Dora
dlbpmpcmedbgknmhanknkankmdnlokdp
Risk Score
4.88
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- webRequest + scripting access to Epic EHR and OSUMC health portals exposes sensitive PHI to interception.
- Privacy policy not scoped to this extension and does not disclose data collection — high privacy gap for a healthcare AI agent.
- DOM-XSS sink (innerHTML with user-controlled variable) with no CSP present elevates XSS risk.
- No developer name listed; very low install count (86) with high-impact healthcare permissions — tail attack surface.
- No CSP on MV3 extension accessing healthcare portals; v2 network penalty applies.
Evidence
- healthcare_host_access manifest Host permissions cover *.epic.com, *.epichosted.com, carelink.osumc.edu — major EHR/PHI environments.
- webRequest_on_phi_hosts manifest webRequest declared alongside healthcare host permissions; can observe patient-lookup traffic.
- no_csp manifest content_security_policy is null; no CSP defined for MV3 extension touching healthcare portals.
- privacy_policy_not_scoped api privacy.trycoral.ai fetched; scope_extension=false, data_collection=false — generic, not extension-specific.
- dom_xss_sink crx core/widget.js: body.innerHTML assigned from variable without sanitization; no CSP to mitigate.
- no_developer_name store developer_name is empty string; reduces accountability for a healthcare-facing AI agent.
- small_install_high_perm api 86 installs with HIGH-tier permissions (webRequest + healthcare host access) — install_perm_anomaly flagged.
- domain_age_established api trycoral.ai first cert 2024-05-31, 431 certs, age 824 days — not a throwaway domain.
Permissions Breakdown
- activeTab low Scoped to user-initiated tab interaction only.
- scripting medium Allows programmatic script injection into pages; moderate risk.
- tabs medium Can read tab URLs and metadata across browser.
- storage low Local extension storage, low direct risk.
- webRequest high Can observe all network requests to permitted hosts including sensitive EHR portals.
- host:https://app.trycoral.ai/* low Developer-controlled backend; expected for AI agent comms.
- host:*://*.epic.com/* high Broad access to Epic EHR portal — sensitive patient data environment.
- host:*://*.epichosted.com/* high Broad access to Epic-hosted EHR instances — sensitive patient data.
- host:https://carelink.osumc.edu/* high Access to OSUMC patient portal — PHI exposure risk.
- host:https://ihishswlnk.osumc.edu/* high Access to OSUMC health system link — PHI exposure risk.
Pillar Scores
Permissions6.50
Reputation6.00
Network4.00
Webstore3.00
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:17
Listing SHA
18afd3c8daba…
Force block
— not fired
Score recovered
no
Elapsed
—