| scripting | Permission | | This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to. |
| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact• 10% increase: Early script execution enables pre-emptive content manipulation |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| gcm | Permission | | This permission enables Google Cloud Messaging for push notifications. Rated Medium because it can maintain persistent connections, receive external messages, and operate in the background. |
| https://mail.google.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://outlook.live.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://outlook.cloud.microsoft/* | Host | | Host permission — access limited to this URL pattern. |
| https://outlook.office365.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://outlook.office.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.linkedin.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.funnelflare.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://calendar.google.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.activedemand.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.pipedrive.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://app.pipelinedeals.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://app.pipelinecrm.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://account.enquiresolutions.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.salesforce.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.lightning.force.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.cloudforce.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.nocrm.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://app.nimble.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.freshsales.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.myfreshworks.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.sherpacrm.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.sherpacrm.co.uk/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.dynamics.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.zoho.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.eldermark.io/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.alisonline.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.welcomehomesoftware.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://*.yardipcv.com/* | Host | | Host permission — access limited to this URL pattern. |
| Access to Sensitive Domains | Risk Factor | | This extension requests access to sensitive domains: https://mail.google.com/*, https://outlook.live.com/*, https://outlook.cloud.microsoft/*, https://outlook.office365.com/*, https://outlook.office.com/*, https://*.linkedin.com/*, https://calendar.google.com/*, https://*.lightning.force.com/* |
| Early Content Script Execution | Risk Factor | | This extension runs content scripts at document_start. |
| notifications | Permission | | This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data. |
| contextMenus | Permission | | This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content. |
| alarms | Permission | | This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data. |