极客侧边栏-免费DeepSeek丨书签云同步
gjkfnalkblnjkalnipilmaacibikciin
Risk Score
6.17
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack redirects to adtsa.mikecrm.com — active monetization/tracking on removal.
- userScripts + scripting + <all_urls>: arbitrary code injection into every site the user visits.
- CSP sandbox allows unsafe-eval and wildcard script-src — remote code execution surface in sandboxed context.
- Privacy policy not scoped to this extension and silent on third-party sharing; effectively opaque data handling.
- Contacts 12 external hosts including adtsa.mikecrm.com, WeChat, Tencent COS, and Google Analytics with no retention disclosure.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to http://adtsa.mikecrm.com/0DzVI9G — third-party ad/monetization domain.
- userScripts_permission manifest userScripts declared — allows injection of arbitrary scripts into any page, bypassing normal scripting guards.
- csp_unsafe_eval_sandbox manifest Sandbox CSP: script-src 'unsafe-inline' 'unsafe-eval' * — wildcard script sources with eval in sandboxed pages.
- broad_host_access manifest <all_urls> host_permission + content_scripts on <all_urls> combined with scripting API.
- privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=false, third_party_silence=true — generic and non-specific.
- external_hosts_diverse crx 12 distinct JS external hosts including adtsa.mikecrm.com, Tencent COS (CN), WeChat, gstatic.cn — geo: CN, SG, US.
- monetization_host crx google-analytics.com in js_external_hosts; adtsa.mikecrm.com in uninstall URL — monetization layer present.
- dom_xss_sink crx innerHTML set from variable in noteEditor-BnNUl5Sj.js without CSP guard — DOM-XSS risk.
Permissions Breakdown
- tabGroups low Tab organization; low risk.
- <all_urls> high Full host access to every site the user visits.
- storage low Standard local data persistence.
- unlimitedStorage low Extended storage; minor risk alone.
- tabs medium Can read tab URLs and titles across all tabs.
- activeTab medium Access to current tab on user action.
- webNavigation medium Monitors navigation events across all tabs.
- contextMenus low Adds right-click menu items; low risk.
- bookmarks medium Read/write access to all browser bookmarks.
- sidePanel low UI surface only.
- scripting high Programmatic script injection into pages; paired with <all_urls>.
- userScripts high Can inject arbitrary user scripts into any page; very high risk surface.
- *://*/* high Redundant broad host — amplifies scripting and content_script risk.
Pillar Scores
Permissions8.50
Reputation5.00
Network6.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:24
Listing SHA
7c8ad4906d2f…
Force block
— not fired
Score recovered
no
Elapsed
—