Merlin AI
camppjleccjaphfdbohjdohecfnoikec
Risk Score
5.27
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetch failed (HTTPError); content of policy unknown — cannot confirm data handling practices.
- webRequest + scripting + <all_urls> content scripts: can observe and modify all page content across every site.
- AI extension processing page content on 900K installs — high-reach exfil surface if ever compromised.
- No developer name listed; developer identity weakly established despite active domain.
- Uninstall URL hijack flag set; post-removal tracking behavior present.
Evidence
- privacy_policy_fetch_failed api Privacy policy URL returned HTTPError; fetched=false. Policy content unverifiable — scored +10.0 privacy.
- broad_host_permissions manifest host_permissions=['https://*/*'] + content_scripts <all_urls> + scripting + webRequest: full page access on all sites.
- ai_extension_page_content store Detected as AI category with 900K installs and broad content script injection; +2.5 webstore AI signal.
- uninstall_url_hijack crx uninstall_url_hijack=true; extension sets a post-uninstall URL. Raises webstore score.
- no_developer_name store developer_name is empty string; identity relies solely on email support@getmerlin.in.
- no_csp manifest content_security_policy=null (MV3 strict default applies); no explicit CSP declared.
- clean_code_scan crx 403 JS files scanned; code_findings_raw empty, obfuscation_score=0.0, no CVEs detected.
- featured_by_google store is_featured_by_google=true; reduces reputation concern. No bad host/affiliate/monetization hits.
Permissions Breakdown
- sidePanel low UI surface only; no data access.
- storage low Local data persistence; low standalone risk.
- contextMenus low Adds right-click menu items; low risk.
- tabs medium Can read tab URLs and titles; moderate privacy risk.
- alarms low Scheduling only; no data access.
- webNavigation medium Monitors navigation events across all pages; tracks user browsing.
- webRequest high Can observe all network requests; significant surveillance capability.
- scripting high Can inject JS into any page; combined with https://*/* is high risk.
- https://*/* high Broad host access across all HTTPS sites; amplifies scripting/webRequest.
- content_scripts <all_urls> high Content script injected into every page; reads/modifies page content universally.
Pillar Scores
Permissions7.50
Reputation5.00
Network3.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.6 | 5.27 | Medium | review | 2026-06-16 |
| v3.4-rev | 5.14 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
a8fab97a8b7a…
Force block
— not fired
Score recovered
no
Elapsed
25.6s