Bless
pljbjcehnhcnofmkdbjolghdcjnmekia
Risk Score
3.54
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- cookies + scripting across 8 high-value AI/commerce origins (ChatGPT, Claude, Google, Amazon, Meta) — broad session-hijack surface
- No developer name listed; txlabs.org unverified organization identity despite verified-publisher badge
- js_external_hosts includes raw.githubusercontent.com and huggingface.co — dynamic model/code fetch risk not confirmed but concerning
- AI-extension processing content on major platforms with rating 3.2 — below-average user satisfaction may reflect behavioral concerns
- system.cpu + system.memory access suggests potential resource-usage telemetry (cryptomining profile pattern)
Evidence
- cookies+scripting on AI/commerce origins manifest cookies perm + scripting + host_permissions span ChatGPT, Claude, Google, Amazon, Meta AI — full session access.
- verified_publisher=true, no developer_name store Publisher badge present but developer_name is empty string; identity opacity elevated.
- js_external_hosts: raw.githubusercontent.com, huggingface.co crx Extension references GitHub raw and HuggingFace — potential remote model/code loading endpoints.
- is_ai_extension + content_scripts on major platforms manifest Content scripts injected into Google, ChatGPT, Grok, Amazon, Meta AI — AI extension reading page content.
- privacy_policy fully scoped and adequate api fetched=true, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — comprehensive policy.
- no code_findings, obfuscation_score=0.0, js_files_scanned=0 crx Code scan returned no findings but 0 files scanned — surface area not confirmed clean.
- rating 3.2 at 100K installs store Below-average rating at significant install base; review fetch failed (SSLError) so red-flag pattern unconfirmed.
- cve_findings_raw=[], threat_intel clean api No CVEs, no bad hosts, no monetization/affiliate hits, domain resolves, not throwaway.
Permissions Breakdown
- storage low Persists local extension data; low standalone risk.
- background low Keeps service worker active; low risk on MV3.
- system.cpu low Read-only CPU metrics; could profile user workload.
- system.memory low Read-only memory info; low direct harm.
- offscreen low Offscreen document for DOM tasks; contained in MV3.
- scripting high Can inject JS into matched AI/shopping origins at runtime.
- tabs medium Reads tab URLs and metadata across sessions.
- declarativeNetRequest medium Can intercept/block/redirect network requests via rules.
- cookies high Access to cookies on matched high-value AI/commerce origins.
- host:chatgpt.com high Full access to ChatGPT sessions including auth cookies.
- host:*.google.com high Broad Google property access including Search, Gmail, Gemini.
- host:perplexity.ai high AI assistant session access.
- host:claude.ai high Anthropic Claude session/cookie access.
- host:grok.com high xAI Grok session access.
- host:amazon.com high Commerce/account session on major shopping platform.
- host:meta.ai + gateway.meta.ai high Meta AI session and API gateway access.
Pillar Scores
Permissions6.50
Reputation4.00
Network3.50
Webstore4.00
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 23:11
Listing SHA
ce9aa5ea78b3…
Force block
— not fired
Score recovered
no
Elapsed
—