chrome-extension

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/messaging-rpc.md

The fragment appears to be legitimate educational Chrome extension messaging documentation, not malware. It contains meaningful security risks in its example implementations: missing authorization and origin validation across the page bridge, weak fetch URL allowlist validation, unvalidated RPC inputs, broad tab/storage access, and incomplete external-sender verification. These issues are potentially exploitable when the examples are used directly, but no overt supply-chain attack behavior or malicious payload is present.

Confidence: 97%Severity: 67%
AnomalyLOW
references/network-csp.md

The material is legitimate Chrome extension networking guidance, not evident malware. It contains important security weaknesses in the sample relay, especially prefix-based URL allowlisting, insufficient request validation, broad permission examples, and potentially dangerous CSP/security-header removal rules. These issues should be corrected before production use; exact origin comparison and strict schema, size, method, and permission validation are recommended.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:01 PM
Package URL
pkg:socket/skills-sh/samber%2Fcc-skills%2Fchrome-extension%2F@77a2f7c880f9dc1977ae4a4e2ca122be9a9179ed3a10738b59fabae701c23e6a
Security Audit — socket — chrome-extension