Open Slack in Browser, not App
jkgehijlkoolgcjifalbiicaomkngakb
Risk Score
5.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
- Brand impersonation: 'slack' mentioned, developer not a confirmed Slack owner, free-webmail gmail dev.
- Shell pattern flagged by description_promise.is_shell_pattern; sparse manifest raises authenticity concern.
- Stale: 20 months since last update on MV3 extension with 4K installs.
- Developer identity unverifiable: free-webmail alias email, no business domain, no verified-publisher badge.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['slack']; confirmed_owner=false; dev domain is gmail.com.
- privacy_policy_generic store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- shell_pattern store description_promise.is_shell_pattern=true; manifest_description equals extension title; no mismatches but suspicious minimal footprint.
- free_webmail_dev store developer_email=user.2g3t@gmail.com; no business website; dev name='yume'; no verified publisher badge.
- stale_extension store months_since_update=20; maps to +6.0 maintenance (6-24 mo band).
- content_scripts_scoped manifest content_scripts limited to *.slack.com only; no broad host permissions; permissions[] empty.
- no_cve_no_obfuscation crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0; single JS file, no external hosts beyond github.com.
- no_bad_hosts_no_monetization api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; operator sibling_count=0.
Permissions Breakdown
- content_scripts: *.slack.com/archives/*, *.slack.com/ssb/redirect* medium Scoped to slack.com subdomains only; low breadth but can read/modify Slack pages.
Pillar Scores
Permissions1.00
Reputation7.50
Network0.00
Webstore6.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
37a61911b9aa…
Force block
— not fired
Score recovered
no
Elapsed
21.5s