Gold Rush - Slot Machine
kbmindomjiejdikjaagfdbdfpnlanobi
Risk Score
4.42
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched from unscoped CDN URL admits data collection and third-party sharing without extension-specific scope — rates maximum privacy score.
- No developer name listed; anonymous publisher with minimal install base (13 users) raises accountability concern.
- Privacy policy hosted on cdn.cloudapi.stream (not developer domain top.rodeo) — lacks authenticity and scoping to this extension.
- Sandbox CSP allows unsafe-inline and unsafe-eval, permitting arbitrary script execution in sandboxed context.
- 12 distinct external JS hosts referenced in source files, including goo.gl shortener and unrelated third-party domains, indicating broad external surface.
Evidence
- privacy_policy_generic_cdn crx Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=true, third_party_sharing=true — triggers D hardening +10.0.
- no_developer_name store developer_name is empty string; no verified publisher badge; anonymous publisher.
- sandbox_unsafe_eval manifest sandbox CSP includes unsafe-inline and unsafe-eval on script-src; extension_pages CSP is strict.
- broad_external_hosts crx 12 external JS hosts including goo.gl, bugzilla.mozilla.org, harrytheo.com, mkeystudio.com — 4+ distinct domains.
- very_low_installs store Only 13 installs; new/obscure extension with no ratings and no operator siblings.
- cloudapi_stream_host manifest Host permissions include wheel.cloudapi.stream and mines.cloudapi.stream — CDN-style domains not clearly tied to developer domain.
- maintenance_3_6mo store months_since_update=11; falls in 6-12 month band (+3.5).
- cve_findings_empty crx No CVEs found; @popperjs/core version unknown; cve_pillar=0.0.
Permissions Breakdown
- identity low OAuth identity; low risk alone, but paired with googleapis host access it enables user-account linkage.
- https://www.googleapis.com/* medium Google API host; enables server-side account operations via identity token.
- https://wheel.cloudapi.stream/* medium Developer-controlled CDN subdomain; unclear purpose beyond stated game function.
- https://mines.cloudapi.stream/* medium Developer-controlled CDN subdomain; second game endpoint on same opaque CDN.
- https://top.rodeo/* low Developer's own domain; expected for a game extension.
Pillar Scores
Permissions1.50
Reputation6.50
Network2.00
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:59
Listing SHA
bedf5a8ef058…
Force block
— not fired
Score recovered
no
Elapsed
—