Slack Channels Grouping
lcbnhfianneihfgkmfncnhpkpghedbkm
Risk Score
3.76
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: mentions 'Slack' without confirmed owner relationship; developer is unaffiliated gmail user.
- Privacy policy fetched but scope_extension=false and third_party_sharing=true with no retention disclosure.
- No developer name listed; gmail-only identity limits accountability.
- Privacy policy on custom domain but does not scope data handling to this extension specifically.
- Verified publisher and featured badges reduce but do not eliminate identity/impersonation concerns.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands=['slack']; developer_domain=gmail.com; confirmed_owner=false.
- verified_publisher + featured store verified_publisher=true and is_featured_by_google=true; reduces reputation risk but doesn't clear impersonation.
- developer_identity store developer_name empty; developer_email=koukun0120@gmail.com; free webmail, no business domain.
- privacy_policy_classification api fetched=true; scope_extension=false; data_collection=false; third_party_sharing=true; retention=false.
- permissions_scope manifest scripting + host_permissions narrowed to app.slack.com only; MV3; no broad host access.
- code_quality crx code_findings_raw=[]; obfuscation_score=0.0; js_external_hosts=[]; jquery 3.7.1 (no known CVEs).
- threat_intel_clean api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], search_engine_count=0.
- maintenance store last_updated=November 29, 2025; months_since_update=7; 3-6 month band (+1.5).
Permissions Breakdown
- scripting medium Allows dynamic script injection into pages; scoped only to app.slack.com via host_permissions.
- http://app.slack.com/* low Narrow host scope — only Slack app domain, matches stated function.
- https://app.slack.com/* low Narrow host scope — only Slack app domain, matches stated function.
Pillar Scores
Permissions2.50
Reputation6.50
Network0.00
Webstore4.50
Maintenance1.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA
70f327065157…
Force block
— not fired
Score recovered
no
Elapsed
19.4s