Woobie
eicibdbdaedbgaoikodgpoikeegncpag
Risk Score
3.57
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy URL is unreachable (fetch error); no policy classification possible — scored as no policy (+10.0).
- Content script runs on all va.gov pages, accessing potentially sensitive veteran health/claims data.
- No developer name listed; small install base (66) with no ratings limits reputation signal.
- AI assistant extension processing VA.gov page content raises data-handling concerns without verifiable privacy policy.
- MV3 + no CSP: v2 calibration +2.0 network penalty applies; all JS hosts are US-only and dev-controlled (mitigates).
Evidence
- privacy_policy_fetch_failed api Privacy policy URL https://woobie.io/privacy-policy/ returned HTTPError; treated as no policy fetched.
- content_script_sensitive_domain manifest content_scripts_matches: *://*.va.gov/* — injects into US government VA pages with veteran PII.
- no_developer_name store developer_name is empty string; only email joe@woobie.io available for identity verification.
- very_low_install_count store Only 66 installs, 0 ratings — very limited adoption; reputation signals are weak.
- no_cve_findings crx cve_findings_raw is empty; no known vulnerable JS libraries detected.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, 6 JS files scanned — no malicious indicators.
- threat_intel_clean api No bad_host_hits, monetization_hits, or affiliate_hits; developer domain resolves, not throwaway.
- ai_extension_va_gov manifest Description states AI assistant for claim/status help while browsing; AI processing on gov site.
Permissions Breakdown
- activeTab low Grants access to current tab only on user action; scoped and low blast radius.
- identity low Used for OAuth/Cognito auth flow; no broad scope requested.
- storage low Local extension storage; no cross-site data exposure.
- host:amazoncognito.com low AWS Cognito auth endpoint; scoped to dev's auth service.
- host:auth.dev-myra.woobie.io low Dev-owned subdomain for auth; scoped.
- host:cognito-idp.us-west-2.amazonaws.com low AWS Cognito IDP; standard auth backend.
- host:api.woobie.io low Dev-owned API; scoped to stated function.
- host:app.woobie.io low Dev-owned app domain; scoped.
- host:dev-app.woobie.io low Dev staging domain; low risk.
- host:api.va.gov medium Government VA API; content scripts run on va.gov — handles sensitive veteran data.
- content_scripts:*://*.va.gov/* medium Injects into all VA.gov pages; accesses sensitive veteran claim/health data in DOM.
Pillar Scores
Permissions2.00
Reputation6.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 15:58
Listing SHA
c6e79133298e…
Force block
— not fired
Score recovered
no
Elapsed
—