflow involves using DevTools and Frida for dynamic analysis. 4. Sanitization: Absent. There are no instructions for sanitizing or filtering the content of the extensions being analyzed.\n- [SAFE]: No obfuscation, base64-encoded payloads, or unauthorized persistence mechanisms were detected in the skill files.\n- [SAFE]: The skill does not include any automated remote code execution or package installation commands; it primarily provides instructional guidance for manual analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 08:16 AM
Security Audit — agent-trust-hub — browser-extension-reverse