Read AI
aiamjjeggglngiggkmmbnpnpeejjejaf
Risk Score
2.63
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy does not scope to this extension yet admits data collection and third-party sharing — rated 10.0.
- Content scripts on Google Meet and Calendar can read sensitive meeting/calendar content sent to read.ai.
- No developer name listed in store; verified_publisher is false despite 400K installs.
- External JS hosts (statsigcdn, featureassets.org, prodregistryv2.org) represent analytics/feature-flag surface with 2 countries.
- AI extension processing meeting content with broad data-sharing policy creates ongoing privacy exposure.
Evidence
- privacy_policy_scope_mismatch api Policy fetched (54687 chars), data_collection=true, third_party_sharing=true, scope_extension=false — generic policy, not scoped to extension.
- content_scripts_sensitive_domains manifest Content scripts injected into meet.google.com and calendar.google.com — can access meeting and calendar data.
- no_developer_name store developer_name is empty string; verified_publisher=false despite 400K installs and AI category.
- external_js_hosts crx 4 external hosts: api.statsigcdn.com, cloudflare-dns.com, featureassets.org, prodregistryv2.org — analytics/feature-flag infra.
- featured_by_google store is_featured_by_google=true provides moderate trust signal, partially offsetting reputation concerns.
- no_csp manifest content_security_policy is null; MV3 default CSP applies, limiting (but not eliminating) remote-code risk.
- react_16_13_1_bundled crx React 16.13.1 detected — below 16.4 threshold; however no CVEs found in cve_findings_raw.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, no bad_host_hits, no monetization or affiliate hits.
Permissions Breakdown
- cookies high Can read/write cookies; scoped only to *.read.ai host, limiting blast radius.
- storage low Local extension storage; no cross-site risk.
- alarms low Scheduling only; no data access.
- *://*.read.ai/ (host_permission) low Scoped to developer's own domain; minimal third-party reach.
- content_scripts: calendar.google.com, meet.google.com medium Runs JS in Google Calendar and Meet — can read meeting data and calendar events.
Pillar Scores
Permissions3.50
Reputation5.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-10 08:33
Listing SHA
0e1f10f8f86d…
Force block
— not fired
Score recovered
no
Elapsed
—