Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SaveChat for Gemini: Export to PDF & Markdown

blndbnmpkgfoopgmcejnhdnepfejgipe
Risk Score
4.31
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 20,000
Rating 4.6
Last updated 2026-05-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer hamzaw31@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail dev with no business identity impersonates Gemini brand; verified publisher discount is limited.
  • No CSP + 3 innerHTML DOM-XSS sinks in content scripts on Gemini and AI Studio.
  • External JS hosts include jsdelivr.com (CDN) and checkout.browserlab.io (payment/monetization) — unexpected for a PDF exporter.
  • install_url_hijack redirects to gemini.google.com on install; uninstall URL hijack flag also set.
  • Privacy policy hosted on free GitHub Pages, collects data but no retention period disclosed; third-party sharing silence.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'gemini'; developer_domain is gmail.com, confirmed_owner=false.
  • free_webmail_dev_no_business store developer_email=hamzaw31@gmail.com, developer_name empty, no verified business domain.
  • dom_xss_sinks_no_csp crx 3 innerHTML user-controlled sinks across injector.js, enhance_prompt.js, content_aistudio.js; csp_present=false.
  • external_hosts_unexpected crx checkout.browserlab.io and www.jsdelivr.com contacted; payment and remote CDN not expected for a chat exporter.
  • install_url_hijack crx install_url_hijack=true targeting gemini.google.com; uninstall_url_hijack=true with null target.
  • privacy_policy_inadequate store Policy on free GitHub Pages; data_collection=true, retention=false, third_party_silence=true.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts apply but capped due to monetization signals.
  • network_external_hosts crx 7 external JS hosts: checkout.browserlab.io, docs.google.com, fonts.googleapis.com, gemini.google.com, pdfmake.org, savechat.hamzaw.com, www.jsdelivr.com.

Permissions Breakdown

  • activeTab medium Accesses current tab on user action; limited scope but paired with content scripts.
  • storage low Local data persistence; low direct risk.
  • contextMenus low Adds right-click menu entries; minimal capability alone.
  • content_scripts:https://gemini.google.com/* medium Injects JS into Gemini chat; reads DOM including conversation content.
  • content_scripts:https://aistudio.google.com/* medium Injects JS into AI Studio; reads DOM including prompts and responses.

Pillar Scores

Permissions2.30
Reputation7.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA 4a253cc6609b…
Force block — not fired
Score recovered no
Elapsed 28.3s