ICPC Luxor CP-Training-Tracker
dalbkjmnafdmooclemgjckpfhkgibbja
Risk Score
3.27
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Host permissions on 9+ AI platforms (ChatGPT, Claude, Gemini, Copilot, Grok, etc.) not justified by stated study-tracker function.
- Privacy policy is 22-char stub with scope_extension=false and third_party_silence=true; effectively no disclosure.
- Free-webmail developer (gmail.com) with no verified domain or publisher badge; low accountability.
- Wildcard *.herokuapp.com host permission broader than the single pinned backend subdomain needed.
- localhost:8080 host permission exposes local services on user machines.
Evidence
- AI platform host permissions manifest 9 distinct AI chat platforms granted full host access; description only mentions Codeforces study tracking.
- Privacy policy stub api Fetched policy is 22 chars long, scope_extension=false, data_collection=false, third_party_silence=true — inadequate.
- Free-webmail developer email store icpcluxor@gmail.com; no verified publisher badge; domain_age_ct not queried due to free webmail.
- Wildcard Heroku host manifest https://*.herokuapp.com/* grants access to any Heroku app subdomain beyond the named backend.
- No CSP (MV3) manifest csp_present=false; MV3 has strict default so no v2 penalty applied, but noted.
- No bad hosts / CVEs / obfuscation crx threat_intel.bad_host_hits=[], cve_findings_raw=[], obfuscation_score=0.0 — clean scan.
- 27 installs, 0 operator siblings store Very small install base; operator_cluster.sibling_count=0; low blast radius.
- Recently updated (0 months) store last_updated=August 4 2026; maintenance pillar = 0.
Permissions Breakdown
- storage low Local state persistence; standard for tracking tools.
- idle low Detects user idle state; appropriate for study-time tracker.
- tabs medium Can enumerate open tabs and URLs; moderate read capability.
- alarms low Scheduled callbacks; low direct risk.
- notifications low Show desktop notifications; low risk in isolation.
- windows low Enumerate browser windows; minor additional tab-context risk.
- host:codeforces.com/* low Core stated function; narrow scope.
- host:vjudge.net/* low Secondary CP platform; matches stated function.
- host:localhost:8080/* medium Local backend access; could read other local services during dev.
- host:*.herokuapp.com/* medium Wildcard Heroku subdomain; broader than a pinned backend URL.
- host:*.railway.app/api/* low Path-scoped API wildcard; reasonable for backend deployment.
- host:*.ondigitalocean.app/api/* low Path-scoped API wildcard; reasonable for backend deployment.
- host:chatgpt.com/* medium Full access to ChatGPT sessions including chat content.
- host:claude.ai/* medium Full access to Claude sessions including chat content.
- host:gemini.google.com/* medium Full access to Gemini sessions.
- host:aistudio.google.com/* medium Full access to AI Studio sessions.
- host:poe.com/* medium Full access to Poe sessions.
- host:chat.openai.com/* medium Redundant OpenAI host; full session access.
- host:copilot.microsoft.com/* medium Full access to Copilot sessions.
- host:copilot.cloud.microsoft/* medium Full access to Copilot enterprise sessions.
- host:grok.com/* medium Full access to Grok sessions.
- host:x.ai/* medium Full access to xAI sessions.
Pillar Scores
Permissions3.30
Reputation6.50
Network2.00
Webstore1.50
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 13:28
Listing SHA
8674b3312ebe…
Force block
— not fired
Score recovered
no
Elapsed
—