{
  "title": "Steam sessions and platform access \u2014 targeted extension code audit",
  "review_date": "2026-10-10",
  "scope": "Credential acquisition, renewal triggers, transmission, registered entry points and related trade-control paths. Not a full security certification of either package.",
  "acquisitions": [
    {
      "name": "Steam WebAPI Token Extension",
      "version": "1.2",
      "official_referral": "https://csgoroll.com/extension",
      "referral_observation": {
        "file": "csgoroll-link-response.html",
        "request_url": "https://csgoroll.com/extension",
        "final_url": "https://chromewebstore.google.com/detail/steam-webapi-token-extens/bdgacfnoihldeemdcbggkgmjgdfcliah?authuser=0&hl=en-GB&pli=1&ucbcb=1",
        "status": 200,
        "content_type": "text/html; charset=utf-8",
        "bytes": 686672,
        "sha256": "f03aaad40b45a6a9afe0131b85cabb031b87028daebb43cccc82d5866e2ba30e",
        "retrieved_at": "2026-10-10T20:57:43.512418+00:00"
      },
      "extension_id": "bdgacfnoihldeemdcbggkgmjgdfcliah",
      "request_url": "https://clients2.google.com/service/update2/crx?response=redirect&prodversion=140.0.0.0&acceptformat=crx2%2Ccrx3&x=id%3Dbdgacfnoihldeemdcbggkgmjgdfcliah%26uc",
      "final_url": "https://clients2.googleusercontent.com/crx/blobs/AZPVhcRS-rUv85L4e9ekmco5etqQcnGskvMrduPHTvNTzGFZ1znyco3x5xlg5aLr0vCs0FXN_AcXsEQdEp2yStGd0KY7eU0ztoav1LArUHzGmOQt1cTWqnwxqLo14ORCrBMAxlKa5SiWCg_LTyLZpNZ0DHxmbVwBw3Ak/BDGACFNOIHLDEEMDCBGGKGMJGDFCLIAH_1_2_0_0.crx",
      "status": 200,
      "content_type": "application/x-chrome-extension",
      "retrieved_at": "2026-10-10T20:58:38.616218+00:00",
      "bytes": 309675,
      "sha256": "b3ad7738bd8aa7a7fda1b8db72a51013a002a2bd7a5e85470f3ab1aca038a443"
    },
    {
      "name": "Steam Inventory Helper",
      "version": "2.11.12",
      "extension_id": "cmeakgjggjdlcpncigglobpjbkabhmjl",
      "official_referral": "https://steaminventoryhelper.com/",
      "file": "sih.zip",
      "request_url": "https://download.steaminventoryhelper.com/chrome-extension.zip",
      "final_url": "https://download.steaminventoryhelper.com/chrome-extension.zip",
      "status": 200,
      "content_type": "application/zip",
      "bytes": 76806729,
      "sha256": "63755fe96c0a55826d45661f8aec56a0b173a833ddf0e64074fd5a798425bd6a",
      "retrieved_at": "2026-10-10T20:57:26.565433+00:00"
    }
  ],
  "crx_verification": {
    "extension_id": "bdgacfnoihldeemdcbggkgmjgdfcliah",
    "package_sha256": "b3ad7738bd8aa7a7fda1b8db72a51013a002a2bd7a5e85470f3ab1aca038a443",
    "proofs": [
      {
        "algorithm": "RSA-PKCS1v1.5-SHA256",
        "public_key_sha256": "b5e4096227b83f82101fc2aa49f2a251accde3d98471464dd17d1819b43786b0",
        "matches_extension_id": false,
        "signature_valid": true
      },
      {
        "algorithm": "RSA-PKCS1v1.5-SHA256",
        "public_key_sha256": "136025de87b344c32166a6c96352b80797d44d1840fcf2232b58b3a6378e0c64",
        "matches_extension_id": true,
        "signature_valid": true
      },
      {
        "algorithm": "ECDSA-SHA256",
        "public_key_sha256": "61f7f2a6bfcf74cd0bc1fe2497cc9b04254c658f79f2145392867ea8366367cf",
        "matches_extension_id": false,
        "signature_valid": true
      }
    ],
    "scope": "CRX3 cryptographic integrity and extension-ID key match; not a safety verdict or independent check of Google key pinning.",
    "format_reference": "https://raw.githubusercontent.com/chromium/chromium/main/components/crx_file/crx3.proto"
  },
  "offline_checks": {
    "mode": "Offline execution of original extractor with a stubbed fetch; synthetic input only",
    "passed": [
      "authenticated request option",
      "extract exact response token and SteamID",
      "identical response returns identical token",
      "missing SteamID returns null",
      "missing token returns null"
    ],
    "requests_intercepted": 4,
    "live_requests": 0,
    "limitation": "Does not test live Steam issuance, token lifetime, browser permission behavior, or platform settlement."
