Chrome Web Store Verified

uberAgent

by [email protected] · 1.0M users · 3.0 rating
4293aba1-2505-514b-ae57-387a7770e0a9 | v4.1.0
58/ 100
MEDIUM risk
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v4.1.0
Artifact
SHA256 896…F5B
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

8 detail rows

YARA Rule Matches

5 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 1
service-worker.js
-
LOWpostinstall crypto operations 1
_metadata/verified_contents.json
-
LOWpostinstall file manipulation 1
service-worker.js
-
LOWpostinstall network communication 2
uberAgent-content.jsservice-worker.js
-
LOWpostinstall file download 1
uberAgent-content.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

28 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

62
Noisy-finding weight
x1.00
Publisher domain
cloud.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

11 evidence rows available.

Finding Categories

28
IoC Indicators

YARA Rules Matched

5 rules(6 hits)
postinstall persistence mechanism postinstall crypto operations postinstall file manipulation postinstall network communication postinstall file download

Requested Permissions

7 permissions
nativeMessaging

Exchange messages with programs outside the browser

Dangerous
<all_urls>

Access and modify data on every website you visit

Dangerous
webRequest

Intercept, modify, and block all network requests

High
tabs
Medium
alarms
Low
webNavigation
Low
storage
Low

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-23. The review verdict is benign but powerful with 92% confidence.

Recommended action: no action. Evidence context: threat category none; evidence quality strong.

This extension is uberAgent, an enterprise endpoint monitoring tool with over 1 million users. The analysis reveals two manifest permissions flagged as potentially sensitive: the tabs permission and nativemessaging permission, both declared in manifest.json. These permissions are legitimate requirements for the extension's stated purpose of collecting web app usage and performance data from Chrome.

The tabs permission allows the extension to access information about open browser tabs, which is necessary for tracking foreground tab activity and page load duration as described in the extension description. The nativemessaging permission enables communication with a native host application, which is standard for enterprise monitoring tools that need to transmit collected data to backend systems.

Critically, there are zero malware signatures, zero obfuscation findings, zero suspicious network indicators, and zero code-smell findings in this extension. The findings summary shows only the two manifest permission findings, both medium severity, with no critical or high severity issues. There are no suspicious domains in the IoC extractor output, no evidence of credential theft, no browser hijacking behavior, and no obfuscated payloads.

The developer attribution shows "[email protected]" which is generic but consistent with enterprise software distribution. The extension name "uberAgent" matches a known enterprise endpoint management solution, and the description explicitly states its purpose: collecting web app usage and performance data. There is no evidence of typosquatting or impersonation of a different product.

Addressing the strongest counterargument: A skeptic might argue that the tabs and nativemessaging permissions could be abused for credential theft or data exfiltration. However, these are the exact permissions required for legitimate web application monitoring. The extension has no malware signatures, no obfuscation, no suspicious network domains, and no code-smell findings that would indicate malicious intent. With 1 million users and a clear enterprise use case, the permissions align with the stated functionality rather than indicating hidden malicious behavior. If this were malicious, we would expect to see obfuscation, suspicious domains, or malware signatures co-located with these permissions—none of which are present.

The evidence quality is strong because the findings are minimal, specific, and fully explainable by the extension's legitimate purpose. This is a benign enterprise tool with powerful capabilities that are appropriate for its function.

Key Reasons

  • Zero malware signatures, zero obfuscation, zero suspicious IoCs
  • Manifest permissions (tabs, nativemessaging) align with stated enterprise monitoring purpose
  • 1 million users indicates widespread legitimate adoption
  • Extension name matches known enterprise product (uberAgent)
  • No deceptive naming, impersonation, or suspicious domains detected

False Positive Considerations

  • MANIFEST-SENSITIVE-PERM-TABS is legitimate for web app monitoring
  • MANIFEST-SENSITIVE-PERM-NATIVEMESSAGING is legitimate for enterprise tools

About This Extension

This is the new uberAgent extension for Manifest V3. It requires uberAgent 7.2 or newer on the endpoint. IMPORTANT: This extension requires the uberAgent endpoint agent for Windows or macOS. The browser extension does not work without the agent. uberAgent is the perfect solution for Windows and macOS end-user computing analytics, focused on user experience and application performance monitoring. It measures logon duration, GPU usage, network latency, browser performance, and application unresponsiveness, to name just a few of its many high-quality metrics not easily found elsewhere. And it does all the above from an agent that is so efficient that it has one of the smallest footprints in the industry. uberAgent is optimized for physical and virtual apps and desktops, including Citrix products. uberAgent easily answers questions like the following: - How can we speed up user logons? - How much time do our employees lose waiting for applications? - Why is the Windows boot process taking so long? - Are Outlook problems really caused by the Exchange backend? - How many licenses do we need for application X? - Which apps do our user spend most of their time with?

Frequently Asked Questions