Security audit
Prompt Switchboard Compare Workflows
Security checks for vulnerabilities and agentic risk
Overview
This is a clear setup guide for a local browser comparison tool, with the main cautions being its external GitHub/npm install and use of already signed-in AI chat tabs.
Before installing, review the referenced GitHub repository and npm dependencies, use only AI chat accounts and browser tabs you intend the tool to operate, and avoid sensitive prompts unless you are comfortable with those providers and any local compare history the sidecar may keep.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
