Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Venice AI to PDF - Export Venice AI Chats to PDF, Markdown, JSON

dpeabmlbmhjbokfijjcpcebgkgkjknkm
Risk Score
4.48
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 181
Rating 5.0
Last updated 2026-08-29
Manifest version MV3
CSP present ✅ yes
Developer neocrtxai@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is 481 chars, not extension-scoped, no data collection or retention disclosure — effectively opaque.
  • Free-webmail developer (gmail) with no business name; install_url_hijack triggered on install.
  • 8 innerHTML DOM-XSS sinks across content scripts handling AI chat HTML without evident sanitization.
  • CSP connect-src is '*' allowing exfil to any host despite MV3; js_external_hosts include Stripe, X, Grok, DeepSeek, ChatGPT beyond stated function.
  • Yandex OAuth/cloud host permissions add foreign-jurisdiction cloud storage risk for exported chat content.

Evidence

  • free_webmail_no_dev_name store developer_email=neocrtxai@gmail.com; developer_name empty; no verified publisher badge.
  • install_url_hijack manifest install_url_hijack=true; target null — onInstalled opens 3rd-party URL.
  • csp_connect_src_broad manifest connect-src is '*' — allows outbound connections to any host from extension pages.
  • js_external_hosts_scope_mismatch crx buy.stripe.com, chat.deepseek.com, chatgpt.com, grok.com, x.com loaded despite venice.ai-only stated purpose.
  • dom_xss_sinks crx 8 innerHTML assignments from variables across options.js, popup.js, cocounsel.js, claude.js, renderer.js, shared.js, helpers.js, pdfobject.
  • privacy_policy_inadequate api Policy length=481, scope_extension=false, data_collection=false, retention=false, third_party_silence=true.
  • yandex_host_permissions manifest Host perms include oauth.yandex.com, oauth.yandex.ru, cloud-api.yandex.net — foreign jurisdiction cloud storage.
  • search_engine_count_3 api threat_intel shows 3 search engines (google, yandex.com, yandex.ru) contacted — unusual for a PDF export tool.

Permissions Breakdown

  • storage low Local data persistence; minimal risk.
  • downloads medium Can initiate file downloads; moderate risk for file-drop attacks.
  • downloads.open medium Can auto-open downloaded files; escalates download risk.
  • identity medium OAuth token access; risk if tokens misused for cloud service auth.
  • activeTab low Limited to user-invoked tab; low standalone risk.
  • host:https://*.amazonaws.com/* medium Broad AWS access; could exfil data to attacker-controlled S3 bucket.
  • host:https://*.googleusercontent.com/* medium Access to Google user content storage endpoints.
  • host:https://ai-chat-exporter-api-venice-*.run.app/* medium Developer-controlled backend; chat content may pass through.
  • host:https://api.dropboxapi.com/* medium Dropbox API access for cloud export; requires token.
  • host:https://api.notion.com/* medium Notion API access; workspace data exposure risk.
  • host:https://cloud-api.yandex.net/* medium Yandex cloud API; foreign jurisdiction storage concern.
  • host:https://oauth.yandex.com/* medium Yandex OAuth; credential flow to Russian jurisdiction service.
  • host:https://oauth.yandex.ru/* medium Yandex OAuth Russian domain; same concern as yandex.com.
  • host:https://venice.ai/* low Stated primary function domain; expected and scoped.
  • host:https://www.googleapis.com/* medium Broad Google APIs; Google Drive export plausible but wide surface.

Pillar Scores

Permissions3.50
Reputation6.50
Network4.50
Webstore5.00
Maintenance0.00
Privacy9.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 13:30
Listing SHA 7e0cd4812d4e…
Force block — not fired
Score recovered no
Elapsed