Is Edit with Sublime Text™ safe?
Edit with Sublime Text exposes a web-accessible page any site can embed to write arbitrary content to disk and open it in Sublime Text.
The extension's native/index.html is accessible to all web origins and reads arbitrary content and a file extension from URL parameters. It passes these directly to the com.add0n.native_client native messaging host, which writes the content to a temp file and executes the user-configured shell command to open that file in Sublime Text. No validation checks that the embedding page is legitimate, so any web page can trigger this flow.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itrynu.smith - 6 other listings from the same operator, 3 of them carrying a finding
rynu.smith - 6 other listings from the same operator, 3 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
6 other listings published from this account, 611k+ users between them. 3 of them carry a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 0.2.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Store data in your browser
storage
Act on the current tab, but only after you click the extension
activeTab
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Show you desktop notifications
notifications
Add items to the right-click menu
contextMenus
Run its own code inside the pages you visit
scripting