GitHub Issue Helper
ofckeainckjmmfocpjilclcdfcoajfno
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension, admits data collection and 3rd-party sharing (v3.5 D: +10.0).
- Brand impersonation: 'GitHub' mentioned in name/description by unverified gmail developer with no confirmed ownership.
- AI extension sends GitHub issue content to generativelanguage.googleapis.com (Google Gemini) — data leaves browser.
- Stale extension (20 months since update) with no CSP and no privacy governance.
- Free-webmail developer (gmail), no verified publisher badge, no business domain — minimal accountability.
Evidence
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D: +10.0.
- brand_impersonation store brand_mention.is_impersonation=true, brands=['github'], developer_domain=gmail.com, confirmed_owner=false.
- ai_extension_external_host crx js_external_hosts includes generativelanguage.googleapis.com; extension processes GitHub issue content via LLM API.
- no_csp manifest content_security_policy=null; MV3 default applies but no explicit CSP defined.
- free_webmail_developer store Developer email kumarshubham347@gmail.com; no business website; no verified publisher badge.
- stale_extension store months_since_update=20; band 6-12mo for maintenance.
- host_permissions_github manifest host_permissions=['https://github.com/*']; content_scripts scoped to issues pages only — partial mitigation.
- no_cve_findings crx cve_findings_raw=[]; js_libraries_detected=[]; CVE pillar=0.0.
Permissions Breakdown
- activeTab low Grants access to current tab only on user action; scoped and transient.
- scripting medium Allows injecting scripts into pages; paired with host_permissions limits scope to github.com.
- storage low Local data persistence only; no exfil risk on its own.
- https://github.com/* medium Broad access to all GitHub pages including private repos and issue content.
Pillar Scores
Permissions2.30
Reputation7.50
Network2.50
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
bb19476c7c8c…
Force block
— not fired
Score recovered
no
Elapsed
21.6s