Is "VaultSage for NAVER Works Mail" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.7

네이버웍스 메일에서 볼트세이지(VaultSage)와 내 문서를 활용해 답장 초안을 빠르고 정확하게 작성하세요. ✅ 주요 기능 🚀 원클릭 답장 생성: 원문과 같은 언어로 답장 본문을 생성 (HTML 형식 지원) 📚 VaultSage 문서 컨텍스트 활용: 정책/가이드/FAQ/템플릿/제품 문서 등을 선택해 답장 품질 향상 🧠 “규칙 & 문서” 자동 매칭: 발신자 기준으로 문서를 자동 선택: 1) 이메일 주소 정확히 일치 2) 도메인 일치 (예: @company.com) 3) 기본 규칙(대체) 🎨 톤/스타일 재작성: 초안을 원하는 스타일로 변경: 🧾 격식 / 💼 전문적 / 😊 캐주얼 / 🤝 친근 ⚙️ 쉬운 설정: 볼트세이지 연결, 규칙/문서 관리, 언어(영/한) 및 테마(시스템/라이트/다크) 지원 📌 참고 볼트세이지(VaultSage) 계정이 필요합니다 메일 내용은 AI 답장 생성시에만 사용되며 저장되지 않습니다. ---- Draft faster, more accurate replies in NAVER Works Mail using VaultSage and your own documents. ✅ Key Features 🚀 One-click reply drafting: Generate a reply body in the same language as the original email (HTML supported) 📚 VaultSage document context: Improve reply quality by selecting policies, guides, FAQs, templates, product docs, and more 🧠 “Rules & Documents” auto-matching: Automatically picks documents based on the sender: 1) Exact email match 2) Domain match (e.g., @company.com) 3) Default rule (fallback) 🎨 Tone/Style rewrite: Restyle your draft instantly: 🧾 Formal / 💼 Professional / 😊 Casual / 🤝 Friendly ⚙️ Easy setup: Connect VaultSage, manage rules/documents, and choose Language (EN/KR) + Theme (System/Light/Dark) 📌 Note A VaultSage account is required: https://vaultsage.ai ---- NAVER Works Mailで、VaultSageと自分のドキュメントを活用して返信文の下書きを素早く・正確に作成できます。 ✅ 主な機能 🚀 ワンクリック返信生成: 元メールと同じ言語で返信本文を生成(HTML形式対応) 📚 VaultSageドキュメントをコンテキストに活用: ポリシー/ガイド/FAQ/テンプレート/製品資料などを選択して返信品質を向上 🧠 「ルール&ドキュメント」自動マッチング: 送信者に応じて参照ドキュメントを自動選択 1) メールアドレスの完全一致 2) ドメイン一致(例:@company.com) 3) デフォルトルール(フォールバック) 🎨 トーン/スタイル再作成: 下書きを好みのスタイルに変更: 🧾 フォーマル / 💼 ビジネス / 😊 カジュアル / 🤝 フレンドリー ⚙️ かんたん設定: VaultSage接続、ルール/ドキュメント管理、言語(英/韓)とテーマ(システム/ライト/ダーク)に対応 📌 注意 VaultSageアカウントが必要です: https://vaultsage.ai

Risk Assessment

Analyzed
62.45
out of 100
MEDIUM

112 security findings detected across all analyzers

Chrome extension requesting 6 permissions

Severity Breakdown

0
Critical
0
High
71
Medium
41
Low
0
Info

Finding Categories

2
Network
68
IoC Indicators

YARA Rules Matched

11 rules(41 hits)
postinstall network communication postinstall environment access postinstall obfuscation postinstall file manipulation postinstall system command postinstall crypto operations AlertStatementsShouldNotBeUsed SQLInjection postinstall file download NoUseWeakRandom postinstall persistence mechanism

Requested Permissions

6 permissions
activeTab
Medium
scripting
Low
storage
Low
*://mail.worksmobile.com/*
Low
https://vaultsage.ai/*
Low
https://api.vaultsage.ai/*
Low

About This Extension

네이버웍스 메일에서 볼트세이지(VaultSage)와 내 문서를 활용해 답장 초안을 빠르고 정확하게 작성하세요. ✅ 주요 기능 🚀 원클릭 답장 생성: 원문과 같은 언어로 답장 본문을 생성 (HTML 형식 지원) 📚 VaultSage 문서 컨텍스트 활용: 정책/가이드/FAQ/템플릿/제품 문서 등을 선택해 답장 품질 향상 🧠 “규칙 & 문서” 자동 매칭: 발신자 기준으로 문서를 자동 선택: 1) 이메일 주소 정확히 일치 2) 도메인 일치 (예: @company.com) 3) 기본 규칙(대체) 🎨 톤/스타일 재작성: 초안을 원하는 스타일로 변경: 🧾 격식 / 💼 전문적 / 😊 캐주얼 / 🤝 친근 ⚙️ 쉬운 설정: 볼트세이지 연결, 규칙/문서 관리, 언어(영/한) 및 테마(시스템/라이트/다크) 지원 📌 참고 볼트세이지(VaultSage) 계정이 필요합니다 메일 내용은 AI 답장 생성시에만 사용되며 저장되지 않습니다. ---- Draft faster, more accurate replies in NAVER Works Mail using VaultSage and your own documents. ✅ Key Features 🚀 One-click reply drafting: Generate a reply body in the same language as the original email (HTML supported) 📚 VaultSage document context: Improve reply quality by selecting policies, guides, FAQs, templates, product docs, and more 🧠 “Rules & Documents” auto-matching: Automatically picks documents based on the sender: 1) Exact email match 2) Domain match (e.g., @company.com) 3) Default rule (fallback) 🎨 Tone/Style rewrite: Restyle your draft instantly: 🧾 Formal / 💼 Professional / 😊 Casual / 🤝 Friendly ⚙️ Easy setup: Connect VaultSage, manage rules/documents, and choose Language (EN/KR) + Theme (System/Light/Dark) 📌 Note A VaultSage account is required: https://vaultsage.ai ---- NAVER Works Mailで、VaultSageと自分のドキュメントを活用して返信文の下書きを素早く・正確に作成できます。 ✅ 主な機能 🚀 ワンクリック返信生成: 元メールと同じ言語で返信本文を生成(HTML形式対応) 📚 VaultSageドキュメントをコンテキストに活用: ポリシー/ガイド/FAQ/テンプレート/製品資料などを選択して返信品質を向上 🧠 「ルール&ドキュメント」自動マッチング: 送信者に応じて参照ドキュメントを自動選択 1) メールアドレスの完全一致 2) ドメイン一致(例:@company.com) 3) デフォルトルール(フォールバック) 🎨 トーン/スタイル再作成: 下書きを好みのスタイルに変更: 🧾 フォーマル / 💼 ビジネス / 😊 カジュアル / 🤝 フレンドリー ⚙️ かんたん設定: VaultSage接続、ルール/ドキュメント管理、言語(英/韓)とテーマ(システム/ライト/ダーク)に対応 📌 注意 VaultSageアカウントが必要です: https://vaultsage.ai

Detailed Findings

43 total

YARA Rule Matches

11 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
10
IP Addresses
3
Domains
54
Strings
68

All Indicators · 68

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

Domain
detected Domain: doc.name

XIOC detected Domain: doc.name

extracted_from_files

URL
detected URL: https://vaultsage.ai/*

XIOC detected URL: https://vaultsage.ai/*

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg'

XIOC detected URL: http://www.w3.org/2000/svg'

extracted_from_files

URL
detected URL: https://vaultsage.ai/login?source=naver-email-ext

XIOC detected URL: https://vaultsage.ai/login?source=naver-email-ext

extracted_from_files

URL
detected URL: https://api.vaultsage.ai/api/v1';

XIOC detected URL: https://api.vaultsage.ai/api/v1';

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

URL
detected URL: https://api.vaultsage.ai/api/v1

XIOC detected URL: https://api.vaultsage.ai/api/v1

extracted_from_files

URL
detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

XIOC detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

extracted_from_files

URL
detected URL: http://ns.adobe.com/exif/1.0/

XIOC detected URL: http://ns.adobe.com/exif/1.0/

extracted_from_files

URL
detected URL: http://ns.adobe.com/tiff/1.0/

XIOC detected URL: http://ns.adobe.com/tiff/1.0/

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

Domain
detected Domain: rule.id

XIOC detected Domain: rule.id

extracted_from_files

Domain
detected Domain: dir.id

XIOC detected Domain: dir.id

extracted_from_files

Domain
detected Domain: dir.name

XIOC detected Domain: dir.name

extracted_from_files

Domain
detected Domain: rule.documents.map

XIOC detected Domain: rule.documents.map

extracted_from_files

Domain
detected Domain: defaultrule.documents.map

XIOC detected Domain: defaultrule.documents.map

extracted_from_files

Domain
detected Domain: mail.worksmobile.com

XIOC detected Domain: mail.worksmobile.com

extracted_from_files

URL
detected URL: https://api.vaultsage.ai/*

XIOC detected URL: https://api.vaultsage.ai/*

extracted_from_files

Domain
detected Domain: lang-button.is

XIOC detected Domain: lang-button.is

extracted_from_files

Domain
detected Domain: payload.email

XIOC detected Domain: payload.email

extracted_from_files

Domain
detected Domain: response.data

XIOC detected Domain: response.data

extracted_from_files

Domain
detected Domain: data.email

XIOC detected Domain: data.email

extracted_from_files

Domain
detected Domain: company.com

XIOC detected Domain: company.com

extracted_from_files

Domain
detected Domain: rule.name

XIOC detected Domain: rule.name

extracted_from_files

Domain
detected Domain: rule.matchers.map

XIOC detected Domain: rule.matchers.map

extracted_from_files

Domain
detected Domain: example.com

XIOC detected Domain: example.com

extracted_from_files

Domain
detected Domain: window.location.search

XIOC detected Domain: window.location.search

extracted_from_files

Domain
detected Domain: documents.map

XIOC detected Domain: documents.map

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Domain
detected Domain: vaultsage.ai

XIOC detected Domain: vaultsage.ai

extracted_from_files

Domain
detected Domain: cb.dataset.id

XIOC detected Domain: cb.dataset.id

extracted_from_files

Domain
detected Domain: cb.dataset.name

XIOC detected Domain: cb.dataset.name

extracted_from_files

Domain
detected Domain: tab.id

XIOC detected Domain: tab.id

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: payload.data

XIOC detected Domain: payload.data

extracted_from_files

Domain
detected Domain: request.data

XIOC detected Domain: request.data

extracted_from_files

Domain
detected Domain: style-button.is

XIOC detected Domain: style-button.is

extracted_from_files

Domain
detected Domain: entry.id

XIOC detected Domain: entry.id

extracted_from_files

Domain
detected Domain: r.id

XIOC detected Domain: r.id

extracted_from_files

Domain
detected Domain: r.name

XIOC detected Domain: r.name

extracted_from_files

Domain
detected Domain: checkbox.dataset.id

XIOC detected Domain: checkbox.dataset.id

extracted_from_files

Domain
detected Domain: file.id

XIOC detected Domain: file.id

extracted_from_files

Domain
detected Domain: checkbox.dataset.name

XIOC detected Domain: checkbox.dataset.name

extracted_from_files

Domain
detected Domain: file.name

XIOC detected Domain: file.name

extracted_from_files

Domain
detected Domain: f.name

XIOC detected Domain: f.name

extracted_from_files

Domain
detected Domain: a.name

XIOC detected Domain: a.name

extracted_from_files

Domain
detected Domain: b.name

XIOC detected Domain: b.name

extracted_from_files

Domain
detected Domain: doc.id

XIOC detected Domain: doc.id

extracted_from_files

Domain
detected Domain: prompts.email

XIOC detected Domain: prompts.email

extracted_from_files

Domain
detected Domain: e.name

XIOC detected Domain: e.name

extracted_from_files

Domain
detected Domain: entry.name

XIOC detected Domain: entry.name

extracted_from_files

Domain
detected Domain: style.id

XIOC detected Domain: style.id

extracted_from_files

Domain
detected Domain: nodefilter.show

XIOC detected Domain: nodefilter.show

extracted_from_files

Domain
detected Domain: crumb.name

XIOC detected Domain: crumb.name

extracted_from_files

Domain
detected Domain: crumb.id

XIOC detected Domain: crumb.id

extracted_from_files

Domain
detected Domain: d.id

XIOC detected Domain: d.id

extracted_from_files

Domain
detected Domain: d.name

XIOC detected Domain: d.name

extracted_from_files

Domain
detected Domain: f.id

XIOC detected Domain: f.id

extracted_from_files

IP
detected IP: ::af

XIOC detected IP: ::af

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: api.vaultsage.ai

XIOC detected Domain: api.vaultsage.ai

extracted_from_files

Domain
detected Domain: container.id

XIOC detected Domain: container.id

extracted_from_files

Domain
detected Domain: stylepanel.id

XIOC detected Domain: stylepanel.id

extracted_from_files

Domain
detected Domain: button.id

XIOC detected Domain: button.id

extracted_from_files

Domain
detected Domain: options.style

XIOC detected Domain: options.style

extracted_from_files

Security Analysis Summary

Security Analysis Overview

VaultSage for NAVER Works Mail is a Chrome Web Store extension published by [email protected]. Version 1.7 has been analyzed by the Risky Plugins security platform, receiving a risk score of 62.45/100 (MEDIUM risk) based on 112 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • Medium: 71 finding(s)
  • Low: 41 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

VaultSage for NAVER Works Mail is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 10 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions