Chrome Web Store
1Versions
1Code reviewed

No malware found

In code review

Our reviewer read this extension’s code and found no malicious behaviour. An automated risk flag was reviewed and overturned.

What our analysis found

影刀RPA, used by 600,000 people, showed no malicious code in Extension Auditor's review. Its permissions mean it can read and change data on all websites and can inject scripts into pages. It comes from a publisher with 5 extensions and was last updated in November 2025.

The extension is a legitimate Chrome automation plugin for the 影刀RPA desktop application. The broad permissions (debugger, nativeMessaging, <all_urls>) are essential for an RPA tool to interact with web pages, communicate with a local native application, and manage browser automation. The publisher has a valid privacy policy at, a good email reputation, and no other malicious extensions. The provided source code (manifest, content script, background page) shows no malicious logic; the actual automation code is dynamically injected via the debugger API, which is standard for such utilities. The ML risk score of 0.00 and the clean permhash cluster (0% malicious peers) contradict the risk engine’s permissions-only alarm.

影刀RPA

影刀RPA Chrome extension security report

ID: hofgfmmdolnmimplihglefekekfcfijf

Supported Languages

🇨🇳Chinese (Simplified)

Extension Info & Metadata

Status
Active
Version
3.1.0.0
Size
0.07 MB
Rating
3.5/5
Reviews
11
Users
600,000
Type
Extension
Updated
Nov 10, 2025
Category
Developer tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
5extensions
2 no longer listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Author
sanco1987
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
5
Active
3
Obsolete
2
Listed
4
Unlisted
1
Users
606,561

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

Screenshots & videos

Screenshot 1
Screenshot 2
Screenshot 3

Install growth

Item
Type
Severity
Description
debugger
Permission
Critical
This permission grants the extension ability to debug and control other extensions and browser tabs. Rated Critical because it can access and modify other extensions' internal state, inject code, and access sensitive data from any tab.
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
clipboardRead
Permission
High
This permission allows reading clipboard content. Rated High because it can steal copied passwords, sensitive data, and monitor all content copied to clipboard.
clipboardWrite
Permission
High
This permission allows modification of clipboard content. Rated High because it can inject malicious content into the clipboard, modify copied passwords, and manipulate copied data.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 10% increase: About:blank access enables potential sandbox escape vectors
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
management
Permission
Medium
This permission manages other installed extensions. Rated Medium because it can enable/disable other extensions and modify their settings, with changes being visible to users.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.

Each row lists a threat category the scanner evaluates. A checkmark means the review ran and found no matching issues in that category for this version.

  • Data Exfiltration

    Code review completed; no malicious patterns detected for this category.

  • Unauthorized Data Collection

    Code review completed; no malicious patterns detected for this category.

  • Network Interception

    Code review completed; no malicious patterns detected for this category.

  • Code Injection

    Code review completed; no malicious patterns detected for this category.

  • Credential Theft

    Code review completed; no malicious patterns detected for this category.

  • Obfuscation

    Code review completed; no malicious patterns detected for this category.

  • Tracking

    Code review completed; no malicious patterns detected for this category.

  • Privilege Escalation

    Code review completed; no malicious patterns detected for this category.

  • Phishing

    Code review completed; no malicious patterns detected for this category.

  • Remote Code Loading

    Code review completed; no malicious patterns detected for this category.

  • Other

    Code review completed; no malicious patterns detected for this category.

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

About this extension

影刀Chrome自动化插件

Read the publisher’s full description

使用影刀RPA实现Chrome自动化,仅适用于影刀RPA用户,用于提供影刀与Chrome浏览器之间的通信,为影刀提供自动化操作支持。当使用影刀需要拾取Chrome内的html元素时,需要安装此扩展做为运行依赖。

User reviews

Extension files

Browse and explore files within this extension package

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

URLs
3
IPv4
1

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
3.1.0.0
Latest
0.07 MBNo malware found0
663beb2d2bc9c4d853b7934752242da084da88c1eb99fd8ae60026f7ff3ffcc3
Showing 1 to 1 of 10 rows
Rows per page:

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

More from sanco1987

Popular in Developer Tools