CodeSquire.ai

ID: ikldibchjbalnngafojhlnbddkehoooc

Could be malicious

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Removed
Version
2.1.4
Size
0.68 MB
Rating
5.0/5
Reviews
6
Users
8,000
Type
Extension
Updated
May 12, 2023
Category
Productivity Developer
Price
Paid
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
https://codesquire.aiView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
8,000

A code writing assistant for data scientists

Do you spend hours deciphering complex code or trying to grok new algorithms? CodeSquire.ai is here to help! Our AI code assistant can take on any coding challenge, from basic data analysis to more advanced artificial intelligence tasks. Whether you're a data scientist struggling with a tricky problem or an engineer tasked with creating the next big app, our code assistant has you covered. We support JupyterLab, Google Colab, and BigQuery Console. To learn more and start using our AI code assistant today, visit codesquire.ai

Item
Type
Severity
Description
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.

By severity

Critical0
High3
Medium3
Low1

Versions scanned

Showing 1 of 19 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.0.07

Files with findings

2 distinct paths — top paths by unique finding count:

  • scripts/background.js5
  • manifest.json2
S.No.
Category
Severity
File
Summary
Found in Version
1Credential Theft
high
scripts/background.js (line 138)The background script accepts external messages (from app.codesquire.ai per externally_connectable) carrying raw email/password or Google OAuth ID tokens and feeds them directly into firebase.auth().signInWithCredenti…
2Privilege Escalation
high
manifest.json (line 70)The match pattern `*://*:*/lab*` injects jQuery, crypto-js, tailwind, highlight.js, and the assistant scripts into ANY URL on ANY host and ANY port whose path begins with `/lab` — e.g. example.com/lab, foo.com/labrado…
3Remote Code Loading
high
scripts/background.js (line 59)The service worker opens a persistent WebSocket to ws://localhost:35729 and dispatches a 'reload' action received from the socket to chrome.runtime.reload() / chrome.tabs.reload(). This is webpack-webextension-plugin …
4Credential Theft
medium
scripts/background.js (line 232)A Firebase ID token is mirrored into chrome.cookies (app.codesquire.ai) AND chrome.storage.local AND injected into content-script contexts running on third-party origins (colab.research.google.com, console.cloud.googl…
5Credential Theft
medium
scripts/background.js (line 120)A hardcoded shared secret `demoeldenlord3142` is embedded in the production service worker (and referenced again as a commented Bearer token in app.js: `'Authorization': 'Bearer demoeldenlord3142'`). Even though the A…
6Unauthorized Data Collection
medium
manifest.json (line 90)The extension declares `<all_urls>` host_permissions plus the `cookies` API permission while its declared content scripts only run on three site groups. The combination grants the background service worker the ability…
7Other
low
scripts/background.js (line 117)The service worker calls importScripts on `../libs/firebase-auth.js`, but no `firebase-auth.js` file is present in the bundle — only firebase-app.js exists. This means the production service worker either silently fai…
URLs
79
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.apache.org/licenses/LICENSE-2.0http://www.apache.org/licenses/LICENSE-2.0
tailwindcss.com/n*//*/n1.https://tailwindcss.com\n*//*\n1.
github.com/mozdevs/cssremedy/issues/4https://github.com/mozdevs/cssremedy/issues/4
github.com/tailwindcss/tailwindcss/pull/116https://github.com/tailwindcss/tailwindcss/pull/116
bugzilla.mozilla.org/show_bug.cgihttps://bugzilla.mozilla.org/show_bug.cgi?id=190655
bugs.chromium.org/p/chromium/issues/detailhttps://bugs.chromium.org/p/chromium/issues/detail?id=999088,
bugs.webkit.org/show_bug.cgihttps://bugs.webkit.org/show_bug.cgi?id=201297
bugs.chromium.org/p/chromium/issues/detailhttps://bugs.chromium.org/p/chromium/issues/detail?id=935729,
bugs.webkit.org/show_bug.cgihttps://bugs.webkit.org/show_bug.cgi?id=195016
github.com/mozilla/gecko-dev/blob/2f9eacd9d3d995c937b4251a5557d95d494c9be1/layout/style/res/forms.csshttps://github.com/mozilla/gecko-dev/blob/2f9eacd9d3d995c937b4251a5557d95d494c9be1/layout/style/res/forms.css#L728-L737
Showing 1 to 10 of 80 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 10 of 20 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.