Handy Screenshot - Full Page Screen Capture
dajlhodahakobmgdiglkajjgbchiiccf
Risk Score
4.03
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing.
- Content scripts injected on <all_urls> including AI platforms (ChatGPT, Claude, Gemini) capturing potentially sensitive sessions.
- Multiple new Function() constructor uses in content_script.js and core JS files; DOM innerHTML sink present.
- Description promises recording but lacks tabCapture/desktopCapture — permission/promise mismatch.
- No developer name listed; ohhandy.com domain resolves but CT log check failed — identity partially unverifiable.
Evidence
- privacy_policy_generic store Privacy URL points to Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- host_permissions_all_urls manifest host_permissions includes <all_urls>; content_scripts also match AI platforms ChatGPT, Claude, Gemini.
- code_function_constructor crx new Function() found in capture.js, settings.js, content_script.js, 295.js — dynamic code execution risk.
- dom_innerhtml_sink crx innerHTML assignment from variable in 223.js; CSP sandbox present but limited to sandbox iframe.
- description_promise_mismatch store Extension promises recording capability but lacks tabCapture/desktopCapture permissions.
- verified_publisher_featured store Extension is verified publisher and featured by Google; ohhandy.com resolves, no throwaway signals.
- js_external_hosts crx 12 external hosts including us-central1-ohhandytools.cloudfunctions.net; all appear dev-owned or known platforms.
- no_developer_name store developer_name is empty string; only email taining@ohhandy.com provided.
Permissions Breakdown
- activeTab low Scoped to user-initiated tab interaction; appropriate for screenshot tool.
- tabs medium Exposes tab URLs and metadata across all tabs.
- storage low Local settings persistence; low standalone risk.
- scripting medium Can inject scripts into pages; paired with <all_urls> raises capability.
- notifications low UI notifications only; minimal abuse surface.
- contextMenus low Adds right-click menu items; low risk.
- identity low OAuth token access; no scopes declared, moderate concern.
- <all_urls> (host_permission) high Content scripts on all URLs including ChatGPT, Claude, Gemini — broad reach.
Pillar Scores
Permissions4.50
Reputation2.00
Network3.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA
27818557157f…
Force block
— not fired
Score recovered
no
Elapsed
29.6s