Back to skill

Security audit

Chrome Extension Maintainer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed review workflow for maintaining Chrome extensions and does not include executable code, hidden persistence, or automatic publishing behavior.

Installers should treat this as a release-review rubric: it may ask the agent to inspect extension code, metadata, privacy claims, analytics exports, and local release artifacts, and to run repo-provided checks. Do not approve actual uploads, store submissions, unpublishing, rollbacks, registry publishing, or broad promotion unless you intentionally want that action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- `SKILL.md` is valid and has concrete workflow, rules, and validation guidance.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
- `SKILL.md` is valid and has concrete workflow, rules, and validation guidance.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/chrome-extension-maintenance-playbook.md (reported line 131)May include surrounding context.

md
- Narrow one-click workflows over broad dashboards.
- `activeTab` and click-triggered scripting over persistent host permissions.
- Local-first output with optional remote improvement only after explicit user action.
- Clear state labels: ready, reading, improving, copied, exported, failed.
- Small versioned releases with one measurable behavior change.
- Locale expansion based on actual language/region usage and support burden.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

L012 states the skill does not bundle an uploader or publisher and should rely on repo-local tools, implying a review-oriented workflow rather than publication mechanics. Later guidance at L081-L096 and L137 includes publication-oriented steps such as registry auth checks and pre-publish validation for skill packages, which softens and partially contradicts the earlier 'does not bundle' framing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.