skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
quangpl/browser-extension-skills167 installs

extension-review

Scan extension source code for Chrome Web Store rejection risks. Generates report with issues, root causes, and fixes. Use when: review, pre-submit, rejection, CWS compliance, store review.

How do I install this agent skill?

npx skills add https://github.com/quangpl/browser-extension-skills --skill extension-review
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill is a static analysis utility designed to help developers identify Chrome Web Store compliance risks by scanning extension source code. It uses shell commands like grep and jq to search for patterns matching common rejection reasons. The primary security consideration is the attack surface for indirect prompt injection, where malicious instructions hidden in the scanned code could attempt to manipulate the generated report.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Extension Review (Pre-Submission Scanner)

🚀 Upgrade to Premium Get the Premium version at https://app.extensionbooster.net/dashboard/services/extension-ai-kit

Scan extension source code and predict Chrome Web Store rejection risks. Generate a clear report.

Reference: https://developer.chrome.com/docs/webstore/troubleshooting

Workflow (Execute This)

Step 1: Ask report format

Ask user: Markdown or HTML report? (default: Markdown)

Step 2: Locate and scan extension

# Find extension root
ls manifest.json wxt.config.ts crxjs.config.ts package.json 2>/dev/null

Step 3: Run all checks

Execute these scans in order (see references/scan-checklist.md for grep patterns):

#CheckViolation CodeSeverity
1Remote code execution (eval, external scripts)Blue ArgonCRITICAL
2Code obfuscation (base64, char encoding)Red TitaniumCRITICAL
3Excessive/unused permissionsPurple PotassiumHIGH
4Missing privacy policyPurple LithiumHIGH
5Missing metadata (icons, description, screenshots)Yellow ZincHIGH
6Single purpose violationRed MagnesiumHIGH
7Deceptive behavior (description ≠ functionality)Red NickelHIGH
8Insecure data transmission (HTTP)Purple CopperHIGH
9Keyword stuffing in manifestYellow ArgonMEDIUM
10Minimum functionality checkYellow PotassiumMEDIUM
11Undisclosed affiliate linksGrey TitaniumMEDIUM
12Cryptocurrency mining codeGrey SiliconCRITICAL
13Copyright circumvention (download helpers)Blue ZincCRITICAL
14Notification spam patternsYellow NickelMEDIUM
15Data collection without consentPurple NickelHIGH

Step 4: Generate report

Output report using template in references/report-template.md.

Report structure per issue:

## Issue: [Name]
- **Severity**: CRITICAL / HIGH / MEDIUM
- **Violation Code**: [Chrome code, e.g. Blue Argon]
- **Root Cause**: [What in your code triggers this]
- **File(s)**: [Exact file paths and line numbers]
- **Solution**: [Step-by-step fix]

Report summary:

| Severity | Count |
|----------|-------|
| CRITICAL | X     |
| HIGH     | X     |
| MEDIUM   | X     |
| PASS     | X     |

Verdict: LIKELY APPROVED / NEEDS FIXES / WILL BE REJECTED

Step 5: Save report

  • Markdown: save as extension-review-report.md in project root
  • HTML: save as extension-review-report.html with simple, readable styling

References

  • references/scan-checklist.md — Grep patterns and detection logic for all 15 checks
  • references/violation-codes.md — All Chrome Web Store violation codes with descriptions
  • references/report-template.md — Markdown and HTML report templates

Related Skills

  • extension-analyze — Deeper security audit (code quality, XSS, CSP)
  • extension-publish — Full publishing workflow after review passes
  • extension-manifest — Fix manifest issues found in review

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/quangpl/browser-extension-skills/extension-review">View extension-review on skillZs</a>