Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GPT Reader/Transcriber: Free AI Text to Speech/Speech to Text (TTS/STT)

aeggkceabpfajnglgaeadofdmeboimml
Risk Score
4.77
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 30,000
Rating 4.6
Last updated 2026-06-02
Manifest version MV3
CSP present ❌ no
Developer democraticdeveloper@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does NOT scope to this extension's data collection/sharing practices.
  • Content scripts injected into chatgpt.com and auth.openai.com; could intercept OpenAI session tokens or credentials.
  • install_url_hijack redirects to support.mozilla.org — anomalous for a Chrome extension.
  • No CSP + multiple innerHTML DOM-XSS sinks across 3 client JS bundles raises XSS risk.
  • Free-webmail developer (gmail) with no business name/domain; verified badge applies but governance is thin.

Evidence

  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own account policy, not scoped to this extension. scope_extension=false, data_collection=true, third_party_sharing=true.
  • content_scripts_sensitive_origin manifest content_scripts_matches includes auth.openai.com/* and chatgpt.com/* — direct access to OpenAI auth and chat sessions.
  • install_url_hijack crx install_url_hijack=true; target is support.mozilla.org — irrelevant to a Chrome extension, suspicious redirect.
  • no_csp_with_dom_sinks crx csp_present=false; three client JS bundles contain innerHTML DOM-XSS sinks; function_constructor in pdf.worker.js.
  • developer_identity store developer_email=democraticdeveloper@gmail.com; developer_name empty; domain gmail.com — free webmail, no business entity.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true — provides partial trust discount.
  • js_external_hosts crx 10 external hosts including chatgpt.com, docs.google.com, gpt-reader.com, readeon.com — >3 distinct domains.
  • mv3_no_csp_network manifest MV3 extension with no explicit CSP; v2 calibration adds +2.0 network for MV2 only — not applied; but network risk present from >3 external hosts.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles, moderate metadata exposure.
  • storage low Persist local settings; low standalone risk.
  • notifications low Display notifications; low risk.
  • activeTab medium Transient access to current tab content on user action.
  • contextMenus low Add right-click menu items; low risk.
  • scripting medium Can inject scripts into pages; elevated when paired with activeTab/content_scripts.
  • content_scripts: https://auth.openai.com/* and https://chatgpt.com/* high Injects into ChatGPT auth flow; could intercept credentials/session tokens.

Pillar Scores

Permissions3.30
Reputation7.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA 886c081f577d…
Force block — not fired
Score recovered no
Elapsed 30.9s