AI: Secure imported contexts and hide page-touching tools Imported Lighthouse reports and Performance traces are untrusted and could contain prompt injections designed to exploit the AI assistant. To prevent cross-origin script execution and data exfiltration, this change disables page-touching tools when operating on imported contexts. For Lighthouse: - Tag imported reports with `isImported = true` upon loading. - Restrict the Accessibility Agent to only declare `getLighthouseAudits` when the report is imported, disabling all page-touching tools. - Prepend a security warning to the LLM query for imported reports. For Traces: - Dynamically hide the `getFunctionCode` tool in the Performance Agent if the trace is not fresh, preventing any execution attempts. - Prepend a security warning to the LLM query for non-fresh traces. - Prevent the security warning and the user query from leaking into the user-facing "Used Context" UI disclosure. - Delete the dead `external` flag from `PerformanceTraceContext` and associated guards, enabling full linkification for active traces. Fixed: 513711812 Change-Id: I22d26e6ac1fd26bb0772b3eb4f9165f548532bc1 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/7902589 Auto-Submit: Jack Franklin <jacktfranklin@chromium.org> Reviewed-by: Paul Irish <paulirish@chromium.org> Commit-Queue: Jack Franklin <jacktfranklin@chromium.org>
The client-side of the Chrome DevTools, including all TypeScript & CSS to run the DevTools webapp.
The frontend is available on chromium.googlesource.com. Check out the Chromium DevTools documentation for instructions to set up, use, and maintain a DevTools front-end checkout, as well as design guidelines, and architectural documentation.
DevTools frontend repository is mirrored on GitHub.
DevTools frontend is also available on NPM as the chrome-devtools-frontend package. It's not currently available via CJS or ES modules, so consuming this package in other tools may require some effort.
The version number of the npm package (e.g. 1.0.373466) refers to the Chromium commit position of latest frontend git commit. It's incremented with every Chromium commit, however the package is updated roughly daily.
There are a few options to keep an eye on the latest and greatest of DevTools development:
Follow What's new in DevTools.
Follow Umar's Dev Tips.
Follow these individual Twitter accounts: @umaar, @malyw, @kdzwinel, @addyosmani, @paul_irish, @samccone, @mathias, @mattzeunert, @PrashantPalikhe, @ziyunfei, and @bmeurer.
Follow to g/devtools-reviews@chromium.org mailing list for all reviews of pending code, and view the log, or follow @DevToolsCommits on Twitter.
Checkout all open DevTools tickets on crbug.com
Use Chrome Canary and poke around the experiments.