Amazon Q Developer | GitHub issue helper
oefafjbablenakmhacfllkmpaeabnnfi
Risk Score
3.50
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is generic AWS policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
- No CSP on MV3 extension; two innerHTML DOM-XSS sinks in content/helpPanel JS running on all GitHub pages.
- Content script injects into all GitHub repo pages — reads issue content and DOM data from every GitHub visit.
- Uninstall URL hijack flag set (uninstall_url_hijack=true) — potential redirect on uninstall.
- AI extension processing GitHub page content with broad React DOM manipulation patterns.
Evidence
- verified_publisher_amazon store Verified publisher with amazon.com domain; recognized org — reputation floored at 2.0 per hard floor rule.
- privacy_policy_generic api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5-D).
- csp_absent_mv3 manifest content_security_policy is null; no CSP present on MV3 extension.
- dom_sink_innerhtml_no_csp crx Two dom_sink_innerhtml_userctrl findings in content.js and helpPanel.js; csp_present=false → +2.0 each (FIX B).
- uninstall_url_hijack crx uninstall_url_hijack=true; target=null. Flagged but target unknown — minor webstore risk.
- content_script_github manifest Content script scoped to https://github.com/*/* only — narrow and matches stated function.
- no_bad_hosts_no_cves api bad_host_hits=[], affiliate_hits=[], cve_findings_raw=[] — clean threat intel and CVE scan.
- ai_extension_page_content store AI extension processing GitHub issue page content via side panel; +2.5 webstore AI signal applied.
Permissions Breakdown
- sidePanel low Opens a side panel UI; no data access beyond what JS can see in panel.
- tabs medium Can read tab URLs and titles; combined with content scripts enables tab tracking.
- content_scripts: https://github.com/*/* medium Injects JS into all GitHub repo/issue pages; reads page DOM including issue content.
Pillar Scores
Permissions1.60
Reputation2.00
Network2.00
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
6ea1d55d30bc…
Force block
— not fired
Score recovered
no
Elapsed
25.0s