Prompt Optimizer - SecondBrain
aajjgdpofhhcjmjoombjdfepplndhgcp
Risk Score
6.07
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension, admits data collection and 3rd-party sharing (Privacy: 10.0).
- webRequest + https://*/* enables full request interception across all sites; AI content processed by secondbrain.is backend.
- Uninstall URL hijack flag set; post-uninstall redirect to unknown destination is a monetization/tracking indicator.
- No developer name, email, install count, or update date — identity and maintenance status unverifiable.
- innerHTML from variable in content script (DOM-XSS sink) running on all HTTPS pages including AI chatbots.
Evidence
- privacy_policy_generic_google store Privacy URL points to myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; data_collection+third_party_sharing=true.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() called; target not captured but constitutes post-uninstall tracking signal.
- broad_host_plus_webrequest manifest webRequest + https://*/* allows observation of all HTTPS traffic across every site the user visits.
- external_js_hosts crx JS contacts optimize.secondbrain.is and secondbrain.is — prompt data likely sent to developer backend.
- dom_xss_sink crx innerHTML assigned from variable in content/ui.js running on all HTTPS pages; DOM-XSS risk.
- no_developer_identity store Developer name, email, install count, and last_updated all missing — accountability unverifiable.
- content_scripts_broad manifest Content scripts match http://*/* and https://*/* — injected into every page, not just AI chatbots.
- ai_extension_page_content manifest Extension processes prompts across ChatGPT, Claude, Gemini, Grok, Perplexity, Meta AI, Copilot — wide AI content reach.
Permissions Breakdown
- webRequest high Can intercept/observe all HTTPS network requests; paired with broad host access.
- https://*/* high Broad host access covering all HTTPS sites amplifies every other permission.
- tabs medium Access to tab URLs, titles, and navigation events across all open tabs.
- storage low Local data persistence; low risk in isolation.
- unlimitedStorage low Removes storage quota; low risk but enables large local data accumulation.
- alarms low Scheduling; minimal standalone risk.
- sidePanel low UI surface only; no data access by itself.
- background low Persistent service worker; extends capability persistence.
Pillar Scores
Permissions6.50
Reputation7.00
Network4.00
Webstore5.50
Maintenance5.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 08:14
Listing SHA
89dcc9d34f22…
Force block
— not fired
Score recovered
no
Elapsed
—