TabLoom: Visual Tab Group Mindmap
bahegaolgkmgnjnppnlgkfedbfnnfila
Risk Score
5.27
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- declarativeNetRequestWithHostAccess + <all_urls> enables network interception on every site the user visits.
- Privacy policy is Google's generic account policy — admits data collection and 3rd-party sharing, not scoped to this extension.
- Free-webmail developer, no verified publisher, identity unverifiable; floor reputation risk.
- Only 3 installs with HIGH-tier permissions — tail-attack-surface anomaly.
- External hosts include example.com and foo.bar — anomalous placeholder domains in a production CRX.
Evidence
- declarativeNetRequestWithHostAccess + <all_urls> manifest Extension can intercept and modify all HTTP(S) requests on every site; HIGH capability mismatch for a tab visualizer.
- Privacy policy is Google account policy store URL myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10 privacy pillar.
- Free-webmail developer, no verified publisher store hunkiepeanut.dev@gmail.com; no business domain, no featured badge, no verified publisher status.
- install_perm_anomaly: small_install_high_perm api Only 3 installs with HIGH-tier permissions (declarativeNetRequestWithHostAccess, <all_urls>).
- Anomalous external JS hosts crx js_external_hosts includes example.com and foo.bar — placeholder/test domains unexpected in a production extension.
- No CSP defined manifest csp_present=false on MV3; no additional script-src hardening beyond MV3 defaults.
- Content scripts on <all_urls> manifest Scripts injected into every page visited; broad reach for a tab-management tool.
- No code findings, obfuscation_score=0 crx 6 JS files scanned; no malicious signals detected in code scan.
Permissions Breakdown
- storage low Standard local data persistence; low risk in isolation.
- tabs medium Reads tab URLs and titles across all open tabs; broad metadata access.
- tabGroups low Manages tab grouping; fits stated mindmap function.
- declarativeNetRequestWithHostAccess high Can intercept/modify network requests on all URLs; high capability even if unused offensively.
- <all_urls> (host_permissions) high Content scripts injected into every site; combined with declarativeNetRequestWithHostAccess is high risk.
Pillar Scores
Permissions6.50
Reputation8.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:22
Listing SHA
6452d474d249…
Force block
— not fired
Score recovered
no
Elapsed
—