Shadow AI Firewall
dobaajjnlgpbfkhlfldikmlfihnilajp
Risk Score
2.90
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Supabase backend host permission implies PII/AI prompt data may be sent to developer-controlled server.
- Privacy policy is 29 chars, fetched but scope_extension==false — effectively no meaningful disclosure.
- Free-webmail developer (gmail), no developer name, no verified publisher, no business domain.
- AI extension processes sensitive page content on 16+ AI platforms with content scripts.
- No CSP defined (MV3 mitigates but no explicit policy); privacy policy hosted on Vercel free tier.
Evidence
- supabase_host_permission manifest https://*.supabase.co/* in host_permissions implies outbound data transmission to developer backend.
- trivial_privacy_policy crx Privacy policy fetched but only 29 chars; scope_extension=false, data_collection=false — not credible.
- free_webmail_no_dev_name store developer_email=varveroglouvas@gmail.com, developer_name empty, no verified publisher badge.
- ai_content_script_reach manifest Content scripts injected into 16 major AI platforms; can read/modify all page content including prompts.
- no_csp manifest content_security_policy is null; no explicit CSP declared (MV3 default applies).
- micro_install_base store Only 3 installs; no community vetting, no reviews, no independent validation of claimed security function.
- js_external_host_vuejs crx js_external_hosts includes vuejs.org; likely CDN reference in HTML, potential remote load vector.
- operator_cluster_no_siblings api sibling_count=0; no cluster risk, but csp_host_set fingerprint matches 1 extension.
Permissions Breakdown
- storage low Stores local config/state only; no cross-origin exfil vector alone.
- host: AI platforms (chat.openai.com, claude.ai, gemini.google.com, etc.) medium Content scripts on major AI platforms to intercept/mask PII. Matches stated function but broad.
- host: *://*.googleapis.com/* medium Wide Google API surface beyond stated AI platforms; potential scope creep.
- host: *://*.bing.com/* medium Covers all Bing subdomains, broader than Copilot-only need.
- host: https://*.supabase.co/* high External backend (Supabase) implies server-side data transmission; unknown data stored.
Pillar Scores
Permissions3.50
Reputation7.00
Network2.00
Webstore3.00
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
5bfc9b6451df…
Force block
— not fired
Score recovered
no
Elapsed
22.9s