This project treats the Chrome extension as a browser supply-chain boundary. The extension should not fetch remote code, expose broad browser permissions, or turn YouTube page text into executable content.
- Extension supply-chain compromise through broadened permissions, remote code, or unexpectedly exposed web-accessible resources.
- Dependency confusion, unpinned package drift, missing package integrity, and non-optional lifecycle install scripts.
- DOM/script injection through extension pages or content scripts.
- Prompt-injection-adjacent abuse where page text is treated as data only; chat messages must never become executable HTML, JavaScript, configuration, or model/tool instructions.
Run before packaging:
npm run securityBun path:
bun run security:bunThe gate fails if:
manifest.jsonleaves Manifest V3.- permissions expand beyond
storage. host_permissionsis added; content-scriptmatchesscopes YouTube injection without granting extension-wide host access.- extension CSP allows inline/eval/remote/blob/data script sources.
- any web-accessible resource other than
stage.html(the danmaku stage frame, embeddable onhttps://www.youtube.com/*only, through its dynamic URL) is exposed. - extension source uses dangerous injection sinks such as
innerHTML,insertAdjacentHTML,document.write,eval, ornew Function. - extension source adds network fetches or remote script/style URLs.
- npm package specs are not pinned exactly.
- lockfile entries lack integrity metadata or use non-registry tarballs.
- non-optional npm packages use lifecycle install scripts, unless the package is dev-only and its package identity is explicitly allowlisted. The identity check is independent of npm's direct or nested lockfile layout.
- Keep executable JS and CSS inside
extension/. - Do not add CDN scripts, remote stylesheets, or runtime-downloaded logic.
- Prefer
textContent,createElement,createElementNS, and fixed CSS text over HTML string insertion. - Treat YouTube chat text, author names, video metadata, and page text as untrusted display data only.
- Keep standalone web relays allowlisted: built-in default relay, same-origin
relays, or explicitly trusted HTTPS origins only. If a deployment adds a
trusted relay origin, update both
SYC_TRUSTED_RELAY_ORIGINSand the web CSPconnect-src. - Never use relay-provided
parts[].udirectly as an image URL. Pass custom emoji URLs through the web sanitizer and keep the allowed image hosts limited to YouTube emoji assets plus rasterdata:image/...mock assets. - Keep
chrome.runtime.onMessagehandlers narrow and validate messagetypeand sender assumptions before acting. - Keep dependency additions rare. If a package is necessary, pin it exactly,
inspect its lockfile entry, and rerun
npm run security.
There is no LLM feature in the extension. If one is added later, YouTube chat and metadata must be passed as quoted untrusted data, never as instructions, and any tool use or external transmission must be explicit and allowlisted.