Toby: Tab Management Tool
hddnkoipeenegfoeaoibdmnaalmgkpip
Risk Score
4.51
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension (generic corporate policy).
- NewTab override with 300K installs — high-engagement surface for potential monetization or data capture.
- declarativeNetRequestWithHostAccess can intercept/modify network requests; elevated capability for a tab manager.
- tabs permission exposes URLs/titles of all open tabs; combined with analytics endpoints (Amplitude, Mixpanel) raises tracking concern.
- Three innerHTML DOM-XSS sinks in content scripts and background; CSP style-src uses 'unsafe-inline' and wildcard.
Evidence
- newtab_override manifest chrome_url_overrides.newtab = toby.html; replaces new-tab page for all 300K users.
- privacy_policy_scope_mismatch api Policy fetched; data_collection=true, third_party_sharing=true, scope_extension=false — generic policy, not extension-scoped.
- analytics_endpoints crx JS contacts api.amplitude.com and api.mixpanel.com; telemetry sent alongside tabs metadata.
- dom_xss_sinks crx 3 innerHTML assignments from variables found in background.js, Note chunk, and content-script inject-public.js.
- csp_style_wildcard_unsafe_inline manifest style-src includes 'unsafe-inline' and '*'; weakens CSP protections against style injection.
- declarativeNetRequestWithHostAccess manifest High-capability permission to intercept requests; only scoped to *.gettoby.com but still elevated.
- featured_by_google store Extension is featured by Google — partial trust signal; no verified publisher badge.
- no_developer_name store developer_name is empty string; only email hello@gettoby.com available.
Permissions Breakdown
- contextMenus low Adds right-click menu items; limited surface.
- unlimitedStorage low Allows large local data storage; no exfil risk alone.
- storage low Standard sync/local storage; expected for tab manager.
- tabs medium Can read tab URLs/titles across all tabs — broad metadata access.
- declarativeNetRequestWithHostAccess high Can intercept/block network requests; paired with host permissions.
- chrome_url_overrides.newtab medium Replaces new-tab page; high-engagement surface, monetization risk.
- host_permissions: https://*.gettoby.com/ low Scoped to developer's own domain; low third-party risk.
Pillar Scores
Permissions5.50
Reputation4.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality1.50
CVE Exposure0.00
Scoring History
| fsssiedxn3098b1a7zan3098b1a7zsssiedx | 4.35 | Medium | review | 2026-09-10 |
| fsssiedxn7d207a5dza"n7d207a5dzsssiedx | 4.05 | Medium | review | 2026-09-10 |
| fsssiedxnd9aba880za | 4.16 | Medium | review | 2026-09-10 |
| sssiednb176aaa3dp727562726963xsx | 4.32 | Medium | review | 2026-09-10 |
| sssiedn6e5843eddp727562726963xsx | 4.37 | Medium | review | 2026-09-09 |
| fsssiedxn631d8d59zan631d8d59zsssiedx | 4.14 | Medium | review | 2026-09-03 |
| fsssiedxn70e964deza'n70e964dezsssiedx | 4.44 | Medium | review | 2026-09-03 |
| fsssiedxn9b1c436aza"n9b1c436azsssiedx | 4.22 | Medium | review | 2026-09-03 |
| sssiednac25ed38dp727562726963xsx | 4.08 | Medium | review | 2026-09-03 |
| fsssiedxn591fddc3za"n591fddc3zsssiedx | 4.27 | Medium | review | 2026-09-02 |
| sssiedn3875a014dp727562726963xsx | 4.04 | Medium | review | 2026-09-02 |
| fsssiedxnddd64236zafdsaxax><!--></ScRiPt>asddnddd64236zsssiedx | 4.26 | Medium | review | 2026-08-30 |
| fsssiedxne87ff5e8za | 4.26 | Medium | review | 2026-08-30 |
| sssiedn3e356232dp727562726963xsx | 4.19 | Medium | review | 2026-08-30 |
| fsssiedxasssiedx | 4.12 | Medium | review | 2026-08-08 |
| fsssiedxa | 4.01 | Medium | review | 2026-08-08 |
| sssieddrubricxsx | 4.28 | Medium | review | 2026-08-08 |
| v3.6 | 4.51 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
57c6dfefea58…
Force block
— not fired
Score recovered
no
Elapsed
26.9s