Trusty Search Assistant for Amazon
hpmchbfaebbmmhepolfecmihamjfmofl
Risk Score
5.77
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 (Arbitrary Code Execution) in bundled underscore@1.8.3, no CSP, amplifier applies.
- Privacy policy is Google's generic policy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy score.
- last_updated missing: maintenance unknown, treated as worst-case >36 months → maximum maintenance score.
- Amazon brand impersonation by unverified gmail developer with no business domain.
- 5 external JS hosts referenced (gifer, lodash, openjsf, npms, underscorejs) with no CSP to constrain them.
Evidence
- CVE critical+high in underscore@1.8.3; no CSP; underscore is DOM-manipulation-adjacent lib crx CVE-2021-23358 (critical ACE) and CVE-2026-27601 (high DoS) both unfixed. csp_present=false triggers ×1.5 amplifier.
- Privacy policy is Google's own account policy, not scoped to this extension store scope_extension=false, data_collection=true, third_party_sharing=true → D-clause: +10.0 privacy pillar.
- last_updated blank; months_since_update null store No update date available; scored as >36 months (maintenance=10.0) per conservative rubric.
- Amazon brand impersonation by gmail developer store brand_mention.is_impersonation=true, developer_email=casey1@gmail.com, not verified, not featured owner.
- 5 external JS hosts with no CSP (MV3) crx i.gifer.com, lodash.com, npms.io, openjsf.org, underscorejs.org — >3 distinct domains; no CSP constraint.
- Free-webmail developer, no business domain store casey1@gmail.com; gmail dev + no business site → reputation floor ≥7.5 per rubric.
- is_featured_by_google=true partially offsets reputation but impersonation and gmail still high-risk store Featured badge applied (-2.0 reputation) but floor rule for free-webmail keeps reputation at 8.0.
- operator_cluster sibling_count by dev_email=1 indicates same email used across multiple extensions api sibling_counts_by_dim.dev_email=1; direct siblings=0 but email fingerprint shared.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Persists local extension state; no data exfil risk on its own.
- content_scripts(*://*.amazon.*/s?*) medium Runs on Amazon search pages across 14 TLDs; scoped to amazon domains only.
Pillar Scores
Permissions1.30
Reputation8.00
Network2.50
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
c7376e507985…
Force block
— not fired
Score recovered
no
Elapsed
28.1s