OCAI 采集插件
bjocdocblhajndcmcfnckbjbkjnjebio
Risk Score
4.84
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- debugger permission confirmed active: full CDP access to every tab, can intercept/modify any traffic.
- scripting + <all_urls>: arbitrary JS injection on all sites including banking and auth pages.
- Free-webmail gmail dev, no verified publisher, privacy policy on free GitHub Pages with no data scope.
- Privacy policy fetched but scope_extension=false and third_party_silence=true — no meaningful disclosure.
- Small-install high-permission anomaly: only 8 users but critical capability set suggests targeted or test-phase tool.
Evidence
- debugger_attach confirmed crx background.js calls chrome.debugger.attach(target,'1.3') — full DevTools protocol control over all tabs.
- High-impact permissions combo manifest debugger + scripting + <all_urls>: can inject JS and control CDP on every site the user visits.
- Free-webmail developer, no verified publisher store Developer email liut03072@gmail.com; not verified; no business domain; privacy policy on GitHub Pages.
- Privacy policy inadequate api Policy fetched (1803 chars) but scope_extension=false, data_collection=false, third_party_silence=true.
- External JS hosts: JD.com and OCAI domain crx js_external_hosts include item.jd.com (major Chinese e-commerce) and ocai.opendatasightai.com.
- install_perm_anomaly api Only 8 installs with has_high_tier_permission=true; small_install_high_perm=true flagged.
- No CSP present manifest content_security_policy is null; MV3 default applies but csp_present=false increases code-quality risk.
- No operator siblings api operator_cluster.sibling_count=0; no historical ownership change detected.
Permissions Breakdown
- activeTab low Access only to current tab on user action; low on its own.
- tabs medium Can read tab URLs and titles across all open tabs.
- scripting high Inject arbitrary JS into any page; paired with <all_urls> is critical.
- debugger high Full Chrome DevTools protocol access; confirmed attach in code. Extremely powerful.
- sidePanel low UI surface only; low direct risk.
- storage low Local extension data storage; low risk.
- <all_urls> (host) high Broad host access enables scripting + debugger on every site visited.
Pillar Scores
Permissions8.50
Reputation7.00
Network4.00
Webstore5.00
Maintenance0.00
Privacy9.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:36
Listing SHA
6452b1799108…
Force block
— not fired
Score recovered
no
Elapsed
—