  },
  "formatting": {
    "formatter": "jsbeautifier 1.15.4; defaults; analysis copy only",
    "files": [
      {
        "product": "sih",
        "file": "bundle/js/background.js",
        "original_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
        "readable_sha256": "67f09a0cb4349ee734414b0c0ecb77215e45bb897c460873e8921dcfc77d8419",
        "lines": 127064
      },
      {
        "product": "sih",
        "file": "bundle/js/common.js",
        "original_sha256": "f1cfa4c20bef835cb0f0e73445077df9ca103f4bd7ed9bd2f8fad602322b0e8c",
        "readable_sha256": "3215f6ad0a5690af3c2a86f7e33d209a9e038f955d4494e130eb0561364cd288",
        "lines": 32073
      },
      {
        "product": "sih",
        "file": "bundle/js/sihAgent.js",
        "original_sha256": "3071af198f4b6f88580971b135728a600b06b5d9ae27e44cdc07a0ecf233406c",
        "readable_sha256": "f75970b23bd2e629bf6176096ff282f0b8d6691578bbf93a65e6798be9ff066e",
        "lines": 15524
      },
      {
        "product": "csgoroll-current",
        "file": "update-token.js",
        "original_sha256": "a5377f3cc9131c6b9a8d7f3c15268ccc51053bc153310634f3ddda8d059365fc",
        "readable_sha256": "2baad5f47b6b3467938b0a0f9ffd78f70fb4ab296575c265a6c51507796efe37",
        "lines": 37
      },
      {
        "product": "csgoroll-current",
        "file": "content-script.js",
        "original_sha256": "46bab786312e2663cd2af9824c422f59a555cb0ce1f96d6bdc05473c0a0cc449",
        "readable_sha256": "6ca97b76f76b46d5779ca180e073d96627e541f1a2bb26298f481f944247bcc8",
        "lines": 9265
      },
      {
        "product": "csgoroll-current",
        "file": "index.js",
        "original_sha256": "b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73",
        "readable_sha256": "04ce62dbfe23f89ab5fe8fef904f7ea72f4932a243581a1ad53d688427568e77",
        "lines": 44
      }
    ]
  },
  "location_convention": "Byte offsets are zero-based in original unmodified files. Line numbers are one-based. Optional formatted lines refer to jsbeautifier 1.15.4 with defaults and are navigational only; hashes refer to original bytes.",
  "findings": [
    {
      "id": "R01",
      "title": "The current CSGORoll link identifies a different package",
      "kind": "Acquisition record",
      "text": "On 10 October 2026, https://csgoroll.com/extension resolved to Steam WebAPI Token Extension, ID bdgacfnoihldeemdcbggkgmjgdfcliah, offered by Ancient Gaming. The Google update service supplied version 1.2. The June 2024 blog links to the earlier ID cgkgfnlnpcifjnbfdbmcphcgnkeinjpd. The two package identities are recorded separately.",
      "locations": [
        {
          "package": "csgoroll-current",
          "file": "manifest.json",
          "file_sha256": "ab2ff2f51b5b1ebc862085e992ea380cfb9c42c837fd74c3e9657d9a57eeb792",
          "anchor": "\"version\":\"1.2\"",
          "byte_offset_zero_based": 174,
          "original_line_one_based": 3,
          "formatted_lines": null
        }
      ]
    },
    {
      "id": "R02",
      "title": "The browser session supplies the token",
      "kind": "Code + offline check",
      "text": "Opening the popup loads index.js, which calls getSteamCommunityInfo(). That function requests https://steamcommunity.com/profiles with credentials included, extracts the SteamID and data-loyalty_webapi_token from the returned HTML, and returns both. It reads a Steam-issued value. An offline fixture confirmed that the same response produces the same token.",
      "locations": [
        {
          "package": "csgoroll-current",
          "file": "index.html",
          "file_sha256": "93351ab1c5ac5bcd7b6aae5a7ce6bb7bd7c4f6d0a1e7b8322483c218c2a6bf71",
          "anchor": "<script src=\"index.js\"",
          "byte_offset_zero_based": 1908,
          "original_line_one_based": 51,
          "formatted_lines": null
        },
        {
          "package": "csgoroll-current",
          "file": "index.js",
          "file_sha256": "b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73",
          "anchor": "getSteamCommunityInfo().then",
          "byte_offset_zero_based": 134,
