AiSenseUs - AI Meeting Notes, Transcription & Summaries Assistant
cbojomnehgiadpclibfpidkipekmeldd
Risk Score
4.64
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail dev (outlook.com) with no developer name — unverifiable identity for a meeting-audio AI tool.
- Brand impersonation: extension claims Google Meet, Zoom, Teams support but developer is not an affiliate/owner.
- Privacy policy not scoped to this extension and third-party silence flag active — data handling undisclosed.
- AI extension processes sensitive meeting audio/transcriptions via api.aisenseus.net with no CSP guardrails.
- No CSP on MV3 extension contacting 8 external JS hosts including script.google.com and stackoverflow.com.
Evidence
- free_webmail_no_dev_name store Developer email vdsoftware@outlook.com; developer_name is empty — no verified identity.
- brand_impersonation store brand_mention: Google, Zoom, Teams mentioned; confirmed_owner=false, is_impersonation=true.
- privacy_policy_not_scoped api Policy fetched but scope_extension=false, data_collection=true, third_party_silence=true → score +9+1.
- no_csp crx content_security_policy is null; extension contacts 8 external hosts with no script restriction.
- external_hosts_diverse crx js_external_hosts includes script.google.com, stackoverflow.com alongside aisenseus.net endpoints.
- install_url_hijack crx install_url_hijack=true targeting meetings.html on install — opens page on extension install.
- ai_meeting_content store AI extension processes meeting audio/transcripts; data sent to api.aisenseus.net (NL-hosted).
- low_install_count store Only 11 installs; no community validation for a tool with access to sensitive meeting content.
Permissions Breakdown
- storage low Local state persistence; standard for productivity extensions.
- downloads medium Can write files to disk; could export meeting recordings or data.
- scripting medium Dynamic script injection into pages; scoped only to meet.google.com host.
- https://meet.google.com/* medium Host access to Google Meet; narrows scope but grants full DOM/audio access on meetings.
Pillar Scores
Permissions2.30
Reputation7.50
Network3.50
Webstore5.00
Maintenance3.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:34
Listing SHA
01620a680a8a…
Force block
— not fired
Score recovered
no
Elapsed
—