Braavos: Bitcoin & Starknet Wallet
jnlgamecbpmbajjfhmmmlhejkemejdma
Risk Score
4.68
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy could not be fetched — treated as no effective policy for scoring.
- cookies permission + broad content_scripts (https://*/*) enables token/session harvesting on any site.
- Dynamic script injection and new Function() constructor in background/content scripts raise XSS-pivot risk.
- innerHTML DOM sink in 473.js is a DOM-XSS vector if upstream data is attacker-controlled.
- 9 distinct external hosts across 4 countries contacted; some are third-party APIs (AWS, Starknet RPCs, fb.me).
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (fetch_error:HTTPError); scored as no effective policy (+10.0 privacy).
- cookies_with_broad_content_scripts manifest cookies permission + content_scripts matching https://*/* creates high-risk session-data access surface.
- uninstall_url_hijack crx uninstall_url_hijack==true; extension registers an uninstall URL redirect.
- dynamic_script_injection crx script_src_dynamic in content.js and main.js; uses chrome.runtime.getURL — internal only, mitigates risk.
- function_constructor crx new Function() in background.js and main.js; classic eval-equivalent pattern.
- dom_xss_sink crx innerHTML assignment in 473.js; CSP present but no nonce hardening observed.
- geo_diversity api JS external hosts span 4 countries (CA, IN, SG, US); wallet category, borderline acceptable but notable.
- no_developer_name store developer_name is empty string; reputation start stays elevated without named entity.
Permissions Breakdown
- storage low Standard wallet key/state persistence.
- alarms low Background scheduling, low risk.
- notifications low User-facing tx alerts, expected for wallet.
- gcm low Push messaging; low standalone risk.
- offscreen low Off-screen document support; low risk.
- sidePanel low UI surface only.
- tabs medium Can read active tab URL; moderate risk.
- cookies high Cookie access; paired with broad content_scripts on https://*/*.
Pillar Scores
Permissions4.00
Reputation5.50
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
31c67c690045…
Force block
— not fired
Score recovered
no
Elapsed
28.9s