          "original_line_one_based": 4,
          "formatted_lines": [
            5,
            9
          ]
        },
        {
          "package": "csgoroll-current",
          "file": "update-token.js",
          "file_sha256": "a5377f3cc9131c6b9a8d7f3c15268ccc51053bc153310634f3ddda8d059365fc",
          "anchor": "getSteamCommunityInfo",
          "byte_offset_zero_based": 63,
          "original_line_one_based": 2,
          "formatted_lines": [
            1,
            37
          ]
        }
      ]
    },
    {
      "id": "R03",
      "title": "Version 1.2 is a popup-and-clipboard path",
      "kind": "Registered code path",
      "text": "The token is displayed in the popup and copied when the user clicks the copy button. The manifest declares no background worker, no alarms permission and no content scripts. The registered JavaScript contains no daily refresh scheduler or automatic platform upload. CSGORoll\u2019s current help page completes this route with a manual paste into its token field. A separate React template bundle is shipped but is not registered or imported by this entry path.",
      "locations": [
        {
          "package": "csgoroll-current",
          "file": "manifest.json",
          "file_sha256": "ab2ff2f51b5b1ebc862085e992ea380cfb9c42c837fd74c3e9657d9a57eeb792",
          "anchor": "\"permissions\":[]",
          "byte_offset_zero_based": 417,
          "original_line_one_based": 3,
          "formatted_lines": null
        },
        {
          "package": "csgoroll-current",
          "file": "index.js",
          "file_sha256": "b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73",
          "anchor": "navigator.clipboard",
          "byte_offset_zero_based": 1273,
          "original_line_one_based": 33,
          "formatted_lines": [
            33,
            44
          ]
        }
      ]
    },
    {
      "id": "S01",
      "title": "SIH runs a privileged background component",
      "kind": "Manifest + entry point",
      "text": "The official SIH ZIP identifies version 2.11.12. Its service worker imports common.js, background.js and backgroundAngular.js. Its declared capabilities include cookies, storage, webRequest and declarativeNetRequest, with host access to all URLs. Those permissions describe available capabilities; the following findings trace specific uses.",
      "locations": [
        {
          "package": "sih",
          "file": "manifest.json",
          "file_sha256": "d9cd8006b8cfb634943c44c540cf5db9ea425af2a59c8b0def2a8bcdef442379",
          "anchor": "\"version\": \"2.11.12\"",
          "byte_offset_zero_based": 164,
          "original_line_one_based": 7,
          "formatted_lines": null
        },
        {
          "package": "sih",
          "file": "manifest.json",
          "file_sha256": "d9cd8006b8cfb634943c44c540cf5db9ea425af2a59c8b0def2a8bcdef442379",
          "anchor": "\"permissions\"",
          "byte_offset_zero_based": 14563,
          "original_line_one_based": 446,
          "formatted_lines": null
        },
        {
          "package": "sih",
          "file": "service-worker.js",
          "file_sha256": "03bc8f4d0ab34af3d93c0245ebb58a680b06443348473ea36d87cb975a48b64c",
          "anchor": "importScripts",
          "byte_offset_zero_based": 393,
          "original_line_one_based": 11,
          "formatted_lines": null
        }
      ]
    },
    {
      "id": "S02",
      "title": "A server message can request a WebAPI token",
      "kind": "Registered handler",
      "text": "In the active background bundle, event Av maps to handler Db. Db requests the Steam profile-edit page, extracts its loyalty WebAPI token, and places the value in a webApiToken response field. The handler map is attached to a WebSocket provider at wss://wss-new.steaminventoryhelper.com. This is a code path for returning a credential to the server when extraction succeeds; this review did not capture a live authenticated exchange.",
      "locations": [
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "Av=\"vYPRqjhY88H91uTxrcm\"",
