Slack PWA
llnpadfplnebjlenlkkjfblppjeakoja
Risk Score
4.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: extension claims to be 'Slack PWA' but developer is unrelated third party (frimware.in).
- Developer domain does not resolve (frimware.in), raising abandonment/hijack risk.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Extension loads from raw.githubusercontent.com, enabling remote code delivery outside Chrome Web Store review.
- No developer name listed; verified publisher badge does not offset impersonation + non-resolving domain.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; mentions 'slack' but confirmed_owner=false; developer domain frimware.in is unrelated.
- developer_domain_not_resolving api threat_intel.developer_domain_info.resolves=false for frimware.in; domain cannot be verified as active.
- generic_privacy_policy store Privacy policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true); not scoped to extension.
- remote_js_host crx js_external_hosts includes raw.githubusercontent.com; potential for remote code delivery not reviewed by Web Store.
- no_csp manifest content_security_policy=null on MV3; default MV3 CSP applies but external host in fingerprint is concerning.
- verified_publisher_cap_applies store verified_publisher=true but developer_domain_info.resolves=false; v3.5 invariant 0c caps discount at -1.0.
- no_developer_name store developer_name is empty string; no 'Offered by' identity visible to users.
- scripting_plus_slack_host manifest scripting permission + content_scripts on app.slack.com/* enables full read/write of Slack sessions.
Permissions Breakdown
- offscreen low Creates offscreen documents; limited scope, low standalone risk.
- scripting medium Can inject scripts into pages; scoped to app.slack.com but enables code execution.
- *://app.slack.com/* medium Host access to Slack app; scoped to single domain but can read/modify all Slack content.
Pillar Scores
Permissions2.30
Reputation7.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA
e642c352a32d…
Force block
— not fired
Score recovered
no
Elapsed
20.7s