ejhhhokbkmlibaeoepkohaflgaohpmeg
ejhhhokbkmlibaeoepkohaflgaohpmeg
Risk Score
4.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Developer-controlled Cloud Run backend (ai-chat-exporter-api-github-copilot-*.run.app) is the primary exfiltration surface for AI chat content.
- 8 DOM-XSS innerHTML sinks across content scripts on copilot.microsoft.com and github.com increase XSS attack surface.
- No developer identity (name, email, domain) — unverifiable publisher with no accountability.
- CSP connect-src allows wildcard '*' on extension pages — permits outbound connections to any host.
Evidence
- privacy_policy_generic_google store Privacy URL is Google's own account policy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
- developer_controlled_backend manifest Host perm to ai-chat-exporter-api-github-copilot-792277256340.northamerica-south1.run.app; also in js_external_hosts.
- csp_connect_src_wildcard crx extension_pages CSP: connect-src * — allows extension to connect to any host at runtime.
- no_developer_identity store developer_name, developer_email, and developer_domain all empty/null — reputation floor 7.5 (free-webmail-like).
- install_url_hijack crx install_url_hijack=true — opens a URL on install; target is null so destination unverifiable.
- dom_xss_sinks_multiple crx 8 innerHTML-from-variable findings across content scripts and lib files without CSP script-src restrictions.
- external_hosts_diversity crx 12 distinct external JS hosts including stripe, grok, deepseek, neocortexai.in, chatgpt.com — broad surface.
- maintenance_unknown store last_updated and months_since_update both null — maintenance state unknown, scored 0.
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- downloads medium Can trigger file downloads to user's machine.
- downloads.open medium Can auto-open downloaded files; elevates downloads risk.
- identity low OAuth token access; scoped to user consent flows.
- activeTab low Scoped to user-initiated action on current tab only.
- host:*.amazonaws.com medium Broad AWS bucket access; could interact with many S3 services.
- host:*.googleusercontent.com medium Access to Google user content CDN.
- host:ai-chat-exporter-api-github-copilot-*.run.app high Calls a developer-controlled backend API — primary exfil surface.
- host:api.dropboxapi.com + content.dropboxapi.com medium Dropbox API access; can read/write user cloud storage.
- host:api.github.com + github.com medium GitHub API and site access; can read repos/gists.
- host:api.notion.com medium Notion workspace API; can read/write user notes.
- host:cloud-api.yandex.net + oauth.yandex.* medium Yandex cloud and OAuth; cross-jurisdiction data flow.
- host:copilot.microsoft.com + copilot.com low Expected for AI chat exporter targeting Copilot.
- host:www.googleapis.com low Standard Google APIs used with identity permission.
Pillar Scores
Permissions3.30
Reputation7.50
Network4.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 13:30
Listing SHA
e8105ee0541b…
Force block
— not fired
Score recovered
no
Elapsed
—