Octopus - All-in-One LinkedIn Automation
afahlliooeebnifondmbhcaghcapepbm
Risk Score
4.75
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false + data_collection=true + third_party_sharing=true → D-clause triggers +10.0 privacy pillar.
- install_url_hijack and uninstall_url_hijack both true; onInstalled/onUninstalled redirect to unspecified 3rd-party URLs.
- LinkedIn automation scrapes and transmits professional data to octopuscrm.io, zapier.com, make.com, and Firebase — broad external data flow.
- Brand mention of 'linkedin' flagged as impersonation (confirmed_owner=false); may violate LinkedIn ToS and mislead users.
- No developer name listed; privacy policy does not scope disclosures to this specific extension's data practices.
Evidence
- privacy_policy_generic_broad api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D: +10.0 privacy.
- install_and_uninstall_url_hijack store install_url_hijack=true, uninstall_url_hijack=true; targets null but flags are set — +2.0+3.0 webstore.
- brand_impersonation_linkedin store brand_mention.is_impersonation=true, confirmed_owner=false, not verified_publisher per rubric gate → +2.0 reputation.
- verified_publisher store verified_publisher=true → -3.0 reputation; no 0c cap triggers (no stale/CVE/monetization hits).
- multiple_external_data_endpoints manifest Host perms include zapier.com, make.com, firebaseio.com, googleapis.com, cloudfunctions.net — 5+ distinct registrable domains.
- test_project_cloud_function manifest host_permission includes us-central1-test-proj-7d39d.cloudfunctions.net; 'test-proj' suggests unpolished infra.
- no_developer_name store developer_name is empty string; reduces accountability signal (+1.0 reputation).
- cve_findings_clean crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0; no malicious code signals detected.
Permissions Breakdown
- tabs medium Access to tab URLs and metadata; medium risk for automation tool.
- notifications low Show desktop notifications; low direct data risk.
- history medium Read browsing history; sensitive personal data exposure.
- scripting medium Inject scripts into pages; scoped to linkedin.com via content_scripts.
- offscreen low Offscreen document support; low standalone risk.
- host:linkedin.com/* medium Scoped to LinkedIn; expected for stated automation function.
- host:api.octopuscrm.io/* medium Sends data to developer's own backend; LinkedIn data exfiltration surface.
- host:hooks.zapier.com/* medium Third-party automation webhook; user data may flow to Zapier.
- host:*.make.com/* medium Third-party automation platform; another external data path.
- host:*.firebaseio.com/* medium Firebase real-time DB; potential data storage for scraped LinkedIn data.
- host:www.googleapis.com/* low Google APIs; broad but commonly used for auth/storage.
- host:cdnjs.cloudflare.com/ajax/libs/raphael/* low CDN for Raphael.js library; scoped path reduces risk.
- host:us-central1-test-proj-7d39d.cloudfunctions.net/* medium Cloud function endpoint with 'test-proj' name; unclear production status.
Pillar Scores
Permissions4.50
Reputation5.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA
10f9a1f4d335…
Force block
— not fired
Score recovered
no
Elapsed
28.4s