塔塔网申神器 - AI一键求职填简历
ldohbgcnonoffldimgdngkojkejibina
Risk Score
4.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- <all_urls> host permission + content_scripts on every page: full read/write access to all browsing activity
- Privacy policy fetched but scope_extension=false and third_party_silence=true: no meaningful disclosure for this extension
- Developer email is numbered QQ alias (2933682586@qq.com), no developer name — low accountability
- AI extension processes page content on all URLs; exfil surface is high even without detected bad hosts
- DOM-XSS sink (innerHTML) in entry.js with no CSP; exploitable if user-controlled content reaches sink
Evidence
- host_permissions_all_urls manifest <all_urls> host permission paired with content_scripts *://*/* grants full page access on every site.
- privacy_policy_scope_missing crx Policy fetched (29k chars) but scope_extension=false, data_collection=false, third_party_silence=true — generic, unscoped.
- developer_identity_weak store Developer email is numbered QQ alias; no developer_name provided; looks_throwaway=true per threat_intel.
- dom_xss_sink_no_csp crx innerHTML user-controlled sink in js/entry.js; csp_present=false on MV3 increases exploitability.
- js_external_hosts crx Extension contacts mp.weixin.qq.com, work.weixin.qq.com, www.tatawangshen.com, www.xiaotastudio.com (3 countries).
- verified_publisher store verified_publisher=true; mitigates reputation somewhat but capped due to looks_throwaway=true per v3.5 rule E.
- no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries detected.
- ai_extension_all_urls store AI job-application filler with <all_urls>; processes page content on arbitrary sites — elevated exfil surface.
Permissions Breakdown
- storage low Standard local data storage; low standalone risk.
- activeTab low Scoped to user-triggered tab; low risk alone.
- <all_urls> (host_permission) high Grants content script access to every site; high reach paired with content_scripts *://*/*.
- content_scripts *://*/* high Scripts injected on all pages; amplifies host permission reach.
Pillar Scores
Permissions5.00
Reputation6.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:14
Listing SHA
e187e2ec7a5a…
Force block
— not fired
Score recovered
no
Elapsed
—