fix(store): listing copy without keyword lists (CWS rejection) - #6
Conversation
Chrome Web Store rejected 1.8.1 for Keyword Spam (Yellow Argon) over the 'WHAT IT DETECTS' lists. Describe the twelve categories in prose instead, and add a test that fails if the listing, short description or manifest description start listing technology names again.
There was a problem hiding this comment.
📋 Review Summary — Not ready to merge
1 medium finding would be worth fixing before merging.
Findings
Keyword-list guard misses differently cased technology names ▶
Fix with agent prompt
These are the findings from a code review of this pull request.
## 1. Keyword-list guard misses differently cased technology names
Path: tests/store-readiness.test.js
Line: 125
Issue: The regex is compiled without case-insensitive matching while the candidate names come from the title-cased signature labels, so a future listing can reintroduce the same rejected pattern as `react, next.js, vue, angular...` and this test still passes. That leaves the regression test unable to enforce the policy rule it was added to protect.
Suggested fix:
- Normalize both the scanned copy and signature names to a common case before matching, or compile the escaped-name regex with the `i` flag.
---
For each finding above, determine whether it is valid and should be fixed. If so, fix it directly. Where a finding offers several remedies, pick one and say why. Leave the pull request's own changed files alone unless a fix requires touching them.Summary
The change rewrites the Chrome Web Store listing for 1.8.1 to avoid keyword-list copy and adds a store-readiness regression test for technology-name lists. The listing copy is aligned with the stated intent, but the new guard is case-sensitive, so it can miss a straightforward reintroduction of the same keyword spam with different casing.
Commands
Re-review the latest changes:
@xhawk-ai review again
Resolve all review threads and post a summary:
@xhawk-ai resolve all
| const short = listing.split('## Short description')[1].split('```')[1]; | ||
| const manifest = readJson('manifest.json').description; | ||
| const names = SIGNATURES.flatMap((r) => [r.name, r.name.split(/[ (/]/)[0]]).filter((n) => n.length > 2); | ||
| const count = (text) => new Set(names.filter((n) => new RegExp(`(?<![\\w.])${n.replace(/[.*+?^${}()|[\]\\]/g, '\\$&')}(?![\\w])`).test(text))).size; |
There was a problem hiding this comment.
Keyword-list guard misses differently cased technology names
The regex is compiled without case-insensitive matching while the candidate names come from the title-cased signature labels, so a future listing can reintroduce the same rejected pattern as react, next.js, vue, angular... and this test still passes. That leaves the regression test unable to enforce the policy rule it was added to protect.
Suggestions
Normalize both the scanned copy and signature names to a common case before matching, or compile the escaped-name regex with the i flag.
Chrome Web Store rejected 1.8.1 for Keyword Spam (violation Yellow Argon) over the lists of technology names in the detailed description. This rewrites the listing to describe the categories in prose, and adds a store-readiness test that fails if the listing, short description or manifest description list technology names again (it fails on the rejected text). No extension code changes; the 1.8.1 zip can be resubmitted as-is.