Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Claude Toolbox - Chat History Search, Bookmarks & Export

camddjjmcemmmlndbciaodchkodhgibh
Risk Score
2.72
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 4,000
Rating 4.2
Last updated 2026-05-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@infi-dev.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: 'Claude' in name without confirmed ownership of the brand; not verified publisher of Anthropic.
  • Privacy policy hosted on ai-toolkit.site (different domain than infi-dev.com) and discloses third-party sharing without extension-specific retention detail.
  • No developer display name listed in store, reducing accountability.
  • Content script on claude.ai can read full conversation content; mitigated by narrow scope.
  • No CSP declared (MV3 provides default protections, but absence is still noted).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'claude'; confirmed_owner=false; developer is infi-dev.com, not Anthropic.
  • verified_publisher store verified_publisher=true; discount capped to -1.0 due to v3.5(E) check: monetization_hits empty, stale<18mo — full -3.0 applies, floored at 2.0.
  • privacy_policy_classification crx fetched=true, scope=true, data_collection=true, retention=true, third_party_sharing=true, third_party_silence=false → +1.0 retention only.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty for no 'Offered by' name.
  • host_permission_scoped manifest host_permissions=['https://claude.ai/*']; narrow scope, not broad <all_urls>; only MEDIUM risk.
  • code_quality_clean crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[], no exfil indicators.
  • threat_intel_clean api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], developer domain resolves, not throwaway.
  • maintenance_current store months_since_update=1; Maintenance pillar = 0.0.

Permissions Breakdown

  • storage low Used to persist bookmarks/settings locally; minimal risk.
  • host_permission: https://claude.ai/* medium Content script on claude.ai — can read chat content but scoped to single AI domain.

Pillar Scores

Permissions1.80
Reputation6.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA 2d4e186e23c0…
Force block — not fired
Score recovered no
Elapsed 20.9s