Is "KCUBE ON Connector for Google" on Chrome Web Store Safe to Install?
KCUBE ON Connector for Google – 스마트한 업무 연결 도구 Google Workspace에서 KCUBE ON의 다양한 업무 지원 서비스를 원활하게 연결하여 보다 효율적인 협업을 가능하게 하는 스마트한 업무 도구입니다. 이 확장 프로그램은 Gmail, Calendar, Drive에서 KCUBE ON의 조직도, DSM(Drive Sharing Management) 등 다양한 Add-on 앱을 직접 실행할 수 있도록 도와줍니다. 단순한 아이콘 추가 기능이 아니라, Google Workspace 환경에서 필요한 업무 지원 서비스를 빠르게 실행하고 활용할 수 있는 연결 플랫폼 역할을 합니다. 핵심 기능 - 조직도 실행 버튼: Gmail 및 Calendar에서 조직도 앱을 바로 실행하여 수신자 또는 초대자를 직관적으로 선택 - 직관적인 수신자 선택: 메일 작성 중 조직도에서 정보를 확인하고 적절한 이메일 수신 대상자를 쉽게 지정 - 편리한 일정 참석자 선택: Google Calendar에서 조직도 기반으로 관련 참석자를 검색하고 일정에 추가 - Drive 문서 공유 관리 : 데이터 보안 정책에 따라 문서 외부 공유 승인 프로세스를 DSM을 통해 즉시 실행 KCUBE ON Connector for Google을 통해 Google Workspace에서 필요한 다양한 업무 도구를 빠르게 실행하고, 조직 내 협업과 데이터 관리의 효율성을 높이세요!
Risk Assessment
Analyzed8 security findings detected across all analyzers
Chrome extension requesting 8 permissions
Severity Breakdown
Finding Categories
Requested Permissions
8 permissionsAccess your identity and sign-in tokens
About This Extension
Detailed Findings
8 totalAI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-27. The review verdict is likely false positive with 85% confidence.
Recommended action: suppress false positive.
Risk context: CRITICAL risk, score 87/100.
Evidence context: threat category none; evidence quality moderate.
KCUBE ON Connector for Google (version 1.3.4) is a benign extension with findings driven entirely by known false-positive patterns.
IoC Analysis: All 188 IoC findings are XIOC extraction errors. The finding titles reveal JavaScript property access chains misidentified as domains: XIOC-DOMAIN-minimizebutton.click, XIOC-DOMAIN-exports.gmail, XIOC-DOMAIN-result.name, XIOC-DOMAIN-div.vi, XIOC-DOMAIN-a.do, XIOC-DOMAIN-api.new.get.email, XIOC-DOMAIN-el.data, XIOC-DOMAIN-cancelbutton.click, XIOC-DOMAIN-obj.name, XIOC-DOMAIN-this.id, and XIOC-DOMAIN-obj.email. These are standard JavaScript patterns (object.property, element.click, this.id) that the XIOC extractor incorrectly flags as network domains. The only legitimate URL found is https://docs.gitlab.com/ee/user/project/repository/web_editor.html, which references GitLab documentation and poses no threat.
Malware Signatures: Zero malware-signature findings and zero malware findings. This is a critical indicator of benign code. Malicious extensions consistently trigger at least one malware signature when combined with suspicious behavior.
Obfuscation: Zero obfuscation findings. Malicious extensions use obfuscation to hide payloads; this extension has none.
Developer Attribution: The developer email [email protected] provides legitimate attribution to a Korean company domain. The extension name "KCUBE ON Connector for Google" does not impersonate any known extension brand.
Code-Smell Findings: The 55 code-smell findings are all low severity and represent expected noise from YARA rules that match basic JavaScript patterns. These findings do not indicate malicious behavior.
Counterargument Addressed: A skeptic would argue that 251 total findings with 188 IoCs represents significant risk. This reasoning is incorrect because finding COUNT is meaningless when finding NATURE is noise. Every single IoC is a documented XIOC false positive pattern (property access chains). Zero malware signatures, zero obfuscation, and no actual suspicious domains confirm the extension is benign. The high finding count results from the XIOC extractor's known tendency to over-match on JavaScript code, not from actual malicious indicators.
Conclusion: This extension exhibits no evidence of malicious behavior. The findings are entirely attributable to XIOC false positives and benign code-smell noise. No security action is required beyond suppressing these known false-positive patterns.
Key Reasons
- All 188 IoC findings are XIOC false positives from JavaScript property access chains
- Zero malware signatures detected
- Zero obfuscation findings
- Developer attribution exists via company email domain
- No actual suspicious domains in findings
False Positive Considerations
- XIOC property access chains misidentified as domains
- Low-severity code-smell YARA rules
- No malware signatures present
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng
[email protected]
SVG to AVIF Converter [ShiftShift]
[email protected]
ChromeCompare
[email protected]
CAI Tools
[email protected]
MAGgie - An AI Assistant
[email protected]
EC Seller Tools
[email protected]