Ries - AI Writing & Translate. Any Language.
gommajbfaholfodlhddhaonphdhonjgj
Risk Score
6.54
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- webRequest + content_scripts <all_urls> + management: high-capability combo on every site visited
- Gmail developer (oriontyce@gmail.com), no dev name — low accountability for high-capability extension
- Privacy policy fetched but scope_extension==false and third_party_silence==true — no disclosure of what THIS extension collects
- uninstall_url_hijack==true: onUninstall redirects to third-party URL
Evidence
- webRequest + management permissions manifest webRequest can intercept all network traffic; management can enumerate/disable other extensions.
- content_scripts <all_urls> manifest Script injected on every page; combined with webRequest creates full traffic + DOM access.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() directs to third-party on removal — monetization/tracking signal.
- gmail developer, no dev name, verified_publisher=true store Developer email oriontyce@gmail.com; no organization name. Verified publisher partially mitigates.
- privacy policy scope_extension==false api Policy at ries.ai/privacy does not scope disclosures to this extension; no retention info.
- affiliate_hits: bit.ly crx bit.ly short-link redirector present in JS external hosts — affiliate/cloaking pattern.
- dom_sink_innerhtml_userctrl in popup-react.js crx innerHTML sink from variable; DOM-XSS risk if user-controlled data reaches this path.
- sandbox CSP allows unsafe-inline + unsafe-eval manifest Sandbox policy permits unsafe-inline and unsafe-eval in script-src, weakening sandbox isolation.
Permissions Breakdown
- storage low Standard local storage for settings/preferences.
- activeTab medium Access to current tab on user action; limited scope.
- alarms low Scheduling background tasks; low direct risk.
- webRequest high Intercept/observe all network requests across all URLs.
- commands low Keyboard shortcut bindings; low risk.
- management high Can enumerate/disable other installed extensions — high abuse potential.
- content_scripts <all_urls> high Injects scripts into every page the user visits — full page read/write.
- host: AI/translation APIs medium Contacts multiple external AI backends (deepseek, siliconflow, aliyun, volces, tu-zi).
- host: youtube/bilibili/googlevideo medium Media platform access for subtitle features; broad reach on high-value sites.
Pillar Scores
Permissions7.50
Reputation6.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
1d34ea6fb76b…
Force block
— not fired
Score recovered
no
Elapsed
27.5s