Google Meet ⇔ Slack integration (Glack)
kddjlbegfaiogihndmglihcgommbjmkc
Risk Score
4.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing (→ Privacy pillar 10.0).
- Brand impersonation: extension name and manifest reference both 'Google' and 'Slack' without verified ownership of either brand.
- Developer is free-webmail (gmail.com) with no verifiable business identity, raising supply-chain risk.
- innerHTML sink in popup.js is an unmitigated DOM-XSS vector if untrusted data reaches it.
- 16 months since last update with no disclosed changelog increases stale-code risk.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands=['slack','google']; confirmed_owner=false; dev domain=gmail.com.
- generic_privacy_policy store Policy is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email meetslack3@gmail.com; no business website; no verified publisher badge.
- dom_xss_sink crx popup.js: innerHTML assigned from variable 'data' — DOM-XSS if attacker controls input.
- is_featured_by_google store Extension carries 'Featured' badge — partial reputation credit applied.
- maintenance_stale store Last updated February 18 2025; months_since_update=16 — 6-12 month band at scoring time.
- host_permissions_scoped manifest Host access limited to meet.google.com, slack.com, gstatic.com — matches stated integration function.
- csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self' — no unsafe-eval or remote CDN; MV3 no bonus penalty.
Permissions Breakdown
- storage low Stores local config; no cross-site data exposure on its own.
- https://meet.google.com/* medium Content script host; scoped to Meet only, matches stated function.
- https://slack.com/* medium Host permission to post status to Slack API; matches stated function.
- https://www.gstatic.com/* low Static Google asset CDN; read-only resource fetch.
Pillar Scores
Permissions1.50
Reputation7.50
Network0.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
4eec630cb964…
Force block
— not fired
Score recovered
no
Elapsed
23.0s