AgentStack
SKILL verified MIT Self-run

Extension Review

skill-quangpl-browser-extension-skills-extension-review · by quangpl

Scan extension source code for Chrome Web Store rejection risks. Generates report with issues, root causes, and fixes. Use when: review, pre-submit, rejection, CWS compliance, store review.

No reviews yet
0 installs
9 views
0.0% view→install

Install

$ agentstack add skill-quangpl-browser-extension-skills-extension-review

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Extension Review? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Extension Review (Pre-Submission Scanner)

Scan extension source code and predict Chrome Web Store rejection risks. Generate a clear report.

Reference: https://developer.chrome.com/docs/webstore/troubleshooting

Workflow (Execute This)

Step 1: Ask report format

Ask user: Markdown or HTML report? (default: Markdown)

Step 2: Locate and scan extension

# Find extension root
ls manifest.json wxt.config.ts plasmo.config.ts package.json 2>/dev/null

Step 3: Run all checks

Execute these scans in order (see references/scan-checklist.md for grep patterns):

| # | Check | Violation Code | Severity | |---|-------|---------------|----------| | 1 | Remote code execution (eval, external scripts) | Blue Argon | CRITICAL | | 2 | Code obfuscation (base64, char encoding) | Red Titanium | CRITICAL | | 3 | Excessive/unused permissions | Purple Potassium | HIGH | | 4 | Missing privacy policy | Purple Lithium | HIGH | | 5 | Missing metadata (icons, description, screenshots) | Yellow Zinc | HIGH | | 6 | Single purpose violation | Red Magnesium | HIGH | | 7 | Deceptive behavior (description ≠ functionality) | Red Nickel | HIGH | | 8 | Insecure data transmission (HTTP) | Purple Copper | HIGH | | 9 | Keyword stuffing in manifest | Yellow Argon | MEDIUM | | 10 | Minimum functionality check | Yellow Potassium | MEDIUM | | 11 | Undisclosed affiliate links | Grey Titanium | MEDIUM | | 12 | Cryptocurrency mining code | Grey Silicon | CRITICAL | | 13 | Copyright circumvention (download helpers) | Blue Zinc | CRITICAL | | 14 | Notification spam patterns | Yellow Nickel | MEDIUM | | 15 | Data collection without consent | Purple Nickel | HIGH |

Step 4: Generate report

Output report using template in references/report-template.md.

Report structure per issue:

## Issue: [Name]
- **Severity**: CRITICAL / HIGH / MEDIUM
- **Violation Code**: [Chrome code, e.g. Blue Argon]
- **Root Cause**: [What in your code triggers this]
- **File(s)**: [Exact file paths and line numbers]
- **Solution**: [Step-by-step fix]

Report summary:

| Severity | Count |
|----------|-------|
| CRITICAL | X     |
| HIGH     | X     |
| MEDIUM   | X     |
| PASS     | X     |

Verdict: LIKELY APPROVED / NEEDS FIXES / WILL BE REJECTED

Step 5: Save report

  • Markdown: save as extension-review-report.md in project root
  • HTML: save as extension-review-report.html with simple, readable styling

References

  • references/scan-checklist.md — Grep patterns and detection logic for all 15 checks
  • references/violation-codes.md — All Chrome Web Store violation codes with descriptions
  • references/report-template.md — Markdown and HTML report templates

Related Skills

  • extension-analyze — Deeper security audit (code quality, XSS, CSP)
  • extension-publish — Full publishing workflow after review passes
  • extension-manifest — Fix manifest issues found in review

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.