clerk-chrome-extension-patterns

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/headless-extension.md

The code implements a plausible headless Clerk-authenticated extension workflow. It contains no clear malware, obfuscation, reverse shell, cryptomining, credential harvesting, or destructive behavior. However, it intentionally transmits every completed tab URL to an external application API together with a bearer session token, which creates a significant browsing-history privacy risk and makes the API a sensitive sink. The code should be reviewed and constrained before deployment.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 04:25 AM
Package URL
pkg:socket/skills-sh/clerk%2Fskills%2Fclerk-chrome-extension-patterns%2F@696942210c0847e107ba01379bcc61da2c400c942d1260ebf1962f975eaffc4e
Security Audit — socket — clerk-chrome-extension-patterns