Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - `SKILL.md` is valid and has concrete workflow, rules, and validation guidance.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed review workflow for maintaining Chrome extensions and does not include executable code, hidden persistence, or automatic publishing behavior.
Installers should treat this as a release-review rubric: it may ask the agent to inspect extension code, metadata, privacy claims, analytics exports, and local release artifacts, and to run repo-provided checks. Do not approve actual uploads, store submissions, unpublishing, rollbacks, registry publishing, or broad promotion unless you intentionally want that action.
Referenced artifact was not completely inspected
- `SKILL.md` is valid and has concrete workflow, rules, and validation guidance.
Referenced artifact was not completely inspected
- `SKILL.md` is valid and has concrete workflow, rules, and validation guidance.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
- Narrow one-click workflows over broad dashboards.
- `activeTab` and click-triggered scripting over persistent host permissions.
- Local-first output with optional remote improvement only after explicit user action.
- Clear state labels: ready, reading, improving, copied, exported, failed.
- Small versioned releases with one measurable behavior change.
- Locale expansion based on actual language/region usage and support burden.
L012 states the skill does not bundle an uploader or publisher and should rely on repo-local tools, implying a review-oriented workflow rather than publication mechanics. Later guidance at L081-L096 and L137 includes publication-oriented steps such as registry auth checks and pre-publish validation for skill packages, which softens and partially contradicts the earlier 'does not bundle' framing.
No suspicious patterns detected.