clerk-chrome-extension-patterns
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/headless-extension.md
LOWAnomalyLOW
references/headless-extension.md
The code implements a plausible headless Clerk-authenticated extension workflow. It contains no clear malware, obfuscation, reverse shell, cryptomining, credential harvesting, or destructive behavior. However, it intentionally transmits every completed tab URL to an external application API together with a bearer session token, which creates a significant browsing-history privacy risk and makes the API a sensitive sink. The code should be reviewed and constrained before deployment.
Confidence: 97%Severity: 62%
Audit Metadata