DeepSeek to PDF - Export DeepSeek Chats to PDF, Markdown, JSON
ecmcbpjdknbbcfbohfcjjilgkgclgdbc
Risk Score
4.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- DeepSeek brand impersonation by unverified gmail dev with no developer name; potential for phishing or supply-chain abuse.
- Developer-controlled backend (GCP Cloud Run) receives DeepSeek chat content — opaque data pipeline with no scoped privacy policy.
- Privacy policy fetched but scope_extension==false and third_party_silence==true; no meaningful data handling disclosures.
- 8 innerHTML DOM-XSS sinks across content scripts ingesting AI chat HTML; risk of stored-XSS from malicious chat content.
- CSP connect-src is broadly open ('connect-src * data: blob: filesystem:') allowing exfiltration to arbitrary endpoints.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'deepseek'; developer domain is gmail.com, confirmed_owner=false.
- gmail_dev_no_name store developer_email=neocrtxai@gmail.com, developer_name empty; free-webmail dev with no verified business.
- install_url_hijack manifest install_url_hijack=true; extension opens URL on install — minor but noteworthy behaviour.
- csp_connect_broad manifest connect-src * data: blob: filesystem: — allows outbound connections to any host from extension pages.
- developer_backend_host crx js_external_hosts includes GCP Cloud Run backend receiving chat data; host_permissions also grant it access.
- privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=false, retention=false, third_party_silence=true.
- multiple_innerHTML_sinks crx 8 dom_sink_innerhtml_userctrl findings across content scripts processing AI-generated HTML.
- multi_search_engine_contact crx threat_intel shows 3 search engines (google, yandex.com, yandex.ru) contacted; extension is not NewTab category.
Permissions Breakdown
- storage low Local state persistence; minimal risk.
- downloads medium Can save files to disk; appropriate for PDF/export use-case.
- downloads.open medium Can auto-open downloaded files; slight UX-abuse risk.
- identity medium OAuth token access; used for cloud storage integrations (Dropbox, Notion, Yandex).
- activeTab low Scoped to user-invoked tab; low blast radius.
- host:*.amazonaws.com medium Broad AWS access; could reach developer backend or S3 uploads.
- host:*.deepseek.com medium Primary function; reads DeepSeek chat content.
- host:*.googleusercontent.com low Google-hosted assets; read-only images/fonts typical.
- host:ai-chat-exporter-api-deepseek-* high Developer-controlled backend receives chat data; opaque pipeline.
- host:api.dropboxapi.com + content.dropboxapi.com medium Cloud upload integration; requires OAuth token.
- host:api.notion.com medium Notion export integration; appropriate but widens surface.
- host:cloud-api.yandex.net + oauth.yandex.* medium Yandex cloud integration; Russian CDN geo-risk consideration.
- host:www.googleapis.com low Standard Google API endpoint for Drive/identity.
Pillar Scores
Permissions3.50
Reputation7.00
Network3.50
Webstore6.50
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 13:32
Listing SHA
d09c800aec9c…
Force block
— not fired
Score recovered
no
Elapsed
—