CommenTron — AI Booster for LinkedIn
hdappgahcgpifoabanfifjicfllpokgo
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: LinkedIn brand referenced without confirmed ownership; is_impersonation=true.
- AI extension processes LinkedIn page content with scripting + host access — high data-exfil surface.
- Two innerHTML DOM-XSS sinks found in content and popup scripts; no CSP to mitigate.
- Privacy policy discloses third-party data sharing scoped to this extension — data leaves the device.
- No CSP present (MV3 default applies) combined with DOM sinks raises XSS exploitability.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; LinkedIn brand used, confirmed_owner=false, developer domain rocket-pod.com.
- ai_page_content_processing manifest AI extension with scripting + content_scripts on linkedin.com; processes LinkedIn post content for AI comment generation.
- dom_xss_sinks crx Two dom_sink_innerhtml_userctrl findings in contents.e7997a5d.js and popup.68feda32.js; no CSP present.
- no_csp crx content_security_policy is null; MV3 default applies but dom_sink findings increase XSS risk without explicit hardening.
- privacy_third_party_sharing api Privacy policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.
- featured_by_google store is_featured_by_google=true; partial trust signal, offsets reputation penalty partially.
- narrow_host_scope manifest host_permissions and content_scripts limited to https://www.linkedin.com/*; no broad cross-site access.
- operator_cluster_clean api sibling_count=0; no known sibling extensions under same fingerprint. bad_host_hits, affiliate_hits, monetization_hits all empty.
Permissions Breakdown
- storage low Local data persistence; no cross-origin access implied.
- scripting medium Allows programmatic script injection; scoped to linkedin.com via host_permissions.
- https://www.linkedin.com/* medium Host access scoped to single domain; sufficient for stated function but enables DOM read/write.
Pillar Scores
Permissions2.00
Reputation5.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy1.00
Code Quality4.00
CVE Exposure0.00
Scoring History
| sssiedn9dd01e40dp727562726963xsx | 2.04 | Low | review | 2026-09-12 |
| v3.6 | 4.07 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
e9d9a09ca0c0…
Force block
— not fired
Score recovered
no
Elapsed
24.4s