Grok 4
aoemlgniakbojcecmjefonjkgnceklpg
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Title 'Grok 4' impersonates xAI's Grok brand; dev email is a free Gmail with no verified business identity.
- Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
- Extension loads content from 7 easytool.dev subdomains (ChatGPT, Grok, Gemini, DeepSeek, Perplexity) — broad external JS surface with no CSP.
- Uninstall and install URL hijack flags set — typical monetization/tracking shell pattern.
- Manifest name/description use i18n placeholders only; no visible developer name; classic anonymity indicators.
Evidence
- brand_impersonation_pattern store Title 'Grok 4' + Gmail dev email grokaitool@gmail.com; not affiliated with xAI. brand_mention.is_impersonation==false but name mimics brand.
- uninstall_install_url_hijack crx uninstall_url_hijack=true AND install_url_hijack=true; targets null but flags indicate monetization shell wiring.
- external_js_hosts crx 7 easytool.dev subdomains contacted: chatgpt-5, chatgpt-sidebar, deepseek-ai, gemini-2, grok-3, grok-ai, perplexity-ai.
- no_csp crx csp_present=false on MV3 extension loading 7 external JS hosts; DOM-XSS sink present.
- privacy_policy_generic store Policy is Google's own account privacy page (scope_extension=false, data_collection=true, third_party_sharing=true).
- free_webmail_dev_no_name store Developer email is Gmail; developer_name empty; domain_age_ct not queried due to free webmail.
- manifest_placeholders crx manifest_name='__MSG_appName__'; manifest_description='__MSG_shortDesc__' — identity obscured.
- dom_xss_sink crx innerHTML assignment from variable in iframe-service-C9N42zcQ.js with no CSP mitigating XSS risk.
Permissions Breakdown
- storage low Local key-value storage; no cross-origin access.
- sidePanel low Displays sidebar UI; no data exfil capability alone.
Pillar Scores
Permissions0.60
Reputation7.50
Network3.50
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:23
Listing SHA
161ed8b48c3f…
Force block
— not fired
Score recovered
no
Elapsed
—