AI Chat Turbo
fbakofpmbmcodpmbecdimecilceplfll
Risk Score
4.39
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — admits data collection/3rd-party sharing, not scoped to this extension (+10.0 privacy).
- Brand impersonation: mentions ChatGPT and Claude but developer is unverified (m.qayyum@live.com) (+2.0 reputation).
- No developer name listed and free-webmail email; no verified business identity.
- Content scripts on AI platforms (ChatGPT, Claude) can read sensitive conversation content.
- No CSP declared on MV3 extension contacting AI platform hosts.
Evidence
- generic_privacy_policy store Privacy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- brand_impersonation store brand_mention.is_impersonation=true; brands=[claude,chatgpt]; developer is unverified individual (live.com email).
- no_developer_name store developer_name is empty string; no verified publisher badge; free-webmail address.
- content_script_ai_platforms manifest Content scripts injected into chat.openai.com, chatgpt.com, claude.ai — can read full AI conversation text.
- no_csp crx content_security_policy=null; csp_present=false on MV3 extension.
- clean_code_scan crx code_findings_raw=[]; obfuscation_score=0.0; 4 JS files scanned, no suspicious patterns found.
- no_cves crx cve_findings_raw=[]; no known-vulnerable bundled libraries detected.
- low_install_count store 761 installs; no operator cluster siblings; wayback shows no ownership change.
Permissions Breakdown
- storage low Local data persistence; no cross-origin exfil risk on its own.
- activeTab low Transient access to current tab only; low blast radius.
- https://chat.openai.com/* medium Host access to ChatGPT; can read/modify AI session content.
- https://chatgpt.com/* medium Duplicate ChatGPT domain; same session-content exposure.
- https://claude.ai/* medium Host access to Claude; can read/modify AI conversation content.
Pillar Scores
Permissions2.00
Reputation7.50
Network2.00
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:00
Listing SHA
116d9bba568d…
Force block
— not fired
Score recovered
no
Elapsed
—