Smart Sidebar: Chat GPT, Claude & DeepSeek
fnmihdojmnkclgjpcoonokmkhjpjechg
Risk Score
6.10
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- scripting + <all_urls> + content_scripts on every page: full DOM read/write on all sites for 400K users
- Brand impersonation: mentions Claude & DeepSeek without confirmed ownership; domain chatgptbuddy.com mismatches policy domain chataigpt.pro
- Privacy policy too short (25 chars), not scoped to this extension, no retention disclosure — effectively no policy
- Multiple new Function() constructors and 15+ unguarded innerHTML sinks with no CSP — elevated DOM-XSS surface
- Uninstall URL hijack detected; AI extension with broad host access and no verified publisher accountability
Evidence
- host_permissions + content_scripts <all_urls> with scripting manifest Full-site scripting capability on all URLs for 400K installs; HIGH×1.2 multiplier applied.
- brand impersonation store brands_mentioned=[claude,deepseek], confirmed_owner=false, is_impersonation=true; +2.0 Reputation.
- privacy policy inadequate crx Policy fetched but length=25, scope_extension=false, data_collection=false → +9.0 Privacy (FIX A).
- no CSP + function_constructor + dom_sink_innerhtml crx csp_present=false; 4 function_constructor hits (+2.5) + innerHTML sinks elevated by no-CSP rule (+2.0).
- uninstall URL hijack crx uninstall_url_hijack=true; +3.0 Webstore (setUninstallURL to 3rd party).
- AI extension processing page content store Detected as AI sidebar with <all_urls> content scripts; +2.5 Webstore AI signal.
- no verified publisher; developer domain mismatch store verified_publisher=false; policy at chataigpt.pro differs from dev domain chatgptbuddy.com.
- js_external_hosts > 3 distinct domains crx 12 external JS hosts (feross.org, github.com, etc.); +1.5 Network for >3 distinct registrable domains.
Permissions Breakdown
- storage low Local state persistence; low standalone risk.
- scripting high Allows dynamic script injection into any page via <all_urls> host perm.
- system.display low Read display info; low risk for sidebar positioning.
- contextMenus low Adds right-click menu items; low standalone risk.
- <all_urls> (host_permissions) high Full read/modify access to all websites; paired with scripting = critical reach.
- <all_urls> (content_scripts) high Content scripts run on every page; broad DOM access at scale.
Pillar Scores
Permissions8.00
Reputation7.00
Network4.00
Webstore5.50
Maintenance0.00
Privacy9.00
Code Quality7.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 06:06
Listing SHA
d2150c87d750…
Force block
— not fired
Score recovered
no
Elapsed
33.3s