Is 阿里云RPA safe?

Low risk

阿里云RPA connects to a local native host and executes arbitrary JavaScript in any browser tab using the Chrome debugger API.

The extension establishes a native messaging channel to 'sky.chromenativemsg' on the local machine. Commands received over this channel can instruct the extension to attach Chrome's debugger to any open tab and run caller-supplied JavaScript strings via Runtime.evaluate, with access to cookies, form inputs, credentials, and DOM content across all sites. On startup it also silently disables a specific other installed extension (jfdgbmdcialpkmjdbpmgchbinkjhacem) if present, without user notification.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

alibaba_cloud_rpav3.1.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.1.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See the address and title of every tab you have open

    tabs

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Attach to pages with the browser's debugger, which can read and rewrite anything on them

    debugger

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Start, monitor and manage your downloads

    downloads

  • Read whatever you have copied to your clipboard

    clipboardRead

  • Write to your clipboard

    clipboardWrite

  • See, disable and uninstall your other extensions, including your security ones

    management

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026lpalkccnhoonbaaajhfgfbmhgnodcebi