Chat with all AI models (Gemini, Claude, DeepSeek…) & AI Agents | AITOPIA
becfinhbfclcgokjlobojlnldbfillpf
Risk Score
6.05
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- <all_urls> host permission + scripting: can read/modify every page the user visits, including sensitive auth sessions.
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — users cannot assess actual data exposure.
- Brand impersonation (Gemini, Claude, DeepSeek) without confirmed ownership; confirmed impersonation flag from threat_intel.
- Uninstall URL hijack active: extension sets a third-party URL on removal, indicating monetization or tracking at uninstall.
- 20 innerHTML DOM-XSS sinks + 4 new Function() uses with no CSP — code execution paths exist on every injected page.
Evidence
- host_permissions <all_urls> + scripting manifest Extension can inject scripts and read/modify content on every URL the user visits.
- brand_mention.is_impersonation=true store Brands Gemini, Claude, DeepSeek mentioned; confirmed_owner=false — brand impersonation risk.
- uninstall_url_hijack=true crx Extension calls setUninstallURL() to a third-party destination — monetization/tracking signal.
- privacy_policy scope_extension=false, data_collection=true, third_party_sharing=true api Policy admits collection and 3rd-party sharing but does not scope to this extension → +10 privacy.
- no CSP + function_constructor + dom_sink_innerhtml crx csp_present=false; 4 new Function() findings + 16 innerHTML sinks across marketplace JS files.
- AI/Gen-AI extension processing page content store 1M installs AI sidebar with <all_urls> injects into every page and routes content to AI backends.
- external host captaina.co in js_external_hosts crx Unknown domain captaina.co referenced in JS; not dev-owned domain, warrants network scrutiny.
- is_featured_by_google=true, verified_publisher=false store Featured badge present but not verified publisher; featured discount applied, not full verified discount.
Permissions Breakdown
- storage low Stores local extension data; low standalone risk.
- scripting high Allows programmatic script injection into any page via host_permissions.
- activeTab medium Grants temporary access to current tab on user action.
- unlimitedStorage low Removes storage quota; low direct risk.
- tabs medium Can read tab URLs and metadata across all open tabs.
- sidePanel low UI surface only; low risk.
- <all_urls> (host_permission) high Broad host access paired with scripting = read/modify any page content.
Pillar Scores
Permissions7.20
Reputation5.50
Network4.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality6.00
CVE Exposure0.00
Scoring History
| %F6"onmouseover=osKd(90835)// | 6.43 | High | review | 2026-08-05 |
| bfg1541<s1﹥s2ʺs3ʹhjl1541 | 4.43 | Medium | review | 2026-08-05 |
| v3.6&n969604=v999292 | 6.19 | High | review | 2026-08-05 |
| v3.6 | 6.05 | High | block | 2026-06-16 |
| v3.4-rev | 5.64 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA
e08c5bc20f04…
Force block
— not fired
Score recovered
no
Elapsed
32.4s