          "byte_offset_zero_based": 532222,
          "original_line_one_based": 1,
          "formatted_lines": [
            22939,
            22954
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "Webapi token get: called",
          "byte_offset_zero_based": 723214,
          "original_line_one_based": 1,
          "formatted_lines": [
            32324,
            32354
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "Av,Db",
          "byte_offset_zero_based": 1210623,
          "original_line_one_based": 1,
          "formatted_lines": [
            56880,
            56880
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "wss://wss-new.steaminventoryhelper.com",
          "byte_offset_zero_based": 1212415,
          "original_line_one_based": 1,
          "formatted_lines": [
            56933,
            56976
          ]
        }
      ]
    },
    {
      "id": "S03",
      "title": "The connection has explicit operating conditions",
      "kind": "Control flow",
      "text": "The agent runner checks the sih_app_market_toggle setting and stored Steam authorization before connecting. Its controller also considers server configuration, eligible account cohorts and pending orders. The token handler itself contains no additional project-permission check or per-request confirmation. Server-side authorization and which commands are actually sent remain outside the downloaded client package.",
      "locations": [
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "e[this.settingName]&&r",
          "byte_offset_zero_based": 513763,
          "original_line_one_based": 1,
          "formatted_lines": [
            22093,
            22115
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "h=f.AVAILABLE_CONTROLLER_LAST_NUMBER_IDS,p=l&&l.steamId",
          "byte_offset_zero_based": 1224236,
          "original_line_one_based": 1,
          "formatted_lines": [
            57525,
            57581
          ]
        }
      ]
    },
    {
      "id": "S04",
      "title": "Trade reads can recover by rereading the profile",
      "kind": "Code path",
      "text": "SIH stores a webApiToken and supplies it as access_token to IEconService/GetTradeOffers. Its HTTP 403 branch obtains the profile again, extracts a token, updates storage and retries. The shared profile helper has a 60-second cache threshold. These are response-driven and cache-driven mechanisms; this path contains no fixed 24-hour token-renewal timer.",
      "locations": [
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "Date.now()-Vc.ts>=6e4",
          "byte_offset_zero_based": 328760,
          "original_line_one_based": 1,
          "formatted_lines": [
            12621,
            12679
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "Not available web api",
          "byte_offset_zero_based": 665071,
          "original_line_one_based": 1,
          "formatted_lines": [
            29396,
            29459
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/common.js",
          "file_sha256": "f1cfa4c20bef835cb0f0e73445077df9ca103f4bd7ed9bd2f8fad602322b0e8c",
          "anchor": "data-loyalty_webapi_token",
          "byte_offset_zero_based": 204323,
          "original_line_one_based": 1,
          "formatted_lines": null
        }
      ]
    },
    {
      "id": "S05",
      "title": "Refresh-token renewal is a separate implementation",
      "kind": "Separate credential path",
      "text": "SIH also contains an authenticator/session-management subsystem. It checks an access token\u2019s exp claim and can request another access token from Steam\u2019s GenerateAccessTokenForApp endpoint using a refresh token and SteamID. This subsystem requires its own session material; the profile-page token extraction path does not itself establish possession of a refresh token.",
      "locations": [
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "isTokenExpired error:",
          "byte_offset_zero_based": 1483401,
          "original_line_one_based": 17,
          "formatted_lines": [
            69444,
            69457
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "refresh_token:e,steamid:r",
