Influencer Butler
cnkfballfjhdijogkjjhdfmnkijcjgbc
Risk Score
2.74
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- brand_mention.is_impersonation=true for Amazon brand without verified ownership; could mislead enterprise reviewers.
- scripting + multi-locale Amazon host permissions enables JS injection into Amazon affiliate pages including order history.
- External JS hosts include api.openai.com, affiliate link networks (geni.us, linktw.in, levanta.io) — broad network reach.
- Privacy policy discloses third_party_sharing=true; no data-collection fields confirmed but sharing with partners acknowledged.
- No CSP defined (csp_present=false); MV3 mitigates remote-eval risk but no explicit script-src restriction.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'amazon'; developer domain influencerbutler.com is not confirmed Amazon owner.
- external_hosts_diversity crx 12 distinct external JS hosts including api.openai.com, affiliate networks linktw.in, my.geni.us, urlgeni.us, app.levanta.io.
- scripting_on_amazon_affiliate manifest scripting permission + host_permissions covering Amazon affiliate-program and order-history URLs across 12 locales.
- privacy_third_party_sharing api Privacy policy fetched, extension-scoped, but third_party_sharing=true; retention disclosed.
- no_csp manifest content_security_policy is null; MV3 provides baseline but no explicit CSP declared.
- very_low_installs store Only 90 installs; no ratings. New/unproven extension with broad Amazon/Walmart scripting access.
- openai_api_contact crx api.openai.com listed in js_external_hosts; AI feature present despite not flagged is_ai_extension by scan.
- no_bad_hosts_no_cves api threat_intel bad_host_hits empty, cve_findings_raw empty, obfuscation_score=0.0; code quality clean.
Permissions Breakdown
- storage low Stores local extension state; standard low-risk permission.
- alarms low Schedules background tasks; no data access.
- notifications low Displays browser notifications; low capability on its own.
- tabs medium Can read tab URLs and titles across sessions.
- scripting medium Injects JS into host_permissions domains (Amazon, Walmart); scoped but powerful.
- host_permissions: amazon.* medium Broad access to Amazon shopping/affiliate pages across 12 locales; fits stated function.
- host_permissions: walmart.com medium Read/script access to Walmart pages; matches stated influencer tool purpose.
- host_permissions: influencerbutler.com / links.influencerbutler.com low Dev-controlled domain for API calls; expected for SaaS extension.
Pillar Scores
Permissions3.50
Reputation6.00
Network2.00
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:55
Listing SHA
5da178ef2b86…
Force block
— not fired
Score recovered
no
Elapsed
—