cross-browser-compatibility

Fail

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing a Node.js package from the @anthropic-ai scope (e.g., @anthropic-ai/anthropic-sdk-types). This scope appears to be an impersonation of the legitimate 'anthropics' organization, which is a common tactic for distributing malicious software via typosquatting.\n- [EXTERNAL_DOWNLOADS]: The documentation references an unofficial GitHub repository at https://github.com/AntSim/anthropic-ai-webextension-polyfill instead of the standard, trusted Mozilla repository for this tool. This repository is hosted by an unverified third party ('AntSim').\n- [REMOTE_CODE_EXECUTION]: By encouraging the installation of untrusted and impersonated packages via npm install, the skill facilitates the potential execution of malicious code on the user's system through installation scripts or compromised library logic.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 22, 2026, 12:56 AM