          "byte_offset_zero_based": 1483633,
          "original_line_one_based": 17,
          "formatted_lines": [
            69458,
            69523
          ]
        }
      ]
    },
    {
      "id": "S06",
      "title": "The active agent includes trade execution paths",
      "kind": "Registered handlers",
      "text": "The same active handler map registers send, accept, decline and cancel operations. The send path constructs an offer from the payload\u2019s recipient and items, adds the local Steam session ID and recipient trade-link token, and POSTs to Steam with credentials included. The server receives the resulting trade ID. Actual execution remains subject to the active session, agent state and Steam\u2019s checks; final mobile confirmation was not tested.",
      "locations": [
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "dv=\"tradesend\"",
          "byte_offset_zero_based": 531972,
          "original_line_one_based": 1,
          "formatted_lines": [
            22939,
            22947
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "https://steamcommunity.com/tradeoffer/new/send",
          "byte_offset_zero_based": 1199292,
          "original_line_one_based": 1,
          "formatted_lines": [
            56297,
            56329
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "partner:s.data.recipient.steamId",
          "byte_offset_zero_based": 1201080,
          "original_line_one_based": 1,
          "formatted_lines": [
            56397,
            56408
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "Trade send: called",
          "byte_offset_zero_based": 1209217,
          "original_line_one_based": 1,
          "formatted_lines": [
            56806,
            56825
          ]
        }
      ]
    },
    {
      "id": "F01",
      "title": "What the package establishes about CSGOFast",
      "kind": "Attribution boundary",
      "text": "The SIH package contains a CSGOFast-labelled notification and send-trade implementation in bundle/js/sihAgent.js, plus CSGOFast promotional references in the active background bundle. A package-wide text search found no registration or import reference to sihAgent.js. The active credential path above belongs to SIH; the supplied code does not establish that CSGOFast currently controls that path. A distinct current CSGOFast extension ID or package is still needed to attribute a separate implementation.",
      "locations": [
        {
          "package": "sih",
          "file": "bundle/js/sihAgent.js",
          "file_sha256": "3071af198f4b6f88580971b135728a600b06b5d9ae27e44cdc07a0ecf233406c",
          "anchor": "CSGOFast: Confirm trade",
          "byte_offset_zero_based": 364333,
          "original_line_one_based": 1,
          "formatted_lines": [
            14343,
            14422
          ]
        },
        {
          "package": "sih",
          "file": "bundle/js/background.js",
          "file_sha256": "dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36",
          "anchor": "key:\"CSGOFAST\"",
          "byte_offset_zero_based": 2273840,
          "original_line_one_based": 17,
          "formatted_lines": null
        }
      ],
      "follow_up": "Current Fast frontend now establishes a direct SIH installation and permission flow. See trade-tracking.html#fast and findings CF01\u2013CF03 in the follow-up record. Original SIH package observations are preserved."
    }
  ],
  "unresolved": [
    "Actual token lifetime and live rotation cadence for a Steam account were not measured.",
    "The earlier CSGORoll 2024 package was not acquired; its automatic workflow is documented by the operator\u2019s dated publication.",
    "Current CSGOFast extension identity and attribution of SIH\u2019s active credential handler to CSGOFast are unresolved.",
    "No live server commands, authenticated Steam requests, trades, account changes or settlement operations were performed.",
    "The SIH review follows selected credential and trade-control paths, not all 225 JavaScript files or every feature."
