VU Toolkit - Quiz Firewall Bypasser DigiSkills & Cisco Study Buddy
fkffpcgkilifkfofbklahpfjmgbdflho
Risk Score
3.47
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Cookies permission over 3 educational domains enables session-token theft if extension is ever compromised.
- No CSP: new Function() constructor in content3.js executes without sandbox protection.
- Free-webmail developer (gmail) with no verified business identity; no developer name listed.
- Privacy policy admits data collection and third-party sharing but lacks retention details.
- External JS hosts include tinyurl.com (redirect service) alongside github.com — potential redirection risk.
Evidence
- cookies+host_permissions manifest cookies permission scoped to vu.edu.pk, netacad.com, digiskills.pk — can read auth cookies on all three.
- no_csp crx content_security_policy is null; no CSP protection for MV3 extension.
- function_constructor crx new Function('return this') in content3.js; common in bundled polyfills but increases code-exec surface.
- free_webmail_dev store Developer email vutoolkitbyparadox@gmail.com; no developer name; no business domain.
- privacy_policy_third_party api Policy fetched, scoped, but third_party_sharing=true and retention=false — incomplete data handling disclosure.
- external_js_hosts crx js_external_hosts: github.com, tinyurl.com — tinyurl is a URL shortener with unpredictable destinations.
- geo_diversity crx JS hosts span 4 countries (CA, IN, PK, US); triggers +1.5 network penalty for non-exempt category.
- verified_publisher store verified_publisher=true; discounts reputation but capped at -1.0 under v3.5 invariant 0c due to gmail domain.
Permissions Breakdown
- activeTab low Only the currently active tab; limited blast radius.
- scripting medium Can inject scripts into matched pages; moderate risk when combined with host_permissions.
- storage low Local extension storage; no cross-origin data access.
- cookies high Can read/write cookies; combined with host_permissions on vu.edu.pk/digiskills.pk/netacad.com is credential-risk.
- *://*.vu.edu.pk/* medium Scoped to one educational domain; matches stated function.
- *://*.netacad.com/* medium Scoped to Cisco NetAcad; matches stated function.
- *://*.digiskills.pk/* medium Scoped to DigiSkills Pakistan; matches stated function.
Pillar Scores
Permissions4.00
Reputation7.50
Network2.00
Webstore1.00
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA
556026ce736c…
Force block
— not fired
Score recovered
no
Elapsed
24.8s