Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

塔塔网申神器 - AI一键求职填简历

ldohbgcnonoffldimgdngkojkejibina
Risk Score
4.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 9,000
Rating 5.0
Last updated 2026-08-22
Manifest version MV3
CSP present ❌ no
Developer 2933682586@qq.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • <all_urls> host permission + content_scripts on every page: full read/write access to all browsing activity
  • Privacy policy fetched but scope_extension=false and third_party_silence=true: no meaningful disclosure for this extension
  • Developer email is numbered QQ alias (2933682586@qq.com), no developer name — low accountability
  • AI extension processes page content on all URLs; exfil surface is high even without detected bad hosts
  • DOM-XSS sink (innerHTML) in entry.js with no CSP; exploitable if user-controlled content reaches sink

Evidence

  • host_permissions_all_urls manifest <all_urls> host permission paired with content_scripts *://*/* grants full page access on every site.
  • privacy_policy_scope_missing crx Policy fetched (29k chars) but scope_extension=false, data_collection=false, third_party_silence=true — generic, unscoped.
  • developer_identity_weak store Developer email is numbered QQ alias; no developer_name provided; looks_throwaway=true per threat_intel.
  • dom_xss_sink_no_csp crx innerHTML user-controlled sink in js/entry.js; csp_present=false on MV3 increases exploitability.
  • js_external_hosts crx Extension contacts mp.weixin.qq.com, work.weixin.qq.com, www.tatawangshen.com, www.xiaotastudio.com (3 countries).
  • verified_publisher store verified_publisher=true; mitigates reputation somewhat but capped due to looks_throwaway=true per v3.5 rule E.
  • no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries detected.
  • ai_extension_all_urls store AI job-application filler with <all_urls>; processes page content on arbitrary sites — elevated exfil surface.

Permissions Breakdown

  • storage low Standard local data storage; low standalone risk.
  • activeTab low Scoped to user-triggered tab; low risk alone.
  • <all_urls> (host_permission) high Grants content script access to every site; high reach paired with content_scripts *://*/*.
  • content_scripts *://*/* high Scripts injected on all pages; amplifies host permission reach.

Pillar Scores

Permissions5.00
Reputation6.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:14
Listing SHA e187e2ec7a5a…
Force block — not fired
Score recovered no
Elapsed