  ],
  "sources": [
    {
      "id": "A01",
      "title": "CSGORoll\u2019s current extension redirect",
      "url": "https://csgoroll.com/extension",
      "note": "Observed final URL and timestamp are retained in the audit record."
    },
    {
      "id": "A02",
      "title": "Steam WebAPI Token Extension \u2014 Chrome Web Store",
      "url": "https://chromewebstore.google.com/detail/steam-webapi-token-extens/bdgacfnoihldeemdcbggkgmjgdfcliah",
      "note": "Version 1.2; Ancient Gaming; listed update 22 February 2025."
    },
    {
      "id": "A03",
      "title": "Current CRX from Google\u2019s update service",
      "url": "https://clients2.google.com/service/update2/crx?response=redirect&prodversion=140.0.0.0&acceptformat=crx2%2Ccrx3&x=id%3Dbdgacfnoihldeemdcbggkgmjgdfcliah%26uc",
      "note": "Downloaded package, SHA-256 and signature checks pinned in this report."
    },
    {
      "id": "A04",
      "title": "CSGORoll \u2014 WebAPI P2P Solution",
      "url": "https://www.csgoroll.com/blog/steam-p2p-solution/",
      "note": "10 April 2024. Same-session token extraction and daily renewal instruction."
    },
    {
      "id": "A05",
      "title": "CSGORoll \u2014 WebAPI Trading Extension",
      "url": "https://www.csgoroll.com/blog/csgoroll-trading-extension/",
      "note": "25 June 2024. Automatic collection, refresh and transmission in the announced workflow."
    },
    {
      "id": "A06",
      "title": "CSGORoll Help Center \u2014 Steam WebAPI Token",
      "url": "https://intercom.help/csgoroll/en/articles/12033745-steam-webapi-token",
      "note": "10 November 2025. Extension copy-and-paste instructions and trade-status use."
    },
    {
      "id": "A07",
      "title": "SIH official download page",
      "url": "https://steaminventoryhelper.com/",
      "note": "The page links directly to the audited ZIP and identifies RedBoon Limited."
    },
    {
      "id": "A08",
      "title": "SIH official ZIP",
      "url": "https://download.steaminventoryhelper.com/chrome-extension.zip",
      "note": "Downloaded version 2.11.12. This is the audit\u2019s SIH code source."
    },
    {
      "id": "A09",
      "title": "SIH \u2014 Chrome Web Store",
      "url": "https://chromewebstore.google.com/detail/steam-inventory-helper/cmeakgjggjdlcpncigglobpjbkabhmjl",
      "note": "Published identity and version cross-check."
    },
    {
      "id": "A10",
      "title": "Chromium \u2014 CRX3 format",
      "url": "https://raw.githubusercontent.com/chromium/chromium/main/components/crx_file/crx3.proto",
      "note": "Signed archive layout and extension-ID derivation."
    },
    {
      "id": "A11",
      "title": "Chrome \u2014 cross-origin network requests",
      "url": "https://developer.chrome.com/docs/extensions/develop/concepts/network-requests",
      "note": "Extension host permissions and cross-origin request behavior. Host-permission paths do not constrain access to just that path."
    },
    {
      "id": "A12",
      "title": "Chrome \u2014 cookies API",
      "url": "https://developer.chrome.com/docs/extensions/reference/api/cookies",
      "note": "Cookie access requires the cookies permission and matching host permissions."
    },
    {
      "id": "A13",
      "title": "Chrome \u2014 alarms API",
      "url": "https://developer.chrome.com/docs/extensions/reference/api/alarms",
      "note": "A scheduled callback interval is distinct from the expiry encoded in a token."
    }
  ],
  "follow_up": {
    "review_date": "2026-10-10",
    "page": "../../../trade-tracking.html#fast",
    "record": "../trade-tracking-2026-10-10/audit-record.json",
    "summary": "Current CSGOFast frontend supplies an SIH extension installation link and checks connections.SIH online and permission state. This supplements the earlier SIH-only attribution review."
  }
}
