Venice AI to PDF - Export Venice AI Chats to PDF, Markdown, JSON
dpeabmlbmhjbokfijjcpcebgkgkjknkm
Risk Score
4.48
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is 481 chars, not extension-scoped, no data collection or retention disclosure — effectively opaque.
- Free-webmail developer (gmail) with no business name; install_url_hijack triggered on install.
- 8 innerHTML DOM-XSS sinks across content scripts handling AI chat HTML without evident sanitization.
- CSP connect-src is '*' allowing exfil to any host despite MV3; js_external_hosts include Stripe, X, Grok, DeepSeek, ChatGPT beyond stated function.
- Yandex OAuth/cloud host permissions add foreign-jurisdiction cloud storage risk for exported chat content.
Evidence
- free_webmail_no_dev_name store developer_email=neocrtxai@gmail.com; developer_name empty; no verified publisher badge.
- install_url_hijack manifest install_url_hijack=true; target null — onInstalled opens 3rd-party URL.
- csp_connect_src_broad manifest connect-src is '*' — allows outbound connections to any host from extension pages.
- js_external_hosts_scope_mismatch crx buy.stripe.com, chat.deepseek.com, chatgpt.com, grok.com, x.com loaded despite venice.ai-only stated purpose.
- dom_xss_sinks crx 8 innerHTML assignments from variables across options.js, popup.js, cocounsel.js, claude.js, renderer.js, shared.js, helpers.js, pdfobject.
- privacy_policy_inadequate api Policy length=481, scope_extension=false, data_collection=false, retention=false, third_party_silence=true.
- yandex_host_permissions manifest Host perms include oauth.yandex.com, oauth.yandex.ru, cloud-api.yandex.net — foreign jurisdiction cloud storage.
- search_engine_count_3 api threat_intel shows 3 search engines (google, yandex.com, yandex.ru) contacted — unusual for a PDF export tool.
Permissions Breakdown
- storage low Local data persistence; minimal risk.
- downloads medium Can initiate file downloads; moderate risk for file-drop attacks.
- downloads.open medium Can auto-open downloaded files; escalates download risk.
- identity medium OAuth token access; risk if tokens misused for cloud service auth.
- activeTab low Limited to user-invoked tab; low standalone risk.
- host:https://*.amazonaws.com/* medium Broad AWS access; could exfil data to attacker-controlled S3 bucket.
- host:https://*.googleusercontent.com/* medium Access to Google user content storage endpoints.
- host:https://ai-chat-exporter-api-venice-*.run.app/* medium Developer-controlled backend; chat content may pass through.
- host:https://api.dropboxapi.com/* medium Dropbox API access for cloud export; requires token.
- host:https://api.notion.com/* medium Notion API access; workspace data exposure risk.
- host:https://cloud-api.yandex.net/* medium Yandex cloud API; foreign jurisdiction storage concern.
- host:https://oauth.yandex.com/* medium Yandex OAuth; credential flow to Russian jurisdiction service.
- host:https://oauth.yandex.ru/* medium Yandex OAuth Russian domain; same concern as yandex.com.
- host:https://venice.ai/* low Stated primary function domain; expected and scoped.
- host:https://www.googleapis.com/* medium Broad Google APIs; Google Drive export plausible but wide surface.
Pillar Scores
Permissions3.50
Reputation6.50
Network4.50
Webstore5.00
Maintenance0.00
Privacy9.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 13:30
Listing SHA
7e0cd4812d4e…
Force block
— not fired
Score recovered
no
Elapsed
—