Shortcut Assistant
kmdlofehocppnlkpokdbiaalcelhedef
Risk Score
7.64
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVEs in bundled lodash and underscore 1.8.3 (Prototype Pollution, Arbitrary Code Execution) with no CSP on MV3.
- Multiple high-severity CVEs in lodash, nth-check, css-what, underscore — versions unknown/unfixed.
- Dev-operated DigitalOcean proxy (proxy-zcffd.ondigitalocean.app) receives extension traffic; server-side handling opaque.
- lodash is a DOM-manipulation-adjacent lib with critical/high CVEs and no CSP: CVE amplifier applies.
- Developer name absent from store listing; only 3 installs reduces trust signal despite verified publisher badge.
Evidence
- critical_cve_lodash crx CVE-2019-10744 (critical Prototype Pollution) and CVE-2021-23337 (high Command Injection) in bundled lodash@unknown.
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical Arbitrary Code Execution); fixed_in 1.12.1.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening, amplifying CVE risk.
- dev_proxy_endpoint manifest host_permissions include https://proxy-zcffd.ondigitalocean.app/* — dev-operated proxy with unknown server-side data handling.
- verified_publisher store Extension has verified_publisher=true with matching dev domain voidworks.io that resolves.
- privacy_policy_adequate api Privacy policy fetched, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true, third_party_silence=false.
- telemetry_only_monetization crx threat_intel.monetization_hits contains only Google Analytics; no affiliate or bad-host hits.
- narrow_content_script manifest content_scripts scoped to https://app.shortcut.com/* only; matches stated function as Shortcut power-user tool.
CVE Exposures (13)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2026-41907 | uuid@unknown | moderate | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| CVE-2026-41988 | uuid@unknown | moderate | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| CVE-2021-3803 | nth-check@unknown | high | 2.0.1 | Inefficient Regular Expression Complexity in nth-check |
| CVE-2022-21222 | css-what@unknown | high | 2.1.3 | css-what vulnerable to ReDoS due to use of insecure regular expression |
| CVE-2021-23337 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2026-4800 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2018-16487 | lodash@unknown | high | 4.17.11 | Prototype Pollution in lodash |
| CVE-2025-13465 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2026-2950 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2018-3721 | lodash@unknown | moderate | 4.17.5 | Prototype Pollution in lodash |
| CVE-2019-10744 | lodash@unknown | critical | 4.17.12 | Prototype Pollution in lodash |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Accesses current tab only on user action; low ambient risk.
- commands low Registers keyboard shortcuts; no data access.
- identity low OAuth token flow; no broad scope declared.
- storage low Local/sync storage only; no exfil path alone.
- tabs medium Can enumerate tab URLs/titles; mild privacy surface.
- https://api.openai.com/* medium Sends content to OpenAI API; data leaves browser.
- https://proxy-zcffd.ondigitalocean.app/* medium Dev-operated proxy on DigitalOcean; unknown server-side handling.
- https://www.googleapis.com/* low Standard Google API access; broad but common for identity/AI extensions.
- content_scripts: https://app.shortcut.com/* low Narrow scope to single SaaS app; matches stated purpose.
Pillar Scores
Permissions2.50
Reputation3.00
Network3.50
Webstore1.50
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure9.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:00
Listing SHA
5f4e04b7f722…
Force block
— not fired
Score recovered
no
Elapsed
—