Chrome Web Store Verified

Adobe Workfront review tool

by [email protected] · 10.0K users · 5.0 rating
95f4a24f-1462-58a3-8cd8-ca82664e0bee | v1.3.0
52/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (52/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v1.3.0
Artifact
SHA256 981…8AE
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

14 detail rows

YARA Rule Matches

7 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 2
manifest.jsonbackground.js
-
LOWNoUseWeakRandom 1
content-scripts/content.js
-
LOWpostinstall persistence mechanism 3
constants.jscontent-scripts/content.jsbackground.js
-
LOWpostinstall crypto operations 1
_metadata/verified_contents.json
-
LOWpostinstall file manipulation 2
content-scripts/content.jsbackground.js
-
LOWpostinstall network communication 2
content-scripts/content.jsbackground.js
-
LOWpostinstall system command 1
background.js
-

Publisher Evidence

Low

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

79
Noisy-finding weight
x1.00
Publisher domain
adobe.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
25
Portfolio

12 evidence rows available.

Finding Categories

1
Network

YARA Rules Matched

7 rules(12 hits)
postinstall file download NoUseWeakRandom postinstall persistence mechanism postinstall crypto operations postinstall file manipulation postinstall network communication postinstall system command

Requested Permissions

7 permissions
*://*/*
Dangerous
<all_urls>

Access and modify data on every website you visit

Dangerous
tabs
Medium
scripting
Low
declarativeNetRequest
Low
declarativeNetRequestFeedback
Low
webNavigation
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The extension’s manifest and JavaScript files contain no malware signatures or obfuscated payloads, and there is no code that accesses cookies, modifies the new‑tab page, or hijacks search queries. The only notable findings are a series of domain IoCs such as r.id, sagacproof.com, samepage.graphcom.com, smiths-medical.com, workfront.abelsontaylor.com, proofhub.co.uk, o.id, n.id, proofing.mtacity.com, e.map, proofs.project.com, and review.mergeworld.com. All of these are listed under the generic “extracted_from_files” source, indicating they were pulled from static strings rather than active network calls. None of the domains are known command‑and‑control or credential‑stealing hosts, and several (e.g., workfront.abelsontaylor.com) appear to be sub‑domains of services that Adobe Workfront legitimately integrates with. The developer field shows a verified Adobe support address (chrome‑[email protected]), matching the extension name “Adobe Workfront review tool”. There are no findings indicating permission abuse, credential theft, or browser hijacking, and the single network finding does not target sensitive sites. Consequently, the pattern matches the known false‑positive behavior of the XIOC extractor, which often flags innocent third‑party domains embedded in SDKs or documentation strings.

Counterargument: A skeptic might argue that the presence of many unfamiliar domains could indicate hidden data exfiltration. However, without any code that opens connections to those domains, without use of fetch/XMLHttpRequest targeting them, and without any obfuscation concealing such calls, the domains remain passive strings. The extension’s permissions are standard for a review tool and do not include host permissions for the listed domains, further weakening the exfiltration hypothesis. Therefore, the evidence still points to benign behavior rather than malicious intent.

Key Reasons

  • No malware signatures or obfuscation detected
  • All findings are static domain strings extracted by XIOC
  • Official Adobe developer email matches the extension’s branding
  • No permission or code behavior indicating data exfiltration
  • Only generic third‑party domains, none known as C2 or phishing hosts

False Positive Considerations

  • IoC extractor generic domain matches
  • Bundled third‑party SDK strings
  • Lack of active network calls
  • Verified Adobe publisher

Reviewed 2026-05-25; recommended action: no action; model confidence 86%.

About This Extension

Transform your review and approval process for interactive content, including websites, interactive PDFs, and any browser-based material. Add comments and annotate interactive proofs—all without having to download a desktop application. Simply install the plugin, and get to work.

Frequently Asked Questions