Quiz Boost AI - Smart Test Assistant, Exam Helper & Homework Quiz Solver
The AI review rates the findings as likely false positive, but the risk score (56/100) still counts them.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.0.3
- Artifact
- SHA256 5ED…97C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 2 | assets/client-BrKYtKys.js_metadata/verified_contents.json | - |
| LOW | postinstall system command | 8 | assets/FloatButton.tsx-loader-8zI3xk8h.jsassets/index.html-CXa_mNQz.jsassets/inject.ts-loader-ldqJW7Ge.js +5 more | - |
| LOW | postinstall file manipulation | 6 | assets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.jsassets/FloatButton.tsx-CMq4At7t.js +3 more | - |
| LOW | postinstall environment access | 5 | assets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.jsassets/FloatButton.tsx-CMq4At7t.js +2 more | - |
| LOW | postinstall obfuscation | 3 | assets/index.html-CXa_mNQz.jsassets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.js | - |
| LOW | postinstall network communication | 7 | assets/index.html-CXa_mNQz.jsassets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.js +4 more | - |
| LOW | postinstall file download | 4 | assets/index.html-CXa_mNQz.jsassets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.js +1 more | - |
| LOW | NoUseWeakRandom | 2 | assets/index.html-CXa_mNQz.jsassets/client-BrKYtKys.js | - |
| LOW | postinstall persistence mechanism | 1 | assets/background.ts-BRGTSiMA.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
11 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(38 hits)Requested Permissions
4 permissionsAccess and modify data on every website you visit
AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-28. The review verdict is likely false positive with 85% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality weak.
This extension's security findings are entirely consistent with known false-positive patterns in the CVEQ detection system. The 115 IoC findings shown in the evidence bundle are not real network indicators—they are JavaScript property access chains misidentified as domains by the XIOC extractor. For example, findings like XIOC-DOMAIN-e.target, XIOC-DOMAIN-r.data, XIOC-DOMAIN-h.target, and XIOC-DOMAIN-se.prototype.tostring.call are not domains at all; they are standard JavaScript syntax where e.target and r.data represent object property access. The threat model explicitly documents this as "Property access chains misread as domains: b.call, h.next, g.id" and states these are benign.
The network findings are equally benign. The single network finding shown, NET-FETCH-assets/index.html-CXa_mNQz.js-1, indicates a fetch call to a local asset file within the extension's own directory structure (assets/index.html-CXa_mNQz.js). This is standard behavior for any extension loading its own resources and poses no security risk.
Critically, there are zero malware signatures, zero obfuscation findings, and zero critical or high severity findings. The 38 code-smell findings are classified as low severity, which the threat model explicitly states are "NOISE" and should "NEVER drive a verdict." The extension's functionality—a quiz/test assistant—is a legitimate category with no inherent security concerns.
The strongest counterargument to this verdict would be the developer's use of a generic email address ([email protected]) rather than a verified publisher name, combined with the high total finding count of 156. However, finding COUNT is explicitly stated in the threat model as "NOT evidence"—only finding NATURE matters. The developer identity concern is valid but insufficient to override the complete absence of actual malicious indicators. A Gmail address as developer attribution is common for individual developers and does not constitute impersonation or deception. The extension does not mimic any known extension name, does not use suspicious domains, and shows no evidence of credential theft, browser hijacking, or malware delivery.
The verdict of likely_false_positive is appropriate because every finding can be explained by documented false-positive patterns, and there is no evidence of intentional harm or risky behavior.
Key Reasons
- All 115 IoC findings are property access chains misread as domains (e.target, r.data, h.target, etc.)
- Zero malware signatures detected
- Zero obfuscation findings
- Network findings reference only local asset files
- Code-smell findings are low severity noise per threat model
False Positive Considerations
- XIOC property access chain misidentification
- Code-smell low severity findings
- High finding count from bundled dependencies
Chrome version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Edge Translate - Text Selection Translation
[email protected]
QuizShot – AI Math Solver, Homework Helper & Study Assistant Tutor
[email protected]
Canvas Zero - Canvas quizzes Assistant
[email protected]
Pinora – Pinterest Board Pins Images Downloader
[email protected]
No Distract - Hide YouTube, Facebook, Reddit, Twitter Feeds
[email protected]
SideGPT - Free Access ChatGPT sidebar
[email protected]