Claude Toolbox - Chat History Search, Bookmarks & Export
camddjjmcemmmlndbciaodchkodhgibh
Risk Score
2.72
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: 'Claude' in name without confirmed ownership of the brand; not verified publisher of Anthropic.
- Privacy policy hosted on ai-toolkit.site (different domain than infi-dev.com) and discloses third-party sharing without extension-specific retention detail.
- No developer display name listed in store, reducing accountability.
- Content script on claude.ai can read full conversation content; mitigated by narrow scope.
- No CSP declared (MV3 provides default protections, but absence is still noted).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'claude'; confirmed_owner=false; developer is infi-dev.com, not Anthropic.
- verified_publisher store verified_publisher=true; discount capped to -1.0 due to v3.5(E) check: monetization_hits empty, stale<18mo — full -3.0 applies, floored at 2.0.
- privacy_policy_classification crx fetched=true, scope=true, data_collection=true, retention=true, third_party_sharing=true, third_party_silence=false → +1.0 retention only.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty for no 'Offered by' name.
- host_permission_scoped manifest host_permissions=['https://claude.ai/*']; narrow scope, not broad <all_urls>; only MEDIUM risk.
- code_quality_clean crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[], no exfil indicators.
- threat_intel_clean api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], developer domain resolves, not throwaway.
- maintenance_current store months_since_update=1; Maintenance pillar = 0.0.
Permissions Breakdown
- storage low Used to persist bookmarks/settings locally; minimal risk.
- host_permission: https://claude.ai/* medium Content script on claude.ai — can read chat content but scoped to single AI domain.
Pillar Scores
Permissions1.80
Reputation6.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
2d4e186e23c0…
Force block
— not fired
Score recovered
no
Elapsed
20.9s