CRX aminer
Extension icon

GNOME Shell integration

Version 12.1 View in Chrome Web Store

Last scanned: about 15 hours ago

Extension Details

Developer: http://extensions.gnome.org/
Rating: 3.8 ★ (328 ratings)
Users: 700,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension is developed by the official GNOME project (extensions.gnome.org), which is a well-established open-source desktop environment with strong community backing. With 700,000 users and a 3.8-star rating, it demonstrates reasonable adoption and user satisfaction. The extension serves a legitimate technical purpose - integrating Chrome with GNOME Shell extensions management.

Concerns:

The nativeMessaging permission allows direct communication with native applications on your system, which could potentially be exploited if the extension or GNOME infrastructure were compromised. While the host permissions are appropriately limited to official GNOME domains, the combination of native messaging with storage and notifications creates multiple attack vectors. The extension essentially acts as a bridge between your browser and desktop environment, which inherently carries elevated risk.

Recommendations:

This extension is generally safe for users of GNOME desktop environments who need to manage shell extensions through their browser. The risk is acceptable given its official source and specific functionality. However, users should ensure they're running updated versions of both the extension and GNOME Shell. If you don't actively use GNOME Shell extensions or have switched to a different desktop environment, consider removing this extension to reduce your attack surface. Monitor for any unusual system behavior or unexpected notifications after installation.

Findings

MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.