GameBuddy - Mini Games Anytime
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.1.0
- Artifact
- SHA256 C98…EA0
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall crypto operations Cryptographic operations detected | 1 | _metadata/verified_contents.json | Risky Plugins Authors FP 30% |
| HIGH | postinstall system command System command execution detected | 38 | games/css/apple-snake.cssgames/css/drag-maze-door.cssgames/css/barcode-maze.css +35 more | Risky Plugins Authors FP 10% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 20 | games/js/letter-swap.jsgames/js/drag-maze-door.jsgames/js/puppy-snake.js +17 more | FP 5% |
| HIGH | postinstall network communication Network communication detected | 8 | sound/1.mp3games/js/blocker-maze.jsjs/storage-proxy.js +5 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 21 | games/js/word-search.jsgames/js/mine-finder.jsgames/js/letter-swap.js +18 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 1 | js/content.js | Risky Plugins Authors FP 20% |
| HIGH | LocalStorageShouldNotBeUsed Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory. | 15 | games/js/2048-game.jsgames/js/barcode-maze.jsgames/js/color-snake.js +12 more | FP 5% |
| HIGH | postinstall file download File download activity detected | 7 | games/js/barcode-maze.jsjs/content.jsgames/js/drag-maze.js +4 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 4 | js/content.jsgames/js/color-snake.jsgames/js/classic-snake.js +1 more | Risky Plugins Authors FP 20% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(115 hits)Requested Permissions
1 permissionAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality absent.
The extension 'GameBuddy - Mini Games Anytime' cannot be properly assessed due to the complete absence of security findings in the evidence bundle. The findings_by_category object is empty {}, containing no IoC findings, no code-smell findings, no obfuscation indicators, and no malware signatures across any category.
The extension metadata shows a developer email ([email protected]), 124 users, and version 0.1.0, indicating a recently published small-scale extension. The description states it provides mini-games functionality through an animated buddy interface, which is a legitimate use case for browser extensions.
Without any findings to evaluate, I cannot identify specific threats such as credential theft, browser hijacking, data exfiltration, or malware delivery. The absence of findings could indicate three scenarios: (1) the extension is genuinely clean with no detectable security issues, (2) the analysis pipeline failed to scan the extension files, or (3) the extension is too minimal to trigger any detection rules.
The strongest counterargument to this verdict would be that zero findings should indicate a clean, safe extension. However, this reasoning is flawed because the CVEQ platform has documented scoring biases where finding volume drives risk scores disproportionately. More critically, an empty findings object provides no evidence of what the code actually does. I cannot verify whether files were scanned, whether the analysis completed, or whether the extension contains any security-relevant code. A clean extension would still generate some baseline findings (e.g., legitimate CDN domains, basic code patterns).
Without knowing if files were scanned or if the analysis completed successfully, I cannot make a security determination. The extension requires reanalysis to generate proper findings before any verdict can be reached. Until then, the security posture remains unknown.
Key Reasons
- findings_by_category is empty with zero findings across all categories
- No security signals available to evaluate extension behavior
- Cannot verify if analysis pipeline executed successfully
- Extension metadata present but insufficient for security assessment
False Positive Considerations
- No findings to evaluate for false positive patterns
Reviewed 2026-04-24; recommended action: reanalyze; model confidence 60%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace