Is ESCB-PKI user certificate enrollment safe?

Low risk

ESCB-PKI bridges certificate enrollment pages on ESCB and BDE sites to a native messaging host that loads PKCS11 DLLs supplied by the page.

The extension injects a JavaScript API (IndraToken.js) into specific paths on *.bde.es and *.escb.eu. When a page calls that API, the extension relays the request through a content-script port to a background service worker, which forwards it verbatim to the native messaging host indra.minsait.indratokennativewrapper. The native host is then expected to load a PKCS11 library by the name the page provided, with no path validation performed in the extension layer.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

escb-pkiv1.3Chrome Web Store
20Risk
Who publishes it

BANCO DE ESPAÑA - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
escb-pki
Declared legal entity
BANCO DE ESPAÑA
Registered address
CALLE ALCALA 48, MADRID, Madrid 28014, ES
Registered contact
BANCO DE ESPAÑA

Same operator - 1 listing

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026pnaapcaggocnllecimkopedaacemikbb