uberAgent
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v4.1.0
- Artifact
- SHA256 896…F5B
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
5 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 1 | service-worker.js | - |
| LOW | postinstall crypto operations | 1 | _metadata/verified_contents.json | - |
| LOW | postinstall file manipulation | 1 | service-worker.js | - |
| LOW | postinstall network communication | 2 | uberAgent-content.jsservice-worker.js | - |
| LOW | postinstall file download | 1 | uberAgent-content.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
11 evidence rows available.
Finding Categories
YARA Rules Matched
5 rules(6 hits)Requested Permissions
7 permissionsExchange messages with programs outside the browser
Access and modify data on every website you visit
Intercept, modify, and block all network requests
AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-23. The review verdict is benign but powerful with 92% confidence.
Recommended action: no action. Evidence context: threat category none; evidence quality strong.
This extension is uberAgent, an enterprise endpoint monitoring tool with over 1 million users. The analysis reveals two manifest permissions flagged as potentially sensitive: the tabs permission and nativemessaging permission, both declared in manifest.json. These permissions are legitimate requirements for the extension's stated purpose of collecting web app usage and performance data from Chrome.
The tabs permission allows the extension to access information about open browser tabs, which is necessary for tracking foreground tab activity and page load duration as described in the extension description. The nativemessaging permission enables communication with a native host application, which is standard for enterprise monitoring tools that need to transmit collected data to backend systems.
Critically, there are zero malware signatures, zero obfuscation findings, zero suspicious network indicators, and zero code-smell findings in this extension. The findings summary shows only the two manifest permission findings, both medium severity, with no critical or high severity issues. There are no suspicious domains in the IoC extractor output, no evidence of credential theft, no browser hijacking behavior, and no obfuscated payloads.
The developer attribution shows "[email protected]" which is generic but consistent with enterprise software distribution. The extension name "uberAgent" matches a known enterprise endpoint management solution, and the description explicitly states its purpose: collecting web app usage and performance data. There is no evidence of typosquatting or impersonation of a different product.
Addressing the strongest counterargument: A skeptic might argue that the tabs and nativemessaging permissions could be abused for credential theft or data exfiltration. However, these are the exact permissions required for legitimate web application monitoring. The extension has no malware signatures, no obfuscation, no suspicious network domains, and no code-smell findings that would indicate malicious intent. With 1 million users and a clear enterprise use case, the permissions align with the stated functionality rather than indicating hidden malicious behavior. If this were malicious, we would expect to see obfuscation, suspicious domains, or malware signatures co-located with these permissions—none of which are present.
The evidence quality is strong because the findings are minimal, specific, and fully explainable by the extension's legitimate purpose. This is a benign enterprise tool with powerful capabilities that are appropriate for its function.
Key Reasons
- Zero malware signatures, zero obfuscation, zero suspicious IoCs
- Manifest permissions (tabs, nativemessaging) align with stated enterprise monitoring purpose
- 1 million users indicates widespread legitimate adoption
- Extension name matches known enterprise product (uberAgent)
- No deceptive naming, impersonation, or suspicious domains detected
False Positive Considerations
- MANIFEST-SENSITIVE-PERM-TABS is legitimate for web app monitoring
- MANIFEST-SENSITIVE-PERM-NATIVEMESSAGING is legitimate for enterprise tools
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Citrix Workspace
[email protected]
Browser Redirection Extension
[email protected]
Citrix Web Extension - Beta
[email protected]
Browser Redirection Extension [Beta]
[email protected]
Citrix Web Extension
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]