Intent-Code Divergence
Medium
- Confidence
- 93% confidence
- Finding
- The document presents an example manifest with an extension_pages CSP that appears relaxable while later text correctly states MV3 does not allow relaxing extension page CSP with unsafe-inline/unsafe-eval or remote scripts. In a reference skill, contradictory security guidance is dangerous because users may copy the invalid or insecure example and ship an extension with misunderstood CSP constraints, leading to unsafe workarounds or review failures.
