AI: Secure imported contexts and hide page-touching tools

Imported Lighthouse reports and Performance traces are untrusted and
could contain prompt injections designed to exploit the AI assistant.
To prevent cross-origin script execution and data exfiltration, this
change disables page-touching tools when operating on imported
contexts.

For Lighthouse:
- Tag imported reports with `isImported = true` upon loading.
- Restrict the Accessibility Agent to only declare `getLighthouseAudits`
  when the report is imported, disabling all page-touching tools.
- Prepend a security warning to the LLM query for imported reports.

For Traces:
- Dynamically hide the `getFunctionCode` tool in the Performance Agent
  if the trace is not fresh, preventing any execution attempts.
- Prepend a security warning to the LLM query for non-fresh traces.
- Prevent the security warning and the user query from leaking into the
  user-facing "Used Context" UI disclosure.
- Delete the dead `external` flag from `PerformanceTraceContext` and
  associated guards, enabling full linkification for active traces.

Fixed: 513711812
Change-Id: I22d26e6ac1fd26bb0772b3eb4f9165f548532bc1
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/7902589
Auto-Submit: Jack Franklin <jacktfranklin@chromium.org>
Reviewed-by: Paul Irish <paulirish@chromium.org>
Commit-Queue: Jack Franklin <jacktfranklin@chromium.org>
7 files changed
tree: e1c01c6ed4de9e2fe2deea4fbf2e5c1c6086a952
  1. .agents/
  2. .gemini/
  3. .github/
  4. .vscode/
  5. build_overrides/
  6. config/
  7. docs/
  8. extension-api/
  9. extensions/
  10. front_end/
  11. inspector_overlay/
  12. mcp/
  13. node_modules/
  14. scripts/
  15. test/
  16. third_party/
  17. v8/
  18. .clang-format
  19. .clang-format-ignore
  20. .editorconfig
  21. .env.template
  22. .geminiignore
  23. .git-blame-ignore-revs
  24. .gitallowed
  25. .gitattributes
  26. .gitignore
  27. .gitmodules
  28. .gn
  29. .mailmap
  30. .npmignore
  31. .npmrc
  32. .style.yapf
  33. .stylelintignore
  34. .stylelintrc.json
  35. AUTHORS
  36. BUILD.gn
  37. codereview.settings
  38. CONTRIBUTING.md
  39. DEPS
  40. DIR_METADATA
  41. eslint.config.mjs
  42. favicon.ico
  43. LICENSE
  44. OWNERS
  45. package-lock.json
  46. package.json
  47. PRESUBMIT.py
  48. README.md
  49. SECURITY.md
  50. WATCHLISTS
README.md

Chrome DevTools frontend

npm package

The client-side of the Chrome DevTools, including all TypeScript & CSS to run the DevTools webapp.

Source code and documentation

The frontend is available on chromium.googlesource.com. Check out the Chromium DevTools documentation for instructions to set up, use, and maintain a DevTools front-end checkout, as well as design guidelines, and architectural documentation.

Source mirrors

DevTools frontend repository is mirrored on GitHub.

DevTools frontend is also available on NPM as the chrome-devtools-frontend package. It's not currently available via CJS or ES modules, so consuming this package in other tools may require some effort.

The version number of the npm package (e.g. 1.0.373466) refers to the Chromium commit position of latest frontend git commit. It's incremented with every Chromium commit, however the package is updated roughly daily.

Getting in touch

There are a few options to keep an eye on the latest and greatest of DevTools development: