Auditing Browser Extension Trust

Audit a browser extension (Manifest V3) for a trust boundary another web page or extension can cross to reach a privileged capability, after the permission scope and the message-sender checks are resolved. Covers an externally_connectable or onMessageExternal handler that verifies an origin but not the calling script, a content-script-to-background message handler with no sender validation, host permissions broader than the extension needs, a web_accessible_resources page that acts on URL parameters, an injected content script writing page-controlled data to a DOM sink, and a weak or eval-permitting content-security policy. Use when reviewing the manifest, background and content scripts, and cross-context message passing, not the web-page DOM sink taxonomy the client-side DOM skill owns. An untrusted web origin or another extension is the source, a privileged extension API or DOM sink is the sink, and a message reaching it without a sender-and-origin check is the bug.

UnboundCompute 12af487 9.7 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-browser-extension-trust commit 12af4875ca

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-browser-extension-trust