影刀

影刀

ID: nhkjnlcggomjhckdeamipedlomphkepc

Extension Info & Metadata

Status
Active
Version
1.1
Size
0.01 MB
Rating
4.4/5
Reviews
5
Users
600,000
Type
Extension
Updated
Aug 10, 2020
Category
Developer tools
Price
Free
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
whyinggongView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
1
Obsolete
0
Listed
0
Unlisted
1
Total Users
600,000
Screenshot 1

影刀Chrome自动化插件

用于提供影刀与Chrome浏览器之间的通信,为影刀提供自动化操作支持。当使用影刀需要拾取Chrome内的html元素时,需要安装此扩展做为运行依赖。

Item
Type
Severity
Description
debugger
Permission
Critical
This permission grants the extension ability to debug and control other extensions and browser tabs. Rated Critical because it can access and modify other extensions' internal state, inject code, and access sensitive data from any tab.
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
clipboardRead
Permission
High
This permission allows reading clipboard content. Rated High because it can steal copied passwords, sensitive data, and monitor all content copied to clipboard.
clipboardWrite
Permission
High
This permission allows modification of clipboard content. Rated High because it can inject malicious content into the clipboard, modify copied passwords, and manipulate copied data.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 15% increase: Older manifest version lacks modern security controls• 10% increase: About:blank access enables potential sandbox escape vectors
management
Permission
Medium
This permission manages other installed extensions. Rated Medium because it can enable/disable other extensions and modify their settings, with changes being visible to users.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2

Each row lists a threat category the scanner evaluates. A checkmark means the review ran and found no matching issues in that category for this version.

  • Data Exfiltration

    Code review completed; no malicious patterns detected for this category.

  • Unauthorized Data Collection

    Code review completed; no malicious patterns detected for this category.

  • Network Interception

    Code review completed; no malicious patterns detected for this category.

  • Code Injection

    Code review completed; no malicious patterns detected for this category.

  • Credential Theft

    Code review completed; no malicious patterns detected for this category.

  • Obfuscation

    Code review completed; no malicious patterns detected for this category.

  • Tracking

    Code review completed; no malicious patterns detected for this category.

  • Privilege Escalation

    Code review completed; no malicious patterns detected for this category.

  • Phishing

    Code review completed; no malicious patterns detected for this category.

  • Remote Code Loading

    Code review completed; no malicious patterns detected for this category.

  • Other

    Code review completed; no malicious patterns detected for this category.

URLs
3
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
*/*http://*/*
*/*https://*/*

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.1
Latest
0.01 MB
Benign
0
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.