Running the godsplan 3.0.2 CLI connects to Chrome's debugging port (9222) and injects JavaScript into every open page. It bypasses Content Security Policy and intercepts selected test-page requests. When triggered by a mouse gesture or keyboard shortcut, the injected script collects the page text and current editor input; the CLI sends that content to https://ai-script.test0ing7.workers.dev/ for AI-generated answers and inserts the response into the page. The package also disables TLS certificate verification with NODE_TLS_REJECT_UNAUTHORIZED=0. This behavior can disclose browser-page and editor contents to an external service and alter test-page content. The observed trigger is CLI execution; no install-time execution was identified.
Evidence: package/cdp_inject.js:2 disables TLS verification; lines 150-180 collect page and editor content; lines 252-282 send the content to the external endpoint; lines 330-350 connect to Chrome, bypass CSP and inject the script; lines 370-390 forward the collected content. Static review of the published npm tarball (sha256 8627139afbb193624535de0c32348e7b2747449ed9940f9c29e4dfb5a3f9a350); the package was not executed during manual review.
{
"iocs": {
"domains": [
"ai-script.test0ing7.workers.dev"
],
"files": [
{
"digests": {
"sha256": "e8cd7729997babf809d59dbf14b34f9f416fd47ff4ca006fc42b88382910e99e"
},
"note": "CLI entry point that injects into Chrome pages, forwards collected page and editor content to an external endpoint, and inserts generated answers.",
"paths": [
"package/cdp_inject.js"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://ai-script.test0ing7.workers.dev/"
